千萬(wàn)別泄漏IP,否則Boom

k8s僅添加cdn的白名單。如果感興趣可以仔細(xì)看下iptables的具體流向。 --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: dk8s-svc-policy spec: podSelector: matchLabels: app: dk8s-svc policyTypes: - Ingress ingress: - from: - ipBlock: cidr: 192.168.0.0/16 - ipBlock: cidr: 172.16.0.0/12 - ipBlock: cidr: 10.0.0.0/8 - ipBlock: cidr: 101.33.1.0/24 - ipBlock: cidr: 101.33.10.0/24 - ipBlock: cidr: 101.33.12.0/24 # cdn網(wǎng)段 ports: - protocol: TCP port: 80 - protocol: TCP port: 443
標(biāo)簽:
千萬(wàn)別泄漏IP,否則Boom的評(píng)論 (共 條)
