Revert NetworkPolicy v1 docs (#3849)

* Revert "Update configure-namespace-isolation.md (#3758)"

This reverts commit a712b13a3b.

* Revert "Add Configure Namespace Isolation task"

This reverts commit f050c4cc57.

* Revert "Update networkpolicies.md (#3755)"

This reverts commit 15ca8f0b2f.

* Revert "Update NetworkPolicy docs for v1"

This reverts commit 3a158ecf296e3009db1284d69849e7e24479245a.
This commit is contained in:
Dan Winship
2017-05-22 14:54:57 -04:00
committed by Andrew Chen
parent 71ff265e47
commit a58afb2a2e
4 changed files with 48 additions and 68 deletions
@@ -1,51 +0,0 @@
---
assignees:
- thockin
- caseydavenport
- danwinship
title: Configuring Namespace Isolation
---
{% capture overview %}
This page shows how to add `NetworkPolicy` objects to an isolated namespace to specify what traffic should be allowed.
{% endcapture %}
{% capture prerequisites %}
Network policies are implemented by the network plugin, so you must be using a networking solution which supports `NetworkPolicy` - simply creating the resource without a controller to implement it will have no effect.
{% endcapture %}
{% capture steps %}
## Configuring Namespace Isolation
By default, all traffic is allowed between all pods (and `NetworkPolicy` resources have no effect).
Isolation can be configured on a per-namespace basis. Currently, only isolation on inbound traffic (ingress) can be defined. When a namespace has been configured to isolate inbound traffic, all traffic to pods in that namespace (even from other pods in the same namespace) will be blocked. `NetworkPolicy` objects can then be added to the isolated namespace to specify what traffic should be allowed.
Isolation is enabled via the `NetworkPolicy` field of the `Namespace` object. To enable isolation via `kubectl`:
```shell
{% raw %}
kubectl patch ns <namespace> -p '{"spec": {"networkPolicy": {"ingress": {"isolation": "DefaultDeny"}}}}'
{% endraw %}
```
To disable it:
```shell
{% raw %}
kubectl patch ns <namespace> -p '{"spec": {"networkPolicy": null}}'
{% endraw %}
```
NOTE: older network plugins may instead require the v1beta1 syntax, using an annotation:
```shell
{% raw %}
kubectl annotate ns <namespace> "net.beta.kubernetes.io/network-policy={\"ingress\": {\"isolation\": \"DefaultDeny\"}}"
{% endraw %}
```
{% endcapture %}
{% capture whatsnext %}
* For conceptual information about Network Policies, see [Network Policies](/docs/concepts/services-networking/networkpolicies).
{% endcapture %}
{% include templates/task.md %}
@@ -1,7 +1,6 @@
---
assignees:
- caseydavenport
- danwinship
title: Declaring Network Policy
redirect_from:
- "/docs/getting-started-guides/network-policy/walkthrough/"
@@ -72,7 +71,7 @@ Connecting to nginx (10.100.0.16:80)
Let's say you want to limit access to the `nginx` service so that only pods with the label `access: true` can query it. The first step is to enable ingress isolation on the `default` namespace. This prevents **_any_** pods from accessing the `nginx` service.
```console
$ kubectl patch ns default -p '{"spec": {"networkPolicy": {"ingress": {"isolation": "DefaultDeny"}}}}'
$ kubectl annotate ns default "net.beta.kubernetes.io/network-policy={\"ingress\": {\"isolation\": \"DefaultDeny\"}}"
```
## Test the access limitation
@@ -97,7 +96,7 @@ Next, create a `NetworkPolicy` that allows connections from pods with the label
```yaml
kind: NetworkPolicy
apiVersion: networking/v1
apiVersion: extensions/v1beta1
metadata:
name: access-nginx
spec: