helm: document what turning the network policies on costs

Three things the values did not say: a Prometheus outside the release stops
scraping and nothing reports it, the resize hook's policy is a hook resource
that uninstall leaves behind, and the DNS selectors are wrong on OpenShift.
This commit is contained in:
Chris Lu committed 2026-07-29 20:20:23 -07:00
1 parent f43e8eda1d
commit 1a4554bda6
2 files changed
+26 -1

No files matched your search

+9
View File
@@ -395,8 +395,17 @@ networkPolicy:
port: 5432
```
`kubeApiServer.cidrs` is only demanded when something in the release actually needs the API server, which is the COSI sidecar and, on an upgrade that grows a volume PVC, the resize hook. No seaweedfs component itself speaks to it.
Anything reaching the release from outside - an ingress controller, a Prometheus in another namespace - goes into `networkPolicy.extraIngress`, or into `networkPolicy.components.<component>.extraIngress` for a single component. See the `networkPolicy` block in `values.yaml` for the full set.
Two things worth knowing before you turn this on:
- **Monitoring stops.** The metrics ports are admitted from release pods like every other port, so with `global.seaweedfs.monitoring.enabled` the ServiceMonitors keep scraping targets a Prometheus in another namespace can no longer reach. Nothing reports it; add the scraper's namespace to `extraIngress`.
- **The resize hook's policy is a Helm hook.** Its Job runs before the release manifest is applied, so the policy has to be a `pre-install` hook too. Helm does not garbage-collect hook resources, so on an upgrade that grows a volume PVC the policy is created and then left behind on uninstall - delete `<release>-seaweedfs-volume-resize-hook` by hand if it bothers you.
The DNS selectors default to CoreDNS as kubeadm, kind, EKS, GKE and AKS install it. On OpenShift, override `egress.dnsNamespaceSelector` and `egress.dnsPodSelector` to match `openshift-dns`; see the comment in `values.yaml`.
## OpenShift Support
SeaweedFS can be deployed on OpenShift or any cluster enforcing the Kubernetes "restricted" Pod Security Standard. By default, OpenShift blocks containers that run as root or use `hostPath` volumes.
+17 -1
View File
@@ -1830,7 +1830,12 @@ networkPolicy:
# does not leave the policy behind. Everything else is denied.
#
# Traffic from outside the release has to be added here. Rules are plain
# NetworkPolicyIngressRule entries, appended to every component's policy:
# NetworkPolicyIngressRule entries, appended to every component's policy.
#
# The metrics ports are covered by the same rule as everything else, so with
# global.seaweedfs.monitoring.enabled the ServiceMonitors keep pointing at
# ports a Prometheus outside the release can no longer reach. Nothing reports
# that - the targets just go down - so add the scraper here:
#
# extraIngress:
# # an ingress controller reaching filer/s3/admin
@@ -1875,6 +1880,17 @@ networkPolicy:
# Every component resolves its peers by DNS name, so this is required
# for the release to function at all.
#
# The defaults below are CoreDNS as kubeadm, kind, EKS, GKE and AKS install
# it. OpenShift runs its resolver elsewhere and needs both overridden:
# dnsNamespaceSelector:
# matchLabels:
# kubernetes.io/metadata.name: openshift-dns
# dnsPodSelector:
# matchLabels:
# dns.operator.openshift.io/daemonset-dns: default
# A node-local DNS cache is not a pod peer at all - the resolver address is
# a link-local IP - so name it with an ipBlock in extraEgress instead.
allowDNS: true
dnsNamespaceSelector:
matchLabels: