Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-9307

[Network Policy support] Tailored Network Policies for Quay team-owned Operators

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected

      Feature Overview (aka. Goal Summary)  

      This effort supports OCPSTRAT-819. 

      • All OpenShift Operators, including OLM-managed products, are expected to ensure required network policies are in place.

      Goals (aka. expected user outcomes)

      • Develop and test tight ingress and egress K8s Network Policies to restrict communication to only the necessary communication.
      • Apply the network policies during the operator installation and upgrade.

      Requirements (aka. Acceptance criteria):

      • The focus of this initial phase is on adding a tailored Network Policy for the Operator controller itself.  Apply network policies during operator installation and upgrade. 
      • The Network Policy for the Custom Resources (i.e., Operands) is out of scope in this initial phase. 

      List any affected packages or components.

      Operators owned by the Quay engineering team:

      • Quay Operator Quay 
      • Container Security Operator 
      • Quay Bridge Operator

      Relevant resources:

      Other Operator teams:

      • OCPSTRAT-1969 [LVM Storage] Network Policies for OpenShift layered Components
      • OCPSTRAT-2211 Tailored Network Policies for Cluster Infrastructure team owned Operators
      • VIRTSTRAT-103 [VIRT] Protect from unintended data leaks / attacks via tailored Network Policies
      • ACM-19479 Protect from unintended data leaks / attacks via tailored Network Policies
      • OBSDA-1022 Tailored Network Policies for Cluster Logging Operator
      • SECFLOWOTL-273 Builds for OpenShift Network Policies
      • OCPSTRAT-2057 Secondary Scheduler Operator : Protect from unintended data leaks / attacks via tailored Network Policies

              Unassigned Unassigned
              rhn-coreos-tunwu Tony Wu
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: