tree 6c170a86e9a7e4d3f48343d4987f1fbbe04c5d05
parent 677567861fd5681f10c8f15cfc343af976e3dc94
author Thomas Draebing <thomas.draebing@sap.com> 1550676552 +0100
committer Thomas Dräbing <thomas.draebing@sap.com> 1607003579 +0000

Add NetworkPolicies to the gerrit chart

By default, the network traffic to and from Kubernetes pods is not
restricted, which poses a potential security risk. The traffic can be
restricted using the NetworkPolicy resource of Kubernetes, which hadn't
been done so far for the gerrit chart.

This change adds basic NetworkPolicies to the gerrit chart:

- All traffic is blocked by default to and from pods installed by the
  chart.
- Egress to DNS services is allowed. The required ports can be
  configured in the chart.
- External ingress traffic is allowed to port 8080 of the gerrit
  pods
- Custom ingress- and egress-rules can be configured for the
  gerrit pods to adjust for setups that are not fully supported
  by the basic NetworkPolicies.

Using the NetworkPolicies of the chart is optional and disabled by
default to reduce the initial complexity.

Change-Id: Idb9b11f7592233595e990919fae468143613663a
