networkpolicy-deny-any-any
Deny all ingress and egress traffic for all pods in the namespace.
A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: deny-any-any
annotations:
cenroq.io/displayName: "Deny All Traffic"
cenroq.io/description: "Deny all ingress and egress traffic for all pods in the namespace."
spec:
podSelector: {}
policyTypes:
- Ingress
- EgressSave it as networkpolicy-deny-any-any.yaml — the commands below assume that name.
This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:
$ kubectl apply -f ./networkpolicy-deny-any-any.yaml