add policies

This commit is contained in:
Peter 2026-05-08 11:47:53 +02:00
parent 856e86fd51
commit e8df03cd18
Signed by: Peter
SSH key fingerprint: SHA256:B5tYaxBExaDm74r1px9iVeZ6F/ZDiyiy9SbBqfZYrvg
3 changed files with 22 additions and 2 deletions

View file

@ -6,7 +6,7 @@ namespace: renovate-operator
resources: resources:
- configmap.yaml - configmap.yaml
- namespace.yaml - namespace.yaml
# - policies.yaml - policies.yaml
- renovate-job.yaml - renovate-job.yaml
- secrets.yaml - secrets.yaml

View file

@ -15,3 +15,23 @@ spec:
- 10.0.0.0/8 - 10.0.0.0/8
- 192.168.0.0/16 - 192.168.0.0/16
- 172.16.0.0/12 - 172.16.0.0/12
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: api-server-egress
spec:
podSelector: {}
policyTypes:
- Egress
egress:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
- podSelector:
matchLabels:
k8s-app: kube-apiserver
- ports:
- protocol: TCP
port: 6443

View file

@ -16,7 +16,7 @@ spec:
remoteRef: remoteRef:
key: /secrets/managed/renovate/token key: /secrets/managed/renovate/token
property: RENOVATE_TOKEN property: RENOVATE_TOKEN
- secretKey: GITHUB_TOKEN - secretKey: GITHUB_COM_TOKEN
remoteRef: remoteRef:
key: /secrets/managed/renovate/token key: /secrets/managed/renovate/token
property: GITHUB_COM_TOKEN property: GITHUB_COM_TOKEN