to restrict connections to and from selected pods, namespaces, and the Internet.
to restrict connections to and from selected pods, namespaces, and the Internet.
...
@@ -455,13 +455,13 @@ networkPolicy:
...
@@ -455,13 +455,13 @@ networkPolicy:
enabled:true
enabled:true
```
```
The default policy deployed by the auto deploy pipeline will allow
The default policy deployed by the Auto Deploy pipeline allows
traffic within a local namespace and from the `gitlab-managed-apps`
traffic within a local namespace, and from the `gitlab-managed-apps`
namespace. All other inbound connection will be blocked. Outbound
namespace. All other inbound connections are blocked. Outbound
traffic (for example, to the Internet) is not affected by the default policy.
traffic (for example, to the Internet) is not affected by the default policy.
You can also provide a custom [policy specification](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.16/#networkpolicyspec-v1-networking-k8s-io)
You can also provide a custom [policy specification](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.16/#networkpolicyspec-v1-networking-k8s-io)
via the `.gitlab/auto-deploy-values.yaml` file, for example:
in the `.gitlab/auto-deploy-values.yaml` file, for example:
```yaml
```yaml
networkPolicy:
networkPolicy:
...
@@ -479,16 +479,19 @@ networkPolicy:
...
@@ -479,16 +479,19 @@ networkPolicy:
app.gitlab.com/managed_by:gitlab
app.gitlab.com/managed_by:gitlab
```
```
For more information on how to install Network Policies, see
For more information on installing Network Policies, see
[Install Cilium using GitLab CI/CD](../../user/clusters/applications.md#install-cilium-using-gitlab-cicd).
[Install Cilium using GitLab CI/CD](../../user/clusters/applications.md#install-cilium-using-gitlab-cicd).
### Web Application Firewall (ModSecurity) customization
### Web Application Firewall (ModSecurity) customization
> [Introduced](https://gitlab.com/gitlab-org/charts/auto-deploy-app/-/merge_requests/44) in GitLab 12.8.
> [Introduced](https://gitlab.com/gitlab-org/charts/auto-deploy-app/-/merge_requests/44) in GitLab 12.8.
Customization on an [Ingress](https://kubernetes.io/docs/concepts/services-networking/ingress/) or on a deployment base is available for clusters with [ModSecurity installed](../../user/clusters/applications.md#web-application-firewall-modsecurity).
Customization on an [Ingress](https://kubernetes.io/docs/concepts/services-networking/ingress/)
or on a deployment base is available for clusters with