# Scoped exception to the disallow-nodeport-services policy, narrowly for # the multi-site active-failover pilot's cross-site services (etcd quorum, # Postgres streaming replication) - not a namespace-wide exclusion. # # Why NodePort is genuinely needed here: home nodes are directly reachable # from Netbird mesh peers (VPS, witness) on their real node IP - confirmed # live 2026-08-19 (ping succeeded from the VPS to a node's InternalIP, # which is itself a Netbird-mesh address via the netbird-egress DaemonSet's # route). A NodePort Service binds on that same real interface on every # node, giving the VPS/witness a way to reach it directly over the already- # authenticated Netbird mesh - no public internet exposure, no UniFi # port-forward, no new WAN-facing attack surface. LoadBalancer (MetalLB) # only gets a LAN-side VIP, which isn't reachable from Netbird peers at all # without the same underlying NodePort-style exposure anyway. apiVersion: kyverno.io/v2 kind: PolicyException metadata: name: ha-failover-nodeport-exemption namespace: kyverno spec: exceptions: - policyName: disallow-nodeport-services ruleNames: - disallow-nodeport match: any: - resources: kinds: - Service names: - ha-*