【发布时间】:2021-09-17 03:37:54
【问题描述】:
我正在为我在 K3s 上的应用实施 kubernetes 网络策略。我想允许egress(从 Pod 对 Internet 的外部调用)端口 443 即 https 调用仅 并拒绝/阻止 @987654324 上的所有出口调用@端口即http。简而言之,允许https 出口呼叫并拒绝http 出口呼叫。
我正在使用以下custom-dns.yaml 文件进行测试:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: foo-deny-egress
spec:
podSelector:
matchLabels:
app: foo
policyTypes:
- Egress
egress:
# allow DNS resolution
- ports:
- port: 443
protocol: UDP
- port: 443
protocol: TCP
kubectl apply -f custom-dns.yaml 之后我创建并登录到 pod :kubectl run --restart=Never pod-v1 --image=busybox -i -t -l app=foo 并通过命令测试 http 和 https url:
wget https://www.google.com-
wget http://drive.google.com/drive/u/0/my-drive
两个 wget 命令都给出了wget: bad address 错误。
但是,当我不应用此网络策略时,相同的 wget 命令正在工作并从相同的 pod 给出以下结果:
i.
wget https://www.google.com
Connecting to www.google.com (172.217.167.164:443)
wget: note: TLS certificate validation not implemented
saving to 'index.html'
index.html 100% |******************************************************| 15264 0:00:00 ETA
'index.html' saved
ii.
wget http://drive.google.com/drive/u/0/my-drive
Connecting to drive.google.com (142.250.192.46:80)
Connecting to drive.google.com (142.250.192.46:443)
wget: note: TLS certificate validation not implemented
Connecting to accounts.google.com (142.250.192.77:443)
saving to 'my-drive'
my-drive 100% |******************************************************| 92019 0:00:00 ETA
'my-drive' saved
iii. Telnet 到 google.com IP 172.217.167.164 与 80 和 443 端口发生
#telnet 172.217.166.164 80
Connected to 172.217.166.164
^]q
# telnet 172.217.166.164 443
Connected to 172.217.166.164
^]
iv. 类似地Telnet 到 drive.com IP 142.250.192.46 与 80 & 443 端口发生
我在这里错过了什么?
【问题讨论】:
标签: kubernetes kubernetes-pod kubernetes-networkpolicy