Configuring network policies

By default, all Pods in a Kubernetes cluster can communicate with each other even if they are in different namespaces. In the context of Che, this makes it possible for a workspace Pod in one user namespace to send traffic to another workspace Pod in a different user namespace.

For security, multitenant isolation could be configured by using NetworkPolicy objects to restrict all incoming communication to Pods in a user namespace. However, Pods in the Che namespace must be able to communicate with Pods in user namespaces.

Operator-managed network policies

On OpenShift clusters, Che can automatically create and manage NetworkPolicy resources for the Che namespace and user workspace namespaces. This feature is disabled by default.

When enabled, the operator creates the following fine-grained NetworkPolicy resources:

Table 1. NetworkPolicy resources in the Che namespace
Policy name Description

allow-from-same-namespace

Allows ingress traffic between Che pods in the same namespace.

allow-from-workspaces

Allows ingress traffic from user workspace namespaces.

allow-from-openshift-ingress

Allows ingress traffic from the OpenShift ingress namespace.

allow-from-openshift-monitoring

Allows ingress traffic from the OpenShift monitoring namespace.

allow-from-che-operator

Allows ingress traffic from the operator pod to Che components.

allow-all-egress

Allows all egress traffic from Che pods.

Table 2. NetworkPolicy resources in each user workspace namespace
Policy name Description

allow-from-eclipse-che

Allows ingress traffic from the Che namespace.

allow-from-same-namespace

Allows ingress traffic between pods in the same namespace.

allow-from-devworkspace-operator

Allows ingress traffic from the DevWorkspace operator.

allow-from-openshift-monitoring

Allows ingress traffic from the OpenShift monitoring namespace.

allow-from-openshift-ingress

Allows ingress traffic from the OpenShift ingress namespace.

allow-all-egress

Allows all egress traffic from workspace pods.

Prerequisites
  • An active kubectl session with administrative permissions to the destination OpenShift cluster. See Overview of kubectl.

  • An instance of Che running in OpenShift.

Procedure
  1. Enable operator-managed network policies:

    kubectl patch checluster/eclipse-che -n eclipse-che \
      --type='merge' -p \
      '{"spec":{"networking":{"networkPolicy":{"enabled":true}}}}'
Verification
  1. Verify NetworkPolicy resources are created in the Che namespace:

    kubectl get networkpolicies -n eclipse-che
  2. Start a workspace and verify NetworkPolicy resources are created in the user namespace:

    kubectl get networkpolicies -n <user_namespace>

To disable operator-managed network policies and remove all managed NetworkPolicy resources:

kubectl patch checluster/eclipse-che -n eclipse-che \
  --type='merge' -p \
  '{"spec":{"networking":{"networkPolicy":{"enabled":false}}}}'

Manually configuring network policies

If you do not use operator-managed network policies, you can manually create NetworkPolicy objects to restrict incoming communication to Pods in a user namespace.

Prerequisites
  • The Kubernetes cluster has network restrictions such as multitenant isolation.

Procedure
  • Apply the allow-from-eclipse-che NetworkPolicy to each user namespace. The allow-from-eclipse-che NetworkPolicy allows incoming traffic from the Che namespace to all Pods in the user namespace.

    Example 1. allow-from-eclipse-che.yaml
    apiVersion: networking.k8s.io/v1
    kind: NetworkPolicy
    metadata:
        name: allow-from-eclipse-che
    spec:
        ingress:
        - from:
            - namespaceSelector:
                matchLabels:
                    kubernetes.io/metadata.name: eclipse-che   (1)
        podSelector: {}   (2)
        policyTypes:
        - Ingress
    1 The Che namespace. The default is eclipse-che.
    2 The empty podSelector selects all Pods in the namespace.
  • OPTIONAL: In case you applied Configuring multitenant isolation with network policy, you also must apply allow-from-openshift-apiserver and allow-from-workspaces-namespaces NetworkPolicies to eclipse-che. The allow-from-openshift-apiserver NetworkPolicy allows incoming traffic from openshift-apiserver namespace to the devworkspace-webhook-server enabling webhooks. The allow-from-workspaces-namespaces NetworkPolicy allows incoming traffic from each user project to che-gateway pod.

    Example 2. allow-from-openshift-apiserver.yaml
    apiVersion: networking.k8s.io/v1
    kind: NetworkPolicy
    metadata:
      name: allow-from-openshift-apiserver
      namespace: eclipse-che   (1)
    spec:
      podSelector:
        matchLabels:
          app.kubernetes.io/name: devworkspace-webhook-server   (2)
      ingress:
        - from:
            - podSelector: {}
              namespaceSelector:
                matchLabels:
                  kubernetes.io/metadata.name: openshift-apiserver
      policyTypes:
        - Ingress
    1 The Che namespace. The default is eclipse-che.
    2 The podSelector only selects devworkspace-webhook-server pods
    Example 3. allow-from-workspaces-namespaces.yaml
    apiVersion: networking.k8s.io/v1
    kind: NetworkPolicy
    metadata:
      name: allow-from-workspaces-namespaces
      namespace: eclipse-che   (1)
    spec:
      podSelector: {}   (2)
      ingress:
        - from:
            - podSelector: {}
              namespaceSelector:
                matchLabels:
                  app.kubernetes.io/component: workspaces-namespace
      policyTypes:
        - Ingress
    1 The Che namespace. The default is eclipse-che.
    2 The empty podSelector selects all pods in the Che namespace.
  • Configuring user namespace provisioning

  • Network isolation

  • Configuring multitenant isolation with network policy