diff --git a/assets/templates/diskmaker-discovery-daemonset.yaml b/assets/templates/diskmaker-discovery-daemonset.yaml index ef062d4ff..387c7d61e 100644 --- a/assets/templates/diskmaker-discovery-daemonset.yaml +++ b/assets/templates/diskmaker-discovery-daemonset.yaml @@ -15,9 +15,6 @@ spec: target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}' labels: app: diskmaker-discovery - openshift.storage.network-policy.lso.dns: allow - openshift.storage.network-policy.lso.api-server: allow - openshift.storage.network-policy.lso.diskmaker-metrics: allow spec: containers: - args: diff --git a/assets/templates/diskmaker-manager-daemonset.yaml b/assets/templates/diskmaker-manager-daemonset.yaml index 892f371b5..ac5613d1c 100644 --- a/assets/templates/diskmaker-manager-daemonset.yaml +++ b/assets/templates/diskmaker-manager-daemonset.yaml @@ -15,9 +15,6 @@ spec: target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}' labels: app: diskmaker-manager - openshift.storage.network-policy.lso.dns: allow - openshift.storage.network-policy.lso.api-server: allow - openshift.storage.network-policy.lso.diskmaker-metrics: allow spec: containers: - args: diff --git a/config/manifests/stable/local-storage-operator.clusterserviceversion.yaml b/config/manifests/stable/local-storage-operator.clusterserviceversion.yaml index 451a10058..befc21c6c 100644 --- a/config/manifests/stable/local-storage-operator.clusterserviceversion.yaml +++ b/config/manifests/stable/local-storage-operator.clusterserviceversion.yaml @@ -435,9 +435,6 @@ spec: target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}' labels: name: local-storage-operator - openshift.storage.network-policy.lso.dns: allow - openshift.storage.network-policy.lso.api-server: allow - openshift.storage.network-policy.lso.operator-metrics: allow spec: serviceAccountName: local-storage-operator priorityClassName: openshift-user-critical diff --git a/config/manifests/stable/network-policy-allow-egress-to-api-server.yaml b/config/manifests/stable/network-policy-allow-egress-to-api-server.yaml deleted file mode 100644 index 7a811c4df..000000000 --- a/config/manifests/stable/network-policy-allow-egress-to-api-server.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: lso-allow-egress-to-api-server - annotations: - include.release.openshift.io/hypershift: "true" - include.release.openshift.io/ibm-cloud-managed: "true" - include.release.openshift.io/self-managed-high-availability: "true" - include.release.openshift.io/single-node-developer: "true" - capability.openshift.io/name: Storage -spec: - podSelector: - matchLabels: - openshift.storage.network-policy.lso.api-server: allow - egress: - - ports: - - protocol: TCP - port: 6443 - policyTypes: - - Egress diff --git a/config/manifests/stable/network-policy-allow-egress-to-dns.yaml b/config/manifests/stable/network-policy-allow-egress-to-dns.yaml deleted file mode 100644 index 43c7a8467..000000000 --- a/config/manifests/stable/network-policy-allow-egress-to-dns.yaml +++ /dev/null @@ -1,29 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: lso-allow-egress-to-dns - annotations: - include.release.openshift.io/hypershift: "true" - include.release.openshift.io/ibm-cloud-managed: "true" - include.release.openshift.io/self-managed-high-availability: "true" - include.release.openshift.io/single-node-developer: "true" - capability.openshift.io/name: Storage -spec: - podSelector: - matchLabels: - openshift.storage.network-policy.lso.dns: allow - egress: - - to: - - namespaceSelector: - matchLabels: - kubernetes.io/metadata.name: openshift-dns - podSelector: - matchLabels: - dns.operator.openshift.io/daemonset-dns: default - ports: - - protocol: TCP - port: dns-tcp - - protocol: UDP - port: dns - policyTypes: - - Egress diff --git a/config/manifests/stable/network-policy-allow-ingress-to-diskmaker-metrics.yaml b/config/manifests/stable/network-policy-allow-ingress-to-diskmaker-metrics.yaml deleted file mode 100644 index 267ef3c07..000000000 --- a/config/manifests/stable/network-policy-allow-ingress-to-diskmaker-metrics.yaml +++ /dev/null @@ -1,22 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: lso-allow-ingress-to-diskmaker-metrics - annotations: - include.release.openshift.io/hypershift: "true" - include.release.openshift.io/ibm-cloud-managed: "true" - include.release.openshift.io/self-managed-high-availability: "true" - include.release.openshift.io/single-node-developer: "true" - capability.openshift.io/name: Storage -spec: - podSelector: - matchLabels: - openshift.storage.network-policy.lso.diskmaker-metrics: allow - ingress: - - ports: - - protocol: TCP - port: 8383 - - protocol: TCP - port: 9393 - policyTypes: - - Ingress diff --git a/config/manifests/stable/network-policy-allow-ingress-to-operator-metrics.yaml b/config/manifests/stable/network-policy-allow-ingress-to-operator-metrics.yaml deleted file mode 100644 index de5ce9afe..000000000 --- a/config/manifests/stable/network-policy-allow-ingress-to-operator-metrics.yaml +++ /dev/null @@ -1,22 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: lso-allow-ingress-to-operator-metrics - annotations: - include.release.openshift.io/hypershift: "true" - include.release.openshift.io/ibm-cloud-managed: "true" - include.release.openshift.io/self-managed-high-availability: "true" - include.release.openshift.io/single-node-developer: "true" - capability.openshift.io/name: Storage -spec: - podSelector: - matchLabels: - openshift.storage.network-policy.lso.operator-metrics: allow - ingress: - - ports: - - protocol: TCP - port: 8080 - - protocol: TCP - port: 8081 - policyTypes: - - Ingress diff --git a/config/manifests/stable/network-policy-default-deny-all.yaml b/config/manifests/stable/network-policy-default-deny-all.yaml deleted file mode 100644 index 3c6e36576..000000000 --- a/config/manifests/stable/network-policy-default-deny-all.yaml +++ /dev/null @@ -1,15 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: NetworkPolicy -metadata: - name: lso-default-deny-all - annotations: - include.release.openshift.io/hypershift: "true" - include.release.openshift.io/ibm-cloud-managed: "true" - include.release.openshift.io/self-managed-high-availability: "true" - include.release.openshift.io/single-node-developer: "true" - capability.openshift.io/name: Storage -spec: - podSelector: {} - policyTypes: - - Ingress - - Egress