103 lines
3.2 KiB
YAML
Executable File
103 lines
3.2 KiB
YAML
Executable File
# Cilium default network policy — shipped with the SysDeck firewall module.
|
|
# Author: Jeremy Anderson <info@dcos.net>
|
|
#
|
|
# This policy is applied by firewall/templates/cilium.sh `start` action
|
|
# when the operator selects the Cilium backend in the SysDeck Firewall
|
|
# panel. It implements a sensible default:
|
|
#
|
|
# - default-deny ingress + egress at the cluster level
|
|
# - allow DNS (UDP/TCP 53) to kube-dns (K8s) or any local resolver
|
|
# (standalone installs run systemd-resolved without kube labels)
|
|
# - allow SSH (TCP 22) from anywhere — no L7 parser on port 22
|
|
# - allow HTTP/HTTPS (TCP 80/443) from anywhere, with the HTTP
|
|
# method allow-list scoped to 80/443 only
|
|
#
|
|
# Operators can drop a custom policy at
|
|
# /etc/sysdeck/firewall/cilium-policy.yaml to override.
|
|
#
|
|
# Reference: https://docs.cilium.io/en/stable/security/policy/
|
|
|
|
apiVersion: cilium.io/v2
|
|
kind: CiliumNetworkPolicy
|
|
metadata:
|
|
name: sysdeck-default-deny
|
|
namespace: default
|
|
annotations:
|
|
sysdeck.io/managed-by: "sysdeck-firewall-cilium"
|
|
sysdeck.io/version: "0.4.5"
|
|
spec:
|
|
description: "SysDeck default policy — deny all ingress + egress, then re-allow DNS/SSH/HTTP/HTTPS"
|
|
endpointSelector: {}
|
|
ingress:
|
|
# SSH passes at L3/L4 only: an HTTP L7 filter on port 22 would deny
|
|
# every non-HTTP byte of an SSH session.
|
|
- toPorts:
|
|
- ports:
|
|
- port: "22"
|
|
protocol: TCP
|
|
# HTTP/HTTPS carry the method allow-list — scoped to these ports
|
|
# alone, never to the whole toPorts block.
|
|
- toPorts:
|
|
- ports:
|
|
- port: "80"
|
|
protocol: TCP
|
|
rules:
|
|
http:
|
|
- method: "GET"
|
|
- method: "POST"
|
|
- method: "HEAD"
|
|
- port: "443"
|
|
protocol: TCP
|
|
rules:
|
|
http:
|
|
- method: "GET"
|
|
- method: "POST"
|
|
- method: "HEAD"
|
|
egress:
|
|
# DNS to kube-dns on Kubernetes deployments.
|
|
- toEndpoints:
|
|
- matchLabels:
|
|
k8s:io.kubernetes.pod.namespace: kube-system
|
|
k8s-app: kube-dns
|
|
toPorts:
|
|
- ports:
|
|
- port: "53"
|
|
protocol: UDP
|
|
- port: "53"
|
|
protocol: TCP
|
|
rules:
|
|
dns:
|
|
- matchPattern: "*"
|
|
# DNS to any local resolver on the host network — standalone Cilium
|
|
# (the documented sysdeck mode) has no kube-dns labels to match.
|
|
- toEndpoints:
|
|
- matchLabels:
|
|
reserved:world
|
|
toPorts:
|
|
- ports:
|
|
- port: "53"
|
|
protocol: UDP
|
|
- port: "53"
|
|
protocol: TCP
|
|
# Egress to anywhere on SSH/HTTP/HTTPS.
|
|
- toPorts:
|
|
- ports:
|
|
- port: "22"
|
|
protocol: TCP
|
|
- port: "80"
|
|
protocol: TCP
|
|
- port: "443"
|
|
protocol: TCP
|
|
# Egress to public HTTPS (for system updates) — private ranges stay
|
|
# blocked so endpoints cannot reach internal services uninvited.
|
|
- toCIDRSet:
|
|
- cidr: 0.0.0.0/0
|
|
except:
|
|
- 10.0.0.0/8
|
|
- 172.16.0.0/12
|
|
- 192.168.0.0/16
|
|
toPorts:
|
|
- ports:
|
|
- port: "443"
|
|
protocol: TCP
|