Closed rgolangh closed 1 month ago
/hold last checks before I'm merging
I'm holding this work to make use of a more efficient single label selector -https://github.com/apache/incubator-kie-kogito-serverless-operator/pull/482
I think we may want to make this work a document instead of something the chart will set, here's why:
app.kubernetes.io/component=serverless-workflow
AND from backstage backend.
If there is a case where a mix of cluster platform and namespaced platform is supported(is it?) , then during the namespaced platform installation the network policy to isolate the ns should will prevent ingress but will the sonataflow-infra
namespace will remain open to calls from the platform namespaces.After revisiting this we can rely on the installation using hack/setup.sh to create a workflow namespace with a label.
So this means that the helm chart knows what is the name of all three participating namespaces - workflows, sonata, and rhdh and that is a good start.
If other workflows are deployed in a different namespace then this namespace must be labelled with rhdh.redhat.com/workflow-namespace
should be a disallow all traffic, and after that allow that one, no? If not is not blocking at all.
@eloycoto according to the docs and according to my tests this works. pods outside of the specified namespaces can not reach the target namespaces
@masayag I can't reproduce the helm lint error locally. any clue?
Signed-off-by: Roy Golan rgolan@redhat.com