Manage network policies
A network policy controls, at the network level, what ingress and egress traffic is allowed to and from the services in an Akka project. Every project has exactly one network policy, named default. It cannot be created or deleted, only configured, using the akka projects network-policy command (alias akka projects netpol).
Traffic between services in the same project, and traffic required by Akka platform infrastructure, is always allowed regardless of this configuration. A network policy only needs to be configured when a service in your project needs to talk to, or be talked to by, something outside the project: a service in another project, or a destination or source reachable by IP address, such as a database or third party API.
|
Network policies do not override ACLs. A network policy controls connectivity at the network layer: whether a peer can open a connection to a service at all. Access Control Lists (ACLs) control, once a connection is allowed, which principals can invoke which service methods. Both must permit a request for it to succeed — opening up a network policy does not grant any access that an ACL still denies. Ingress rules only apply to Akka’s private network. They match traffic from a service in another project, or from a CIDR range reachable within that network. They have no effect on traffic reaching your services through a route exposed to the internet — that traffic is always allowed at the network level, and access to it is controlled instead by routes and by ACLs using the internet principal. |
Viewing the network policy
To see the current network policy configuration for your project:
akka projects network-policy get
If no rules have been configured, the output looks like this:
Akka Network Policy Configuration
=================================
Ingress Rules: (none)
Egress Rules: (none)
With this default configuration, no traffic beyond same-project and infrastructure traffic is allowed in or out. Once rules have been added, they are listed with a 1-based index that you use to refer to them when removing a rule:
Akka Network Policy Configuration
=================================
Ingress Rules:
[1]
Ports:
akka-service/TCP
From:
Service: order-service (project: 3f29b6d8-9c34-4a1a-8f77-2b6e9d9a5b21)
Egress Rules:
[1]
Ports:
443/TCP
To:
CIDR: 0.0.0.0/0
If your project spans multiple regions, akka projects network-policy get shows the primary region’s configuration by default. Pass --region to view a specific region, or --all-regions to view every region. See Managing resources in a multi region project for background on how resources like this one are synced across regions.
Adding rules
Rules are added one at a time with akka projects network-policy add ingress-rule and akka projects network-policy add egress-rule. Each command accepts repeatable --port flags and a repeatable peer flag (--from for ingress, --to for egress). Within a single rule, ports are combined with a logical OR, and peers are combined with a logical OR; a rule matches traffic that satisfies both a port and a peer. A rule with no ports allows all ports, and a rule with no peers allows all sources or destinations. If neither is given, the rule allows all traffic from all sources (ingress) or to all destinations (egress).
Port syntax
The --port flag accepts:
| Syntax | Meaning |
|---|---|
|
A numeric port, for example |
|
A numeric port with an explicit protocol ( |
|
A numeric port range, for example |
|
A numeric port range with an explicit protocol. |
|
Traffic on the internal port Akka services receive their traffic on. |
Peer syntax
The --from and --to flags accept:
| Syntax | Meaning |
|---|---|
|
A service in the local project. |
|
A service in another project. |
|
All services in another project. |
|
An IP block, optionally excluding one or more sub-blocks. |
Examples
Allow another project’s order-service to call your services over the internal Akka service port:
akka projects network-policy add ingress-rule \
--port akka-service \
--from service:order-service@3f29b6d8-9c34-4a1a-8f77-2b6e9d9a5b21
Allow ingress from an internal CIDR range, excluding a sub-block:
akka projects network-policy add ingress-rule \
--from cidr:10.20.0.0/16,10.20.30.0/24
Allow your services to make outbound HTTPS calls to any destination:
akka projects network-policy add egress-rule --port 443
A rule can combine multiple ports and multiple peers by repeating the flags:
akka projects network-policy add egress-rule \
--port 80 --port 443 \
--to cidr:0.0.0.0/0
Removing rules
Rules are removed by their 1-based index, as shown by akka projects network-policy get:
akka projects network-policy remove ingress-rule 1
akka projects network-policy remove egress-rule 2
Working with a network policy descriptor
For more complex configurations, or to keep your network policy in version control, you can work with it as a YAML descriptor. This is checked into source control the same way as other Akka descriptors — see Network Policy Descriptor reference for the complete field reference.
Export the current configuration:
akka projects network-policy export -f network-policy.yaml
Edit and re-apply it:
akka projects network-policy apply -f network-policy.yaml
Or edit it directly in your configured editor, applying it on save:
akka projects network-policy edit
A network policy document can also be included as one of the documents in a multi-resource project descriptor, applied with akka projects apply.
|
Changes to the network policy do not take effect for already-running service instances until they are restarted. |