SysDeck/firewall/policies/cilium-default.yaml

103 lines
3.2 KiB
YAML
Executable File

# Cilium default network policy — shipped with the SysDeck firewall module.
# Author: Jeremy Anderson <info@dcos.net>
#
# This policy is applied by firewall/templates/cilium.sh `start` action
# when the operator selects the Cilium backend in the SysDeck Firewall
# panel. It implements a sensible default:
#
# - default-deny ingress + egress at the cluster level
# - allow DNS (UDP/TCP 53) to kube-dns (K8s) or any local resolver
# (standalone installs run systemd-resolved without kube labels)
# - allow SSH (TCP 22) from anywhere — no L7 parser on port 22
# - allow HTTP/HTTPS (TCP 80/443) from anywhere, with the HTTP
# method allow-list scoped to 80/443 only
#
# Operators can drop a custom policy at
# /etc/sysdeck/firewall/cilium-policy.yaml to override.
#
# Reference: https://docs.cilium.io/en/stable/security/policy/
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: sysdeck-default-deny
namespace: default
annotations:
sysdeck.io/managed-by: "sysdeck-firewall-cilium"
sysdeck.io/version: "0.4.5"
spec:
description: "SysDeck default policy — deny all ingress + egress, then re-allow DNS/SSH/HTTP/HTTPS"
endpointSelector: {}
ingress:
# SSH passes at L3/L4 only: an HTTP L7 filter on port 22 would deny
# every non-HTTP byte of an SSH session.
- toPorts:
- ports:
- port: "22"
protocol: TCP
# HTTP/HTTPS carry the method allow-list — scoped to these ports
# alone, never to the whole toPorts block.
- toPorts:
- ports:
- port: "80"
protocol: TCP
rules:
http:
- method: "GET"
- method: "POST"
- method: "HEAD"
- port: "443"
protocol: TCP
rules:
http:
- method: "GET"
- method: "POST"
- method: "HEAD"
egress:
# DNS to kube-dns on Kubernetes deployments.
- toEndpoints:
- matchLabels:
k8s:io.kubernetes.pod.namespace: kube-system
k8s-app: kube-dns
toPorts:
- ports:
- port: "53"
protocol: UDP
- port: "53"
protocol: TCP
rules:
dns:
- matchPattern: "*"
# DNS to any local resolver on the host network — standalone Cilium
# (the documented sysdeck mode) has no kube-dns labels to match.
- toEndpoints:
- matchLabels:
reserved:world
toPorts:
- ports:
- port: "53"
protocol: UDP
- port: "53"
protocol: TCP
# Egress to anywhere on SSH/HTTP/HTTPS.
- toPorts:
- ports:
- port: "22"
protocol: TCP
- port: "80"
protocol: TCP
- port: "443"
protocol: TCP
# Egress to public HTTPS (for system updates) — private ranges stay
# blocked so endpoints cannot reach internal services uninvited.
- toCIDRSet:
- cidr: 0.0.0.0/0
except:
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
toPorts:
- ports:
- port: "443"
protocol: TCP