apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: api-gateway namespace: api labels: app: api-gateway spec: podSelector: matchLabels: app: api-gateway policyTypes: - Ingress - Egress ingress: # Allow from ingress-nginx controller (from ingress-nginx namespace) - from: - namespaceSelector: matchLabels: name: ingress-nginx ports: - protocol: TCP port: 8080 # Allow from Prometheus scraping (if in monitoring namespace) - from: - namespaceSelector: matchLabels: name: monitoring ports: - protocol: TCP port: 8080 egress: # Allow Kubernetes API server (ServiceAdapter CRD loader) # ClusterIP VIP (10.96.0.1:443) + real control-plane endpoints (port 6443) - to: - ipBlock: cidr: 10.96.0.1/32 ports: - protocol: TCP port: 443 - to: - ipBlock: cidr: 192.168.1.0/24 ports: - protocol: TCP port: 6443 # Allow DNS - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: kube-system ports: - protocol: UDP port: 53 - protocol: TCP port: 53 # Allow to upstreams (LLM services in llm-serving namespace) - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: llm-serving ports: - protocol: TCP port: 80 - protocol: TCP port: 8000 - protocol: TCP port: 8001 # Allow to other upstreams if needed (embeddings, reranker, etc.) - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: llm-serving ports: - protocol: TCP port: 8080 # Allow to atlas (riotpiao-backend) for /cluster/* routes - to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: atlas ports: - protocol: TCP port: 8080