apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: api-gateway namespace: api labels: app: api-gateway spec: podSelector: matchLabels: app: api-gateway policyTypes: - Ingress - Egress ingress: # Allow from ingress-nginx controller (from ingress-nginx namespace) - from: - namespaceSelector: matchLabels: name: ingress-nginx ports: - protocol: TCP port: 8080 # Allow from Prometheus scraping (if in monitoring namespace) - from: - namespaceSelector: matchLabels: name: monitoring ports: - protocol: TCP port: 8080 # Allow from poimen namespace (orchestrator & worker pods) # Enable Poimen workflows to call the LLM API gateway - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: poimen ports: - protocol: TCP port: 8080 egress: # Allow DNS - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: kube-system ports: - protocol: UDP port: 53 - protocol: TCP port: 53 # Allow to upstreams (LLM services in llm-serving namespace) - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: llm-serving ports: - protocol: TCP port: 80 - protocol: TCP port: 8000 - protocol: TCP port: 8001 # Allow to other upstreams if needed (embeddings, reranker, etc.) - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: llm-serving ports: - protocol: TCP port: 8080 # Allow to atlas (riotpiao-backend) for /cluster/* routes - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: atlas ports: - protocol: TCP port: 8080