Skip to content

Updates fromEndpoints&toEndpoints to be allow all

What does this MR do?

Updates fromEndpoints&toEndpoints to be allow all in order to be aligned with the humanized version which is based in allowing instead of denying logic. Text change was performed to revert a previous attempt for this fix.

This wasn't allowing all but actually denying all

spec:
  ingress:
    - {}

Therefore this MRs changes it to (which is aligned with https://docs.cilium.io/en/v1.8/policy/language/):

spec:
  ingress:
  - fromEndpoints:
    - matchLabels: {}

Related issue: #270130 (closed)

Screenshots (strongly suggested)

Before:

ingress_deny_all_before

After:

allow_all_ingress_after

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Zamir Martins

Merge request reports