Skip to content

Host-level network security protection (datapath) #9915

@tgraf

Description

@tgraf

Summary

Protection of the worker node is currently left to the user and is typically done using iptables. The NodePort work has introduced the foundation required to apply security policies to host traffic for both ingress and egress.

Details

TBD

Metadata

Metadata

Labels

area/datapathImpacts bpf/ or low-level forwarding details, including map management and monitor messages.kind/featureThis introduces new functionality.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions