← Policy catalog
</> NetworkPolicy · Apache-2.0

Allow Egress to Kube DNS

networkpolicy-allow-traffic-to-kube-dns

productKubernetes

Allow DNS egress (TCP/UDP 53) to kube-dns/coredns in kube-system.

What this is

A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.

Manifest

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-traffic-to-kube-dns
  annotations:
    cenroq.io/displayName: "Allow Egress to Kube DNS"
    cenroq.io/description: "Allow DNS egress (TCP/UDP 53) to kube-dns/coredns in kube-system."
spec:
  podSelector: {}
  policyTypes:
  - Egress
  egress:
  - to:
    - namespaceSelector:
        matchLabels:
          kubernetes.io/metadata.name: kube-system
      podSelector:
        matchExpressions:
        - key: k8s-app
          operator: In
          values:
          - kube-dns
          - coredns
    ports:
    - protocol: UDP
      port: 53
    - protocol: TCP
      port: 53

Save it as networkpolicy-allow-traffic-to-kube-dns.yaml — the commands below assume that name.

Apply it

This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:

$ kubectl apply -f ./networkpolicy-allow-traffic-to-kube-dns.yaml