Bootstraps the empty repo into a kubebuilder go/v4 project: group crawl.example.com, version v1alpha1, kind Proxy (namespaced). Keeps the existing module path and preserves the repo's Go/testing/changelog conventions from CLAUDE.md untouched. Drops the scaffolded GitHub Actions workflows since the remote is Gitea, not GitHub. Everything else is default kubebuilder output, unmodified, so later diffs stay reviewable against a known baseline. Full implementation plan: docs/plans/2026-08-07-1747-proxy-operator.md Co-Authored-By: Claude <noreply@anthropic.com>
28 lines
859 B
YAML
28 lines
859 B
YAML
# This NetworkPolicy allows ingress traffic
|
|
# with Pods running on namespaces labeled with 'metrics: enabled'. Only Pods on those
|
|
# namespaces are able to gather data from the metrics endpoint.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: egress-proxies-operator
|
|
app.kubernetes.io/managed-by: kustomize
|
|
name: allow-metrics-traffic
|
|
namespace: system
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
control-plane: controller-manager
|
|
app.kubernetes.io/name: egress-proxies-operator
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
# This allows ingress traffic from any namespace with the label metrics: enabled
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
metrics: enabled # Only from namespaces with this label
|
|
ports:
|
|
- port: 8443
|
|
protocol: TCP
|