-
Epic
-
Resolution: Done
-
Major
-
None
-
OLMv0 Network Policies
-
Product / Portfolio Work
-
0% To Do, 0% In Progress, 100% Done
-
False
-
-
False
-
Not Selected
-
None
-
None
-
12
OCP/Telco Definition of Done
Epic Template descriptions and documentation.
<--- Cut-n-Paste the entire contents of this description into your new Epic --->
Epic Goal
- ...
Why is this important?
- …
Scenarios
- ...
Acceptance Criteria
- openshift-operators namespace has a default allow-all NetworkPolicy
- openshift-operator-lifecycle-manager namespace has:
- default deny-all NetworkPolicy for all pods in the namespace
- NetworkPolicy for catalog-operator
- NetworkPolicy for olm-operator
- NetworkPolicy for package server
- NetworkPolicy for package server manager (downstream-only)
- openshift-marketplace namespace has:
- default deny-all NetworkPolicy for all pods in the namespace
- NetworkPolicy for marketplace-operator
- NetworkPolicy is generated automatically for CatalogSource operands
- A network policy exists for each GRPC server pod allowing only ingress to port 50051
- A network policy exists that covers all bundle unpack pods derived from a particular CatalogSource that allows only egress to the kubernetes apiserver
Dependencies (internal and external)
- ...
Previous Work (Optional):
- …
Open questions::
- …
Done Checklist
- CI - CI is running, tests are automated and merged.
- Release Enablement <link to Feature Enablement Presentation>
- DEV - Upstream code and tests merged: <link to meaningful PR or GitHub Issue>
- DEV - Upstream documentation merged: <link to meaningful PR or GitHub Issue>
- DEV - Downstream build attached to advisory: <link to errata>
- QE - Test plans in Polarion: <link or reference to Polarion>
- QE - Automated tests merged: <link or reference to automated tests>
- DOC - Downstream documentation merged: <link to meaningful PR>
- is related to
-
OPRUN-3870 [OLM v1] static network policies for controllers
-
- Release Pending
-
- links to