aprs.me/k8s/networkpolicy-cluster.yaml
Graham McIntire 0f2195ef9d
Some checks failed
Build and Push / Build and Push Docker Image (push) Failing after 2s
security: CSP nonces, RemoteIp CIDR gating, rate limiting, NetworkPolicies, deadlock fixes
- Content-Security-Policy: nonce-based per-request plug replacing unsafe-inline scripts
- RemoteIp: CIDR-based trust gating via InetCidr, skips forwarded headers from untrusted peers
- Rate limiting: auth pipeline (20/min), LiveView event handlers, existing mobile channel limits
- NetworkPolicy: 4 k8s policies (web ingress, cluster, metrics, egress) for least-privilege networking
- PartitionManager: deadlock retry with exponential backoff in drop_partition
- Tests: reduced parallelism (max_cases 4), packets_test async:false to prevent trigger contention
- k8s: APRS_PASSWORD -> APRS_PASSCODE secretRef, vendor/aprs submodule hardened
2026-07-26 14:04:56 -05:00

22 lines
448 B
YAML

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: aprs-allow-cluster
namespace: aprs
spec:
podSelector:
matchLabels:
app: aprs
policyTypes:
- Ingress
ingress:
# Allow Erlang distribution ports from other aprs pods
- from:
- podSelector:
matchLabels:
app: aprs
ports:
- port: 4369
protocol: TCP
- port: 9000
protocol: TCP