Skip to content

Commit 9faa06a

Browse files
committed
feat(deployment): add network access allowlist for pod identity webhook
1 parent 1d07873 commit 9faa06a

File tree

1 file changed

+2
-0
lines changed
  • charts/internal/seed-controlplane/charts/stackit-pod-identity-webhook/templates

1 file changed

+2
-0
lines changed

charts/internal/seed-controlplane/charts/stackit-pod-identity-webhook/templates/deployment.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,8 @@ spec:
1717
app.kubernetes.io/name: stackit-pod-identity-webhook
1818
workload-identity.stackit.cloud/skip-pod-identity-webhook: "true"
1919
gardener.cloud/role: controlplane
20+
networking.gardener.cloud/to-dns: allowed
21+
networking.resources.gardener.cloud/to-kube-apiserver-tcp-443: allowed
2022
spec:
2123
topologySpreadConstraints:
2224
- maxSkew: 1

0 commit comments

Comments
 (0)