# Cilium default network policy — shipped with the SysDeck firewall module. # Author: Jeremy Anderson # # This policy is applied by firewall/templates/cilium.sh `start` action # when the operator selects the Cilium backend in the SysDeck Firewall # panel. It implements a sensible default: # # - default-deny ingress + egress at the cluster level # - allow DNS (UDP/TCP 53) to kube-dns (K8s) or any local resolver # (standalone installs run systemd-resolved without kube labels) # - allow SSH (TCP 22) from anywhere — no L7 parser on port 22 # - allow HTTP/HTTPS (TCP 80/443) from anywhere, with the HTTP # method allow-list scoped to 80/443 only # # Operators can drop a custom policy at # /etc/sysdeck/firewall/cilium-policy.yaml to override. # # Reference: https://docs.cilium.io/en/stable/security/policy/ apiVersion: cilium.io/v2 kind: CiliumNetworkPolicy metadata: name: sysdeck-default-deny namespace: default annotations: sysdeck.io/managed-by: "sysdeck-firewall-cilium" sysdeck.io/version: "0.4.5" spec: description: "SysDeck default policy — deny all ingress + egress, then re-allow DNS/SSH/HTTP/HTTPS" endpointSelector: {} ingress: # SSH passes at L3/L4 only: an HTTP L7 filter on port 22 would deny # every non-HTTP byte of an SSH session. - toPorts: - ports: - port: "22" protocol: TCP # HTTP/HTTPS carry the method allow-list — scoped to these ports # alone, never to the whole toPorts block. - toPorts: - ports: - port: "80" protocol: TCP rules: http: - method: "GET" - method: "POST" - method: "HEAD" - port: "443" protocol: TCP rules: http: - method: "GET" - method: "POST" - method: "HEAD" egress: # DNS to kube-dns on Kubernetes deployments. - toEndpoints: - matchLabels: k8s:io.kubernetes.pod.namespace: kube-system k8s-app: kube-dns toPorts: - ports: - port: "53" protocol: UDP - port: "53" protocol: TCP rules: dns: - matchPattern: "*" # DNS to any local resolver on the host network — standalone Cilium # (the documented sysdeck mode) has no kube-dns labels to match. - toEndpoints: - matchLabels: reserved:world toPorts: - ports: - port: "53" protocol: UDP - port: "53" protocol: TCP # Egress to anywhere on SSH/HTTP/HTTPS. - toPorts: - ports: - port: "22" protocol: TCP - port: "80" protocol: TCP - port: "443" protocol: TCP # Egress to public HTTPS (for system updates) — private ranges stay # blocked so endpoints cannot reach internal services uninvited. - toCIDRSet: - cidr: 0.0.0.0/0 except: - 10.0.0.0/8 - 172.16.0.0/12 - 192.168.0.0/16 toPorts: - ports: - port: "443" protocol: TCP