Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Access requests to sidecar from thanos-query #1730

Merged
merged 4 commits into from
Apr 21, 2022

Conversation

polRk
Copy link
Contributor

@polRk polRk commented Apr 14, 2022

Description

Current network polices restrict access to sidecar container from thanos query component. https://github.nmiku.com/thanos-io/kube-thanos/issues/272

Type of change

What type of changes does your code introduce to the kube-prometheus? Put an x in the box that apply.

  • CHANGE (fix or feature that would cause existing functionality to not work as expected)
  • FEATURE (non-breaking change which adds functionality)
  • BUGFIX (non-breaking change which fixes an issue)
  • ENHANCEMENT (non-breaking change which improves existing functionality)
  • NONE (if none of the other choices apply. Example, tooling, build system, CI, docs, etc.)

Changelog entry

Allow request from thanos-query to prometheus-operated service.

 - Add NetworkPolicy rule allowing requests from thanos-query to prometheus-operated service.

@ArthurSens
Copy link
Member

Hi @polRk, thanks for the fix!

Only one thing is missing, could you run make generate to make CI happy? 🙂

@ArthurSens
Copy link
Member

Maybe we could add this patch only when Thanos is being used as well? Following the rule of least privileged, we don't want to give any access when it's not being used 🤔

@polRk
Copy link
Contributor Author

polRk commented Apr 19, 2022

Maybe we could add this patch only when Thanos is being used as well? Following the rule of least privileged, we don't want to give any access when it's not being used 🤔

I've been thinking about it. We can enable this rule if the thanos object is specified?

Copy link
Member

@ArthurSens ArthurSens left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@ArthurSens ArthurSens merged commit 6c1890b into prometheus-operator:main Apr 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants