Networking

Networking draws what reaches what: a project's applications and resources, the hostnames that lead in from outside, and every connection between them. It answers the question a list of Deployments cannot, which is what would stop working if this one thing went away.

What is on the map

Each connection is drawn from something Kaisin was told, and says which:

What else runs on the cluster is drawn too, under its namespace and marked as not in Kaisin, when something of yours calls it. Importing a cluster is how it stops being a stranger.

The boxes drag, the canvas pans, and several namespaces can be drawn at once, including another project's when a link crosses into it. Where the boxes were left is remembered in your browser.

Isolation

An environment is Open until told otherwise: anything in the cluster can reach what runs in its namespace, on any port. That is how Kubernetes arrives, and the map only describes it.

An administrator can set an environment to Enforced, on the same page. Kaisin then writes kaisin-default-deny in the namespace, and one allow policy for each application and resource, written from their links, attachments and routes. They are ordinary NetworkPolicy objects and kubectl reads them like any other.

What is let in:

Everything else is refused.

Before it is turned on

Kaisin lists the connections that would be blocked and offers the fix beside each: an address set in a variable, with no link or attachment to allow it. Make the link and the connection is one the policy is written from.

Four things it says at the same moment, because they are the ways this surprises people:

Isolation fences in only what Kaisin deployed. An imported namespace is somebody else's chart, and enforcing there is refused rather than guessed at.

Turning it off

Setting the environment back to Open removes Kaisin's policies and nothing else, and anything in the cluster can reach it again.