Cleanup and implement style guidelines. (#18980)

* Reworded paragraphs to reduce ambiguity.
* Added min-kubernetes-server-version metadata.
* Converted yaml to a downloadable resource.
This commit is contained in:
Sharjeel Aziz
2020-02-12 14:06:51 -05:00
committed by GitHub
parent a00f65d84c
commit c8eb9126e9
2 changed files with 46 additions and 48 deletions
@@ -3,6 +3,7 @@ reviewers:
- caseydavenport - caseydavenport
- danwinship - danwinship
title: Declare Network Policy title: Declare Network Policy
min-kubernetes-server-version: v1.8
content_template: templates/task content_template: templates/task
--- ---
{{% capture overview %}} {{% capture overview %}}
@@ -30,7 +31,7 @@ The above list is sorted alphabetically by product name, not by recommendation o
## Create an `nginx` deployment and expose it via a service ## Create an `nginx` deployment and expose it via a service
To see how Kubernetes network policy works, start off by creating an `nginx` deployment. To see how Kubernetes network policy works, start off by creating an `nginx` Deployment.
```console ```console
kubectl create deployment nginx --image=nginx kubectl create deployment nginx --image=nginx
@@ -39,7 +40,7 @@ kubectl create deployment nginx --image=nginx
deployment.apps/nginx created deployment.apps/nginx created
``` ```
And expose it via a service. Expose the Deployment through a Service called `nginx`.
```console ```console
kubectl expose deployment nginx --port=80 kubectl expose deployment nginx --port=80
@@ -49,7 +50,7 @@ kubectl expose deployment nginx --port=80
service/nginx exposed service/nginx exposed
``` ```
This runs a `nginx` pods in the default namespace, and exposes it through a service called `nginx`. The above commands create a Deployment with an nginx Pod and expose the Deployment through a Service named `nginx`. The `nginx` Pod and Deployment are found in the `default` namespace.
```console ```console
kubectl get svc,pod kubectl get svc,pod
@@ -64,59 +65,43 @@ NAME READY STATUS RESTARTS AGE
pod/nginx-701339712-e0qfq 1/1 Running 0 35s pod/nginx-701339712-e0qfq 1/1 Running 0 35s
``` ```
## Test the service by accessing it from another pod ## Test the service by accessing it from another Pod
You should be able to access the new `nginx` service from other pods. To test, access the service from another pod in the default namespace. Make sure you haven't enabled isolation on the namespace. You should be able to access the new `nginx` service from other Pods. To access the `nginx` Service from another Pod in the `default` namespace, start a busybox container:
Start a busybox container, and use `wget` on the `nginx` service:
```console ```console
kubectl run --generator=run-pod/v1 busybox --rm -ti --image=busybox -- /bin/sh kubectl run --generator=run-pod/v1 busybox --rm -ti --image=busybox -- /bin/sh
``` ```
```console In your shell, run the following command:
Waiting for pod default/busybox-472357175-y0m47 to be running, status is Pending, pod ready: false
Hit enter for command prompt ```shell
wget --spider --timeout=1 nginx
```
/ # wget --spider --timeout=1 nginx ```none
Connecting to nginx (10.100.0.16:80) Connecting to nginx (10.100.0.16:80)
/ # remote file exists
``` ```
## Limit access to the `nginx` service ## Limit access to the `nginx` service
Let's say you want to limit access to the `nginx` service so that only pods with the label `access: true` can query it. To do that, create a `NetworkPolicy` that allows connections only from those pods: To limit the access to the `nginx` service so that only Pods with the label `access: true` can query it, create a NetworkPolicy object as follows:
```yaml {{< codenew file="service/networking/nginx-policy.yaml" >}}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: access-nginx
spec:
podSelector:
matchLabels:
app: nginx
ingress:
- from:
- podSelector:
matchLabels:
access: "true"
```
{{< note >}} {{< note >}}
In the case, the label `app=nginx` is automatically added. NetworkPolicy includes a `podSelector` which selects the grouping of Pods to which the policy applies. You can see this policy selects Pods with the label `app=nginx`. The label was automatically added to the Pod in the `nginx` Deployment. An empty `podSelector` selects all pods in the namespace.
{{< /note >}} {{< /note >}}
## Assign the policy to the service ## Assign the policy to the service
Use kubectl to create a NetworkPolicy from the above nginx-policy.yaml file: Use kubectl to create a NetworkPolicy from the above `nginx-policy.yaml` file:
```console ```console
kubectl apply -f nginx-policy.yaml kubectl apply -f https://k8s.io/examples/service/networking/nginx-policy.yaml
``` ```
```none ```none
@@ -124,40 +109,40 @@ networkpolicy.networking.k8s.io/access-nginx created
``` ```
## Test access to the service when access label is not defined ## Test access to the service when access label is not defined
If we attempt to access the nginx Service from a pod without the correct labels, the request will now time out: When you attempt to access the `nginx` Service from a Pod without the correct labels, the request times out:
```console ```console
kubectl run --generator=run-pod/v1 busybox --rm -ti --image=busybox -- /bin/sh kubectl run --generator=run-pod/v1 busybox --rm -ti --image=busybox -- /bin/sh
``` ```
```console In your shell, run the command:
Waiting for pod default/busybox-472357175-y0m47 to be running, status is Pending, pod ready: false
Hit enter for command prompt ```shell
wget --spider --timeout=1 nginx
```
/ # wget --spider --timeout=1 nginx ```none
Connecting to nginx (10.100.0.16:80) Connecting to nginx (10.100.0.16:80)
wget: download timed out wget: download timed out
/ #
``` ```
## Define access label and test again ## Define access label and test again
Create a pod with the correct labels, and you'll see that the request is allowed: You can create a Pod with the correct labels to see that the request is allowed:
```console ```console
kubectl run --generator=run-pod/v1 busybox --rm -ti --labels="access=true" --image=busybox -- /bin/sh kubectl run --generator=run-pod/v1 busybox --rm -ti --labels="access=true" --image=busybox -- /bin/sh
``` ```
```console In your shell, run the command:
Waiting for pod default/busybox-472357175-y0m47 to be running, status is Pending, pod ready: false
Hit enter for command prompt ```shell
wget --spider --timeout=1 nginx
/ # wget --spider --timeout=1 nginx
Connecting to nginx (10.100.0.16:80)
/ #
``` ```
```none
Connecting to nginx (10.100.0.16:80)
remote file exists
```
{{% /capture %}} {{% /capture %}}
@@ -0,0 +1,13 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: access-nginx
spec:
podSelector:
matchLabels:
app: nginx
ingress:
- from:
- podSelector:
matchLabels:
access: "true"