[zh] Update network-policies.md

Signed-off-by: xin.li <xin.li@daocloud.io>
This commit is contained in:
xin.li
2022-04-17 21:22:51 +08:00
parent 09b773966b
commit 69984b9616
2 changed files with 36 additions and 36 deletions
@@ -121,42 +121,7 @@ An example NetworkPolicy might look like this:
下面是一个 NetworkPolicy 的示例: 下面是一个 NetworkPolicy 的示例:
```yaml {{< codenew file="service/networking/networkpolicy.yaml" >}}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: test-network-policy
namespace: default
spec:
podSelector:
matchLabels:
role: db
policyTypes:
- Ingress
- Egress
ingress:
- from:
- ipBlock:
cidr: 172.17.0.0/16
except:
- 172.17.1.0/24
- namespaceSelector:
matchLabels:
project: myproject
- podSelector:
matchLabels:
role: frontend
ports:
- protocol: TCP
port: 6379
egress:
- to:
- ipBlock:
cidr: 10.0.0.0/24
ports:
- protocol: TCP
port: 5978
```
<!-- <!--
POSTing this to the API server for your cluster will have no effect unless your chosen networking solution supports network policy. POSTing this to the API server for your cluster will have no effect unless your chosen networking solution supports network policy.
@@ -0,0 +1,35 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: test-network-policy
namespace: default
spec:
podSelector:
matchLabels:
role: db
policyTypes:
- Ingress
- Egress
ingress:
- from:
- ipBlock:
cidr: 172.17.0.0/16
except:
- 172.17.1.0/24
- namespaceSelector:
matchLabels:
project: myproject
- podSelector:
matchLabels:
role: frontend
ports:
- protocol: TCP
port: 6379
egress:
- to:
- ipBlock:
cidr: 10.0.0.0/24
ports:
- protocol: TCP
port: 5978