概览与核心价值网络策略用于 L3/L4 层访问控制,服务网格提供 L7 语义与可观测,二者协同实现零信任。实战与示例apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-web
namespace: default
spec:
podSelector:
matchLabels:
app: web
policyTypes:
- Ingress
- Egress
ingress:
- from:
- podSelector:
matchLabels:
app: api
egress:
- to:
- namespaceSelector:
matchLabels:
istio-injection: enabled
验证与度量以策略命中率、延迟与错误率为核心指标评估策略与网格配置效果。版本与来源Kubernetes NetworkPolicy 文档:https://kubernetes.io/docs/concepts/services-networking/network-policies/

发表评论 取消回复