turbot/kubernetes

steampipe plugin install kubernetessteampipe plugin install kubernetes
On This Page
Get Involved

Table: kubernetes_network_policy

Network policy specifiy how pods are allowed to communicate with each other and with other network endpoints.

Examples

Basic Info

select
name,
namespace,
policy_types,
ingress,
egress,
pod_selector,
labels,
annotations
from
kubernetes_network_policy;

List policies that allow all egress

select
name,
namespace,
policy_types,
pod_selector,
egress
from
kubernetes_network_policy
where
policy_types @> '["Egress"]'
and pod_selector = '{}'
and egress @> '[{}]';

List default deny egress policies

select
name,
namespace,
policy_types,
pod_selector,
egress
from
kubernetes_network_policy
where
policy_types @> '["Egress"]'
and pod_selector = '{}'
and egress is null;

List policies that allow all ingress

select
name,
namespace,
policy_types,
pod_selector,
ingress
from
kubernetes_network_policy
where
policy_types @> '["Ingress"]'
and pod_selector = '{}'
and ingress @> '[{}]';

List default deny ingress policies

select
name,
namespace,
policy_types,
pod_selector,
ingress
from
kubernetes_network_policy
where
policy_types @> '["Ingress"]'
and pod_selector = '{}'
and ingress is null;

View rules for a specific network policy

select
name,
namespace,
policy_types,
jsonb_pretty(ingress),
jsonb_pretty(egress)
from
kubernetes_network_policy
where
name = 'test-network-policy'
and namespace = 'default';

.inspect kubernetes_network_policy

Network policy specifiy how pods are allowed to communicate with each other and with other network endpoints.

NameTypeDescription
annotationsjsonbAnnotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata.
context_nametextKubectl config context name.
creation_timestamptimestamp without time zoneCreationTimestamp is a timestamp representing the server time when this object was created.
deletion_grace_period_secondsbigintNumber of seconds allowed for this object to gracefully terminate before it will be removed from the system. Only set when deletionTimestamp is also set.
deletion_timestamptimestamp without time zoneDeletionTimestamp is RFC 3339 date and time at which this resource will be deleted.
egressjsonbList of egress rules to be applied to the selected pods. If this field is empty then this NetworkPolicy limits all outgoing traffic (and serves solely to ensure that the pods it selects are isolated by default).
finalizersjsonbMust be empty before the object is deleted from the registry. Each entry is an identifier for the responsible component that will remove the entry from the list. If the deletionTimestamp of the object is non-nil, entries in this list can only be removed.
generate_nametextGenerateName is an optional prefix, used by the server, to generate a unique name ONLY IF the Name field has not been provided.
generationbigintA sequence number representing a specific generation of the desired state.
ingressjsonbList of ingress rules to be applied to the selected pods. If this field is empty then this NetworkPolicy does not allow any traffic (and serves solely to ensure that the pods it selects are isolated by default)
labelsjsonbMap of string keys and values that can be used to organize and categorize (scope and select) objects. May match selectors of replication controllers and services.
nametextName of the object. Name must be unique within a namespace.
namespacetextNamespace defines the space within which each name must be unique.
owner_referencesjsonbList of objects depended by this object. If ALL objects in the list have been deleted, this object will be garbage collected. If this object is managed by a controller, then an entry in this list will point to this controller, with the controller field set to true. There cannot be more than one managing controller.
pod_selectorjsonbSelects the pods to which this NetworkPolicy object applies. The array of ingress rules is applied to any pods selected by this field. An empty podSelector matches all pods in this namespace.
policy_typesjsonbList of rule types that the NetworkPolicy relates to. Valid options are "Ingress", "Egress", or "Ingress,Egress". If this field is not specified, it will default based on the existence of Ingress or Egress rules.
resource_versiontextAn opaque value that represents the internal version of this object that can be used by clients to determine when objects have changed.
tagsjsonbA map of tags for the resource. This includes both labels and annotations.
titletextTitle of the resource.
uidtextUID is the unique in time and space value for this object.