firewall-controller icon indicating copy to clipboard operation
firewall-controller copied to clipboard

Make CWNP Validation more strict

Open majst01 opened this issue 2 years ago • 1 comments

We should enforce that for every rule specified either to or toFQDNs and port is specified to prevent accidentally open to wide

majst01 avatar Apr 12 '23 08:04 majst01

Another idea that comes to mind is implementing a validation webhook. This could run as a dedicated pod in the seed's shoot namespace and watch the shoot api-server. This way, we could decline erroneous resources directly before storing them into ETCD.

Gerrit91 avatar Apr 12 '23 09:04 Gerrit91