Files
Homelabv4/infrastructure/istio/manifests/mesh/peer-authentication-webhooks.yaml
T
2026-03-09 20:21:35 -05:00

45 lines
1.1 KiB
YAML

# PeerAuthentication PERMISSIVE for namespaces that receive non-mesh traffic
# The API server calls webhooks from outside the mesh (no SPIFFE identity).
# The CrowdSec firewall bouncer runs on hostNetwork (no mesh identity)
# and must connect to LAPI over plaintext.
# PERMISSIVE allows both mTLS and plaintext inbound.
---
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-apiserver-webhooks
namespace: cnpg-system
spec:
mtls:
mode: PERMISSIVE
---
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-apiserver-webhooks
namespace: mariadb-system
spec:
mtls:
mode: PERMISSIVE
---
# Netbird operator webhook receives calls from the API server
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-apiserver-webhooks
namespace: netbird-operator
spec:
mtls:
mode: PERMISSIVE
---
# CrowdSec firewall bouncer (hostNetwork DaemonSet) connects to LAPI
# from the host network namespace without a mesh identity
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: allow-hostnetwork-bouncer
namespace: crowdsec
spec:
mtls:
mode: PERMISSIVE