networkpolicy-allow-traffic-to-kube-dns
Allow DNS egress (TCP/UDP 53) to kube-dns/coredns in kube-system.
A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-traffic-to-kube-dns
annotations:
cenroq.io/displayName: "Allow Egress to Kube DNS"
cenroq.io/description: "Allow DNS egress (TCP/UDP 53) to kube-dns/coredns in kube-system."
spec:
podSelector: {}
policyTypes:
- Egress
egress:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
podSelector:
matchExpressions:
- key: k8s-app
operator: In
values:
- kube-dns
- coredns
ports:
- protocol: UDP
port: 53
- protocol: TCP
port: 53Save it as networkpolicy-allow-traffic-to-kube-dns.yaml — the commands below assume that name.
This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:
$ kubectl apply -f ./networkpolicy-allow-traffic-to-kube-dns.yaml