metal-stack / firewall-controller

A kubernetes controller running on bare-metal firewalls, creating nftables rules, configures suricata, collects network metrics
MIT License
47 stars 4 forks source link

documentation about automatic ingress rules for services is missing #47

Closed mwennrich closed 4 years ago

mwennrich commented 4 years ago

More documentation is needed about the automatic ingress rules for k8s services:

https://github.com/metal-stack/firewall-controller/blob/2e74932720fcf1c8bd15dd93603546baab1e3cc1/pkg/nftables/firewall.go#L58

maybe with an example, how these can be modified afterward to be more restrictive