summaryrefslogtreecommitdiffstats
path: root/kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml
diff options
context:
space:
mode:
authorDominic Lunanuova <dgl@research.att.com>2018-03-30 02:29:23 +0000
committerDominic Lunanuova <dgl@research.att.com>2018-04-04 16:57:29 +0000
commit50aafc5ef50a1280c9e85d12be3d24104258ae95 (patch)
tree7afe764576247941e036ed1af771dd9e1d07a8b6 /kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml
parentb1f9efe112b56cec2e185d2e649af76726d3ed41 (diff)
Initial chart for dmaap - 2nd attempt
This should conform to new OOM standard helm structure. It starts a directory called dmaap which will hold all dmaap components. But for now it only has buscontroller. Once we get this working, we can add message-router. (see DMAAP-386) Patch 2 gets private postgresql working. I'd prefer to integreate with common postgresql from Tony in a future commit to avoid any immediate delivery timing dependency. Patch 3 corrects some port mapping from service to pod. Change-Id: Id9838d7ddb2ccccfc8b0e3f3b9e50f9b5672c484 Signed-off-by: Dominic Lunanuova <dgl@research.att.com> Issue-ID: DMAAP-117 Signed-off-by: Dominic Lunanuova <dgl@research.att.com>
Diffstat (limited to 'kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml')
-rw-r--r--kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml28
1 files changed, 28 insertions, 0 deletions
diff --git a/kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml b/kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml
new file mode 100644
index 0000000000..92f3b71b15
--- /dev/null
+++ b/kubernetes/dmaap/charts/postgresql/templates/networkpolicy.yaml
@@ -0,0 +1,28 @@
+{{- if .Values.networkPolicy.enabled }}
+kind: NetworkPolicy
+apiVersion: {{ template "postgresql.networkPolicy.apiVersion" . }}
+metadata:
+ name: "{{ template "postgresql.fullname" . }}"
+ labels:
+ app: {{ template "postgresql.fullname" . }}
+ chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
+ release: "{{ .Release.Name }}"
+ heritage: "{{ .Release.Service }}"
+spec:
+ podSelector:
+ matchLabels:
+ app: "{{ template "postgresql.fullname" . }}"
+ ingress:
+ # Allow inbound connections
+ - ports:
+ - port: 5432
+ {{- if not .Values.networkPolicy.allowExternal }}
+ from:
+ - podSelector:
+ matchLabels:
+ {{ template "postgresql.fullname" . }}-client: "true"
+ {{- end }}
+ # Allow prometheus scrapes
+ - ports:
+ - port: 9187
+{{- end }}