gpt4 book ai didi

kubernetes 网络策略 - 导出策略不会阻止流量流出

转载 作者:行者123 更新时间:2023-12-01 04:33:59 25 4
gpt4 key购买 nike

这是我的网络政策:

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: deny
namespace: openstack
spec:
podSelector:
matchLabels: {}
policyTypes:
- Egress
- Ingress
我应用此策略并登录到 1 个 pod,它仍然可以连接到 google.com。
——
-2018-08-29 11:36:33--  http://google.com/
Resolving google.com (google.com)... 172.217.4.46, 2607:f8b0:4009:804::200e
Connecting to google.com (google.com)|172.217.4.46|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://www.google.com/ [following]
--2018-08-29 11:36:33-- http://www.google.com/
Resolving www.google.com (www.google.com)... 172.217.4.36, 2607:f8b0:4009:804::2004
Connecting to www.google.com (www.google.com)|172.217.4.36|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: unspecified [text/html]
Saving to: ‘index.html.85’

index.html.85 [ <=> ] 11.09K --.-KB/s in 0.001s

2018-08-29 11:36:33 (7.77 MB/s) - ‘index.html.85’ saved [11355]
有谁可以解释为什么导出不起作用?谢谢

最佳答案

使用前 NetworkPolicy ,你需要安装一个CNI支持网络策略的插件。

我用 Weave Net ,但您可以使用其他一些:

https://kubernetes.io/docs/tasks/administer-cluster/network-policy-provider/weave-network-policy/

https://kubernetes.io/docs/tasks/administer-cluster/declare-network-policy/

关于kubernetes 网络策略 - 导出策略不会阻止流量流出,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/52082344/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com