From 1a4554bda6418117e9f6a8501d579654697ef912 Mon Sep 17 00:00:00 2001 From: Chris Lu Date: Wed, 29 Jul 2026 20:20:23 -0700 Subject: [PATCH] helm: document what turning the network policies on costs Three things the values did not say: a Prometheus outside the release stops scraping and nothing reports it, the resize hook's policy is a hook resource that uninstall leaves behind, and the DNS selectors are wrong on OpenShift. --- k8s/charts/seaweedfs/README.md | 9 +++++++++ k8s/charts/seaweedfs/values.yaml | 18 +++++++++++++++++- 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/k8s/charts/seaweedfs/README.md b/k8s/charts/seaweedfs/README.md index a2f2289bf..ea1c7ae30 100644 --- a/k8s/charts/seaweedfs/README.md +++ b/k8s/charts/seaweedfs/README.md @@ -395,8 +395,17 @@ networkPolicy: port: 5432 ``` +`kubeApiServer.cidrs` is only demanded when something in the release actually needs the API server, which is the COSI sidecar and, on an upgrade that grows a volume PVC, the resize hook. No seaweedfs component itself speaks to it. + Anything reaching the release from outside - an ingress controller, a Prometheus in another namespace - goes into `networkPolicy.extraIngress`, or into `networkPolicy.components..extraIngress` for a single component. See the `networkPolicy` block in `values.yaml` for the full set. +Two things worth knowing before you turn this on: + +- **Monitoring stops.** The metrics ports are admitted from release pods like every other port, so with `global.seaweedfs.monitoring.enabled` the ServiceMonitors keep scraping targets a Prometheus in another namespace can no longer reach. Nothing reports it; add the scraper's namespace to `extraIngress`. +- **The resize hook's policy is a Helm hook.** Its Job runs before the release manifest is applied, so the policy has to be a `pre-install` hook too. Helm does not garbage-collect hook resources, so on an upgrade that grows a volume PVC the policy is created and then left behind on uninstall - delete `-seaweedfs-volume-resize-hook` by hand if it bothers you. + +The DNS selectors default to CoreDNS as kubeadm, kind, EKS, GKE and AKS install it. On OpenShift, override `egress.dnsNamespaceSelector` and `egress.dnsPodSelector` to match `openshift-dns`; see the comment in `values.yaml`. + ## OpenShift Support SeaweedFS can be deployed on OpenShift or any cluster enforcing the Kubernetes "restricted" Pod Security Standard. By default, OpenShift blocks containers that run as root or use `hostPath` volumes. diff --git a/k8s/charts/seaweedfs/values.yaml b/k8s/charts/seaweedfs/values.yaml index 07f07e3dd..1f3436bea 100644 --- a/k8s/charts/seaweedfs/values.yaml +++ b/k8s/charts/seaweedfs/values.yaml @@ -1830,7 +1830,12 @@ networkPolicy: # does not leave the policy behind. Everything else is denied. # # Traffic from outside the release has to be added here. Rules are plain - # NetworkPolicyIngressRule entries, appended to every component's policy: + # NetworkPolicyIngressRule entries, appended to every component's policy. + # + # The metrics ports are covered by the same rule as everything else, so with + # global.seaweedfs.monitoring.enabled the ServiceMonitors keep pointing at + # ports a Prometheus outside the release can no longer reach. Nothing reports + # that - the targets just go down - so add the scraper here: # # extraIngress: # # an ingress controller reaching filer/s3/admin @@ -1875,6 +1880,17 @@ networkPolicy: # Every component resolves its peers by DNS name, so this is required # for the release to function at all. + # + # The defaults below are CoreDNS as kubeadm, kind, EKS, GKE and AKS install + # it. OpenShift runs its resolver elsewhere and needs both overridden: + # dnsNamespaceSelector: + # matchLabels: + # kubernetes.io/metadata.name: openshift-dns + # dnsPodSelector: + # matchLabels: + # dns.operator.openshift.io/daemonset-dns: default + # A node-local DNS cache is not a pod peer at all - the resolver address is + # a link-local IP - so name it with an ipBlock in extraEgress instead. allowDNS: true dnsNamespaceSelector: matchLabels: