Networking
Networking draws what reaches what: a project's applications and resources, the hostnames that lead in from outside, and every connection between them. It answers the question a list of Deployments cannot, which is what would stop working if this one thing went away.
What is on the map
Each connection is drawn from something Kaisin was told, and says which:
- A route — a hostname, or a path under one, that Traefik sends to an application.
- An attachment — a database, a cache or an object store whose credentials Kaisin injects.
- A link — one application told the address of another.
- A variable — an in-cluster address somebody typed into a variable by hand, with no link or attachment behind it.
What else runs on the cluster is drawn too, under its namespace and marked as not in Kaisin, when something of yours calls it. Importing a cluster is how it stops being a stranger.
The boxes drag, the canvas pans, and several namespaces can be drawn at once, including another project's when a link crosses into it. Where the boxes were left is remembered in your browser.
Isolation
An environment is Open until told otherwise: anything in the cluster can reach what runs in its namespace, on any port. That is how Kubernetes arrives, and the map only describes it.
An administrator can set an environment to Enforced, on the same page. Kaisin then writes
kaisin-default-deny in the namespace, and one allow policy for each application and resource,
written from their links, attachments and routes. They are ordinary NetworkPolicy objects and
kubectl reads them like any other.
What is let in:
- Traefik, to an application that has a domain or a route.
- An application, to whatever it is linked or attached to.
- Kaisin's own namespace, and the certificate solver while a certificate is being issued.
Everything else is refused.
Before it is turned on
Kaisin lists the connections that would be blocked and offers the fix beside each: an address set in a variable, with no link or attachment to allow it. Make the link and the connection is one the policy is written from.
Four things it says at the same moment, because they are the ways this surprises people:
- Addresses kept in secret variables, or written into the source, are invisible to Kaisin. Whatever uses them will be blocked too.
- Links from applications in another cluster will be refused. A policy can only allow traffic from inside its own cluster.
- Outgoing traffic stays open. Isolation is about what may reach an environment, not what it may call.
- The cluster has to enforce policies at all. That is the network plugin's job, and k3s does it as shipped. Where Kaisin cannot confirm it, it says the policies may be written and ignored.
Isolation fences in only what Kaisin deployed. An imported namespace is somebody else's chart, and enforcing there is refused rather than guessed at.
Turning it off
Setting the environment back to Open removes Kaisin's policies and nothing else, and anything in the cluster can reach it again.