From c35f80cd80990ef8527fe7ecb3a3732e9c46817e Mon Sep 17 00:00:00 2001 From: Ram81 Date: Sun, 10 Oct 2021 14:46:44 -0400 Subject: [PATCH 1/2] Revert cilium policy --- .../code_upload_worker_utils/install_dependencies.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/scripts/workers/code_upload_worker_utils/install_dependencies.sh b/scripts/workers/code_upload_worker_utils/install_dependencies.sh index dadf1d35a8..6eedbe0d4b 100755 --- a/scripts/workers/code_upload_worker_utils/install_dependencies.sh +++ b/scripts/workers/code_upload_worker_utils/install_dependencies.sh @@ -45,9 +45,9 @@ echo "### Cilium Installed" sleep 120s; # Apply cilium network policy -echo "### Setting up Cilium Network Policy..." -cat /code/scripts/workers/code_upload_worker_utils/network_policies.yaml | sed "s/{{EVALAI_DNS}}/$EVALAI_DNS/" | kubectl apply -f - -echo "### Cilium EvalAI Network Policy Installed" +# echo "### Setting up Cilium Network Policy..." +# cat /code/scripts/workers/code_upload_worker_utils/network_policies.yaml | sed "s/{{EVALAI_DNS}}/$EVALAI_DNS/" | kubectl apply -f - +# echo "### Cilium EvalAI Network Policy Installed" # Set ssl-certificate echo $CERTIFICATE | base64 --decode > scripts/workers/certificate.crt From 453f3d1aca2a5517406fc7792357600657647d8a Mon Sep 17 00:00:00 2001 From: Ram81 Date: Sun, 10 Oct 2021 15:30:16 -0400 Subject: [PATCH 2/2] Enable all patterns for ubuntu.com --- .../code_upload_worker_utils/install_dependencies.sh | 6 +++--- .../workers/code_upload_worker_utils/network_policies.yaml | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/scripts/workers/code_upload_worker_utils/install_dependencies.sh b/scripts/workers/code_upload_worker_utils/install_dependencies.sh index 6eedbe0d4b..dadf1d35a8 100755 --- a/scripts/workers/code_upload_worker_utils/install_dependencies.sh +++ b/scripts/workers/code_upload_worker_utils/install_dependencies.sh @@ -45,9 +45,9 @@ echo "### Cilium Installed" sleep 120s; # Apply cilium network policy -# echo "### Setting up Cilium Network Policy..." -# cat /code/scripts/workers/code_upload_worker_utils/network_policies.yaml | sed "s/{{EVALAI_DNS}}/$EVALAI_DNS/" | kubectl apply -f - -# echo "### Cilium EvalAI Network Policy Installed" +echo "### Setting up Cilium Network Policy..." +cat /code/scripts/workers/code_upload_worker_utils/network_policies.yaml | sed "s/{{EVALAI_DNS}}/$EVALAI_DNS/" | kubectl apply -f - +echo "### Cilium EvalAI Network Policy Installed" # Set ssl-certificate echo $CERTIFICATE | base64 --decode > scripts/workers/certificate.crt diff --git a/scripts/workers/code_upload_worker_utils/network_policies.yaml b/scripts/workers/code_upload_worker_utils/network_policies.yaml index 4c318106fa..a11552be6a 100644 --- a/scripts/workers/code_upload_worker_utils/network_policies.yaml +++ b/scripts/workers/code_upload_worker_utils/network_policies.yaml @@ -8,8 +8,8 @@ spec: {} egress: - toFQDNs: - - matchName: archive.ubuntu.com - matchName: {{EVALAI_DNS}} + - matchPattern: "*.ubuntu.com" - toEndpoints: - matchLabels: "k8s:io.kubernetes.pod.namespace": kube-system