Add kubeflow/v1.10.0

This commit is contained in:
wbsong111
2025-06-24 12:03:10 +09:00
parent 0132496142
commit 6e8dd89e48
1531 changed files with 120984 additions and 262120 deletions
@@ -1,8 +1,8 @@
### 1. Why would a user apply the extra policies?
It is a second line of defence after Istio autorization policies and it protects pods and services that are not protected by Istio
It is a second line of defence after Istio authorization policies and it protects pods and services that are not protected by Istio.
### 2. Effects they will have in the cluster
Please consult the name of and comments in each networkpolicy for further information.
### 3. We should achieve the same with AuthorizationPolicies
But there are components, e.g. Katib that are not secured by istio
But there are components, e.g. Katib that are not secured by istio.
@@ -2,24 +2,25 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: kubeflow
resources:
- cache-server.yaml
- centraldashboard.yaml
- default-allow-same-namespace.yaml
- jupyter-web-app.yaml
- katib-controller.yaml
- katib-db-manager.yaml
- katib-ui.yaml
- kserve-models-web-app.yaml
- kserve.yaml
- metadata-envoy.yaml
- metadata-grpc-server.yaml
- minio.yaml
- ml-pipeline-ui.yaml
- ml-pipeline.yaml
- model-registry.yaml
- poddefaults.yaml
- pvcviewer-webhook.yaml
- seldon.yaml
- tensorboards-web-app.yaml
- training-operator-webhook.yaml
- volumes-web-app.yaml
- cache-server.yaml
- centraldashboard.yaml
- default-allow-same-namespace.yaml
- jupyter-web-app.yaml
- katib-controller.yaml
- katib-db-manager.yaml
- katib-ui.yaml
- kserve-models-web-app.yaml
- kserve.yaml
- metadata-envoy.yaml
- metadata-grpc-server.yaml
- minio.yaml
- ml-pipeline-ui.yaml
- ml-pipeline.yaml
- model-registry.yaml
- model-registry-ui.yaml
- poddefaults.yaml
- pvcviewer-webhook.yaml
- spark-operator-webhook.yaml
- tensorboards-web-app.yaml
- training-operator-webhook.yaml
- volumes-web-app.yaml
@@ -0,0 +1,23 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: model-registry-ui
namespace: kubeflow
spec:
podSelector:
matchExpressions:
- key: app
operator: In
values:
- model-registry-ui
ingress:
- from:
- namespaceSelector:
matchExpressions:
- key: kubernetes.io/metadata.name
operator: In
values:
- istio-system
- podSelector: {}
policyTypes:
- Ingress
@@ -1,20 +1,24 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
apiVersion: networking.k8s.io/v1
metadata:
name: seldon
name: spark-operator-webhook
namespace: kubeflow
spec:
podSelector:
matchExpressions:
- key: control-plane
operator: In
values:
- seldon-controller-manager # validating webhook
- key: app.kubernetes.io/name
operator: In
values:
- spark-operator
- key: app.kubernetes.io/component
operator: In
values:
- webhook
# https://www.elastic.co/guide/en/cloud-on-k8s/1.1/k8s-webhook-network-policies.html
# The kubernetes api server must reach the webhook
ingress:
- ports:
- protocol: TCP
port: 4443
- ports:
- protocol: TCP
port: 9443
policyTypes:
- Ingress
- Ingress
@@ -13,8 +13,8 @@ spec:
# https://www.elastic.co/guide/en/cloud-on-k8s/1.1/k8s-webhook-network-policies.html
# The kubernetes api server must reach the webhook
ingress:
- ports:
- protocol: TCP
port: 9443
- ports:
- protocol: TCP
port: 9443
policyTypes:
- Ingress
- Ingress