mirror of https://github.com/linkerd/linkerd2.git
Use the 'all-unauthenticated' policy with the identity controller (#7110)
When no default policy is configured, the identity controller uses `cluster-unauthenticated` by default; but this may not permit connections from node IPs. This causes installations to fail in some environments. This change updates the identity controller's default policy to `all-unauthenticated` to match the behavior before policy was introduced. Fixes #7104
This commit is contained in:
parent
c72fe3f618
commit
9612bbeeaa
|
|
@ -195,7 +195,7 @@ spec:
|
|||
The identity controller cannot discover policies, so we configure it with defaults that
|
||||
enforce TLS on the identity service.
|
||||
*/}}
|
||||
{{- $_ := set $tree.Values.proxy "defaultInboundPolicy" "cluster-unauthenticated" }}
|
||||
{{- $_ := set $tree.Values.proxy "defaultInboundPolicy" "all-unauthenticated" }}
|
||||
{{- $_ := set $tree.Values.proxy "requireTLSOnInboundPorts" "8080" }}
|
||||
- {{- include "partials.proxy" $tree | indent 8 | trimPrefix (repeat 7 " ") }}
|
||||
{{ if not .Values.cniEnabled -}}
|
||||
|
|
|
|||
|
|
@ -1586,7 +1586,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.0.0.0/8"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1654,7 +1654,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1654,7 +1654,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1516,7 +1516,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1576,7 +1576,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1645,7 +1645,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1653,7 +1653,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1645,7 +1645,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "ClusterNetworks"
|
||||
- name: LINKERD2_PROXY_CONTROL_LISTEN_ADDR
|
||||
|
|
|
|||
|
|
@ -1585,7 +1585,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
|
|
@ -1571,7 +1571,7 @@ spec:
|
|||
- name: LINKERD2_PROXY_POLICY_WORKLOAD
|
||||
value: "$(_pod_ns):$(_pod_name)"
|
||||
- name: LINKERD2_PROXY_INBOUND_DEFAULT_POLICY
|
||||
value: cluster-unauthenticated
|
||||
value: all-unauthenticated
|
||||
- name: LINKERD2_PROXY_POLICY_CLUSTER_NETWORKS
|
||||
value: "10.0.0.0/8,100.64.0.0/10,172.16.0.0/12,192.168.0.0/16"
|
||||
- name: LINKERD2_PROXY_INBOUND_CONNECT_TIMEOUT
|
||||
|
|
|
|||
Loading…
Reference in New Issue