【问题标题】:How to allow egress traffic on 443 port (https calls) and block 80 port (http calls)如何允许 443 端口(https 调用)和阻止 80 端口(http 调用)上的出口流量
【发布时间】:2021-09-17 03:37:54
【问题描述】:

我正在为我在 K3s 上的应用实施 kubernetes 网络策略。我想允许egress(从 Pod 对 Internet 的外部调用)端口 443 即 https 调用仅 并拒绝/阻止 @987654324 上的所有出口调用@端口即http。简而言之,允许https 出口呼叫并拒绝http 出口呼叫。
我正在使用以下custom-dns.yaml 文件进行测试:

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: foo-deny-egress
spec:
  podSelector:
    matchLabels:
      app: foo
  policyTypes:
  - Egress
  egress:
  # allow DNS resolution
  - ports:
    - port: 443
      protocol: UDP
    - port: 443
      protocol: TCP

kubectl apply -f custom-dns.yaml 之后我创建并登录到 pod :kubectl run --restart=Never pod-v1 --image=busybox -i -t -l app=foo 并通过命令测试 http 和 https url:

  1. wget https://www.google.com
  2. wget http://drive.google.com/drive/u/0/my-drive

两个 wget 命令都给出了wget: bad address 错误。

但是,当我不应用此网络策略时,相同的 wget 命令正在工作并从相同的 pod 给出以下结果:
i.

        wget https://www.google.com
        Connecting to www.google.com (172.217.167.164:443)
        wget: note: TLS certificate validation not implemented
        saving to 'index.html'
        index.html           100% |******************************************************| 15264  0:00:00 ETA
       'index.html' saved

ii.

wget http://drive.google.com/drive/u/0/my-drive
Connecting to drive.google.com (142.250.192.46:80)
Connecting to drive.google.com (142.250.192.46:443)
wget: note: TLS certificate validation not implemented
Connecting to accounts.google.com (142.250.192.77:443)
saving to 'my-drive'
my-drive             100% |******************************************************| 92019  0:00:00 ETA
'my-drive' saved

iii. Telnet 到 google.com IP 172.217.167.164 与 80 和 443 端口发生

#telnet 172.217.166.164 80
Connected to 172.217.166.164
^]q
# telnet 172.217.166.164 443
Connected to 172.217.166.164
^]

iv. 类似地Telnet 到 drive.com IP 142.250.192.46 与 80 & 443 端口发生

我在这里错过了什么?

【问题讨论】:

    标签: kubernetes kubernetes-pod kubernetes-networkpolicy


    【解决方案1】:
    • 您在帖子中提到的 networkPolicy 只允许 443 上的 https/traffic,但您没有在其中提及任何拒绝 http(端口 80)流量的内容。

    • 有两种方法可以实现:

      • 为出口设置默认拒绝策略

      要么

      • 创建另一个出口策略,拒绝端口 80 上的出口

    【讨论】:

    • 嗨@confusedGenius。因此,通过拒绝所有出口呼叫,并创建另一个出口策略来拒绝端口 80 呼叫,我在哪里接受端口 443 呼叫?您能为此提供一些配置示例吗?
    • 如果我理解正确,他的意思是除了您(正确)创建的allow 策略之外,您还应该创建deny 一个。最方便的方法是“创建另一个出口策略,拒绝端口 80 上的出口”。您不需要实施两种解决方案。
    • 顺便说一句,不错的网络策略在线模拟器,你可以试试。 editor.cilium.io
    猜你喜欢
    • 2014-05-24
    • 2019-02-02
    • 2019-06-23
    • 1970-01-01
    • 2013-02-25
    • 2012-03-06
    • 1970-01-01
    • 1970-01-01
    • 2020-04-23
    相关资源
    最近更新 更多