# NetworkPolicy for CNPG pods - allow pod-to-pod replication traffic apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: forgejo-db-allow-replication namespace: cicd spec: podSelector: matchLabels: cnpg.io/cluster: forgejo-db policyTypes: - Ingress - Egress ingress: # Allow CNPG operator to reach instance status endpoints (port 8000) - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: cnpg-system ports: - protocol: TCP port: 8000 # Allow PostgreSQL connections from application pods (Forgejo) - from: - podSelector: {} namespaceSelector: matchLabels: kubernetes.io/metadata.name: cicd ports: - protocol: TCP port: 5432 # Allow PostgreSQL replication from other CNPG pods - from: - podSelector: matchLabels: cnpg.io/cluster: forgejo-db ports: - protocol: TCP port: 5432 # Allow metrics scraping - from: - namespaceSelector: {} ports: - protocol: TCP port: 9187 egress: # Allow all egress (CNPG needs to reach services, API server, DNS, etc.) # Restricting egress breaks replication through services - {}