Files
service-catalog/manifests/helm/keycloakx/7.3.0/templates/networkpolicy.yaml
T
wbsong111 fae1ec2668 keycloakx 차트를 7.2.2에서 7.3.0으로 업그레이드한다
breaking_change_check 결과 breaking=false — custom-values.yaml이 실제로 쓰는 키
(image, http.relativePath, command, ingress, proxy, resources, database, extraEnv)
중 어느 것도 diff에 걸리지 않았다. 유일한 템플릿 변경(probe 경로가
managementRelativePath를 coalesce로 우선하도록 바뀜)도 relativePath: "/" 를 그대로
쓰므로 동작 영향이 없다. CRD·의존성 변경 없음.

appVersion은 26.6.4→26.7.2로 오르지만 custom-values.yaml이 자체 빌드 이미지
태그(26.7.1-bci15.7-hardened)를 명시적으로 고정하므로 이 업그레이드로 실제 배포
버전이 바뀌지는 않는다 — 26.7.2로 올리려면 hardened-containers에서 별도로
자체 빌드해야 한다.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-26 11:18:14 +09:00

53 lines
1.5 KiB
YAML

{{- if .Values.networkPolicy.enabled }}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "keycloak.fullname" . | quote }}
namespace: {{ include "keycloak.namespace" . }}
labels:
{{- include "keycloak.labels" . | nindent 4 }}
{{- range $key, $value := .Values.networkPolicy.labels }}
{{- printf "%s: %s" $key (tpl $value $ | quote) | nindent 4 }}
{{- end }}
spec:
policyTypes:
- Ingress
{{- if .Values.networkPolicy.egress }}
- Egress
{{- end}}
podSelector:
matchLabels:
{{- include "keycloak.selectorLabels" . | nindent 6 }}
ingress:
{{- with .Values.networkPolicy.extraFrom }}
- from:
{{- toYaml . | nindent 8 }}
ports:
- protocol: TCP
port: 8080
- protocol: TCP
port: 8443
{{ range $.Values.extraPorts }}
- protocol: {{ default "TCP" .protocol }}
port: {{ .containerPort }}
{{- end }}
{{- end }}
- from:
- podSelector:
matchLabels:
{{- include "keycloak.selectorLabels" . | nindent 14 }}
ports:
- protocol: TCP
port: 8080
- protocol: TCP
port: 8443
{{ range .Values.extraPorts }}
- protocol: {{ default "TCP" .protocol }}
port: {{ .containerPort }}
{{- end }}
{{- if .Values.networkPolicy.egress }}
egress:
{{- .Values.networkPolicy.egress | toYaml | nindent 4 }}
{{- end }}
{{- end }}