Network Policy Descriptor reference
Akka Network Policy descriptor
An Akka network policy descriptor describes, at the network level, what ingress and egress traffic is allowed to and from the services in an Akka project. It is used by the akka projects network-policy apply command, described in Managing network policies.
Every project has exactly one network policy, named default. It cannot be created or deleted, only configured. Traffic between services in the same project, and traffic required by Akka platform infrastructure, is always allowed regardless of this configuration.
|
Network policies do not override Access Control Lists (ACLs). A network policy controls connectivity at the network layer: whether a peer can open a connection to a service at all. An ACL controls, once a connection is allowed, which principals can invoke which service methods. Both must permit a request for it to succeed. Ingress rules also only match traffic arriving over Akka’s private network, for example from a service in another project, or from a CIDR range reachable within that network. They have no effect on traffic reaching your services through a route exposed to the internet. That traffic is always allowed at the network level, and access to it is controlled instead by routes and by ACLs using the internet principal. |
| Field | Type | Description |
|---|---|---|
ingress |
Rules describing additional traffic allowed into the services in the project. If empty, no additional ingress traffic is allowed beyond same-project and infrastructure traffic. |
|
egress |
Rules describing additional traffic allowed out of the services in the project. If empty, no additional egress traffic is allowed beyond same-project and infrastructure traffic. |
NetworkPolicyIngressRule
Describes a set of traffic that is allowed into the services in the project. Incoming traffic must match both ports and from for the rule to apply.
| Field | Type | Description |
|---|---|---|
ports |
The ports this rule allows traffic on. Items are combined with a logical OR. If empty or omitted, the rule matches all ports. |
|
from |
The sources this rule allows traffic from. Items are combined with a logical OR. If empty or omitted, the rule matches all sources. |
NetworkPolicyEgressRule
Describes a set of traffic that is allowed out of the services in the project. Outgoing traffic must match both ports and to for the rule to apply.
| Field | Type | Description |
|---|---|---|
ports |
The destination ports this rule allows traffic on. Items are combined with a logical OR. If empty or omitted, the rule matches all ports. |
|
to |
The destinations this rule allows traffic to. Items are combined with a logical OR. If empty or omitted, the rule matches all destinations. |
NetworkPolicyPort
A port to match traffic on.
| Field | Type | Description |
|---|---|---|
protocol |
string |
The protocol to match: |
port |
string |
The port to match, either a number (for example |
endPort |
int |
Together with |
NetworkPolicyPeer
Describes a peer to allow traffic to or from. Specify either service and/or projectId, or ipBlock, but not both.
| Field | Type | Description |
|---|---|---|
service |
string |
The name of a service to match. If |
projectId |
string |
The ID of a project to match. If |
ipBlock |
An IP block to match. Cannot be combined with |
To match a service in another project, set both service and projectId. To match all services in another project, set only projectId.
Complete descriptor example
resource: NetworkPolicy
resourceVersion: v1
spec:
ingress:
- ports:
- port: akka-service
from:
- service: order-service
projectId: 3f29b6d8-9c34-4a1a-8f77-2b6e9d9a5b21
- from:
- ipBlock:
cidr: 10.20.0.0/16
except:
- 10.20.30.0/24
egress:
- ports:
- port: 443
to:
- ipBlock:
cidr: 0.0.0.0/0
- ports:
- port: 5432
to:
- service: shared-database
projectId: 91f0c1a4-6b3f-4e2a-9d2e-9a7d5f6c0b12
This example allows two ingress rules: traffic on the internal Akka service port from a service named order-service in another project, and traffic from any port in the 10.20.0.0/16 CIDR range except 10.20.30.0/24. It also allows two egress rules: HTTPS traffic (port 443) to anywhere, and PostgreSQL traffic (port 5432) to a service named shared-database in another project.
Note that this descriptor has no metadata, since a project’s network policy is a singleton resource; it is always named default and does not need to be identified by name.
Using the network policy descriptor
The network policy descriptor is a single-document YAML file, unlike the project descriptor, which can bundle multiple resources. It can be exported from and applied to a project using the akka projects network-policy export and akka projects network-policy apply commands, or edited in place with akka projects network-policy edit. It can also be included as one document within a multi-document project descriptor applied with akka project apply, using resource: NetworkPolicy.
For a walkthrough of managing network policies with the CLI, see Managing network policies.