Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018BAUeCFpDkRD6tU5wGsc1C
240 lines
5.9 KiB
YAML
240 lines
5.9 KiB
YAML
# =============================================================================
|
|
# Politiques reseau
|
|
# =============================================================================
|
|
# k3s applique nativement les NetworkPolicy (controleur kube-router embarque).
|
|
#
|
|
# Objectif : qu'un pod compromis ne puisse ni etre joint par n'importe qui, ni
|
|
# se servir du cluster comme point de rebond vers le reseau prive Hetzner.
|
|
# Sans ces regles, tout pod peut joindre tout pod ET toute IP privee.
|
|
|
|
---
|
|
# --- Refus par defaut, entrant ET sortant -----------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: default-deny
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes: [Ingress, Egress]
|
|
|
|
---
|
|
# --- Resolution DNS (indispensable, sinon plus rien ne fonctionne) ----------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-dns
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes: [Egress]
|
|
egress:
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
ports:
|
|
- protocol: UDP
|
|
port: 53
|
|
- protocol: TCP
|
|
port: 53
|
|
|
|
---
|
|
# --- Trafic entrant depuis l'ingress ----------------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-ingress-from-traefik
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values: [xpeditis-backend, xpeditis-frontend]
|
|
policyTypes: [Ingress]
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
ports:
|
|
- protocol: TCP
|
|
port: 4000
|
|
- protocol: TCP
|
|
port: 3000
|
|
|
|
---
|
|
# --- Le backend ecrit dans le log-exporter ----------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-backend-to-log-exporter
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: xpeditis-log-exporter
|
|
policyTypes: [Ingress]
|
|
ingress:
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: xpeditis-backend
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3200
|
|
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-egress-to-log-exporter
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: xpeditis-backend
|
|
policyTypes: [Egress]
|
|
egress:
|
|
- to:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: xpeditis-log-exporter
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3200
|
|
|
|
---
|
|
# --- Le log-exporter pousse vers Loki ---------------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-log-exporter-to-loki
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: xpeditis-log-exporter
|
|
policyTypes: [Egress]
|
|
egress:
|
|
- to:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: monitoring
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
|
|
---
|
|
# --- Acces a PostgreSQL et Redis sur db-01 ----------------------------------
|
|
# Une seule IP, deux ports. Tout autre acces au reseau prive est refuse : un
|
|
# backend compromis ne peut pas scanner 10.10.0.0/16.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-egress-to-data-node
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values: [xpeditis-backend, xpeditis-migrate]
|
|
policyTypes: [Egress]
|
|
egress:
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 10.10.1.20/32
|
|
ports:
|
|
- protocol: TCP
|
|
port: 5432
|
|
- protocol: TCP
|
|
port: 6379
|
|
|
|
---
|
|
# --- Sorties Internet (Stripe, Brevo, Object Storage, Pappers, carriers) ----
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-egress-internet
|
|
namespace: xpeditis-prod
|
|
spec:
|
|
podSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values: [xpeditis-backend, xpeditis-frontend, xpeditis-migrate]
|
|
policyTypes: [Egress]
|
|
egress:
|
|
- to:
|
|
- ipBlock:
|
|
cidr: 0.0.0.0/0
|
|
# Tout l'espace prive est exclu : la sortie ne sert qu'a joindre
|
|
# des services publics, jamais l'infrastructure interne.
|
|
except:
|
|
- 10.0.0.0/8
|
|
- 172.16.0.0/12
|
|
- 192.168.0.0/16
|
|
- 169.254.0.0/16 # metadonnees cloud
|
|
ports:
|
|
- protocol: TCP
|
|
port: 443
|
|
- protocol: TCP
|
|
port: 80
|
|
- protocol: TCP
|
|
port: 587 # SMTP soumission (Brevo)
|
|
|
|
---
|
|
# --- Namespace monitoring ----------------------------------------------------
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: default-deny
|
|
namespace: monitoring
|
|
spec:
|
|
podSelector: {}
|
|
policyTypes: [Ingress]
|
|
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-loki-writes
|
|
namespace: monitoring
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: loki
|
|
policyTypes: [Ingress]
|
|
ingress:
|
|
# Promtail (meme namespace) et le log-exporter applicatif.
|
|
- from:
|
|
- podSelector: {}
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: xpeditis-prod
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3100
|
|
|
|
---
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: allow-grafana-from-traefik
|
|
namespace: monitoring
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: grafana
|
|
policyTypes: [Ingress]
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: kube-system
|
|
ports:
|
|
- protocol: TCP
|
|
port: 3000
|