)]}'
{"doc/source/devref/network_policy.rst":[{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":37,"context_line":"many calls to Neutron and helping to differentiate between the current Kubernetes"},{"line_number":38,"context_line":"status of the Network Policy and the last one Kuryr-Kubernetes enforced."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Kuryr controller has been modified to react to Network Policy events, and trigger"},{"line_number":41,"context_line":"the necessary updates to others Kubernetes resources."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_790d2536","line":41,"range":{"start_line":40,"start_character":0,"end_line":41,"end_character":53},"updated":"2019-06-03 07:21:01.000000000","message":"I would be a bit more specific here, i.e., a new handler has been added to react to network policy events, plus the existing ones has been modified to account for side effects/actions due to the existence of network policies applied to them, for instance service/pod handlers","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":37,"context_line":"many calls to Neutron and helping to differentiate between the current Kubernetes"},{"line_number":38,"context_line":"status of the Network Policy and the last one Kuryr-Kubernetes enforced."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Kuryr controller has been modified to react to Network Policy events, and trigger"},{"line_number":41,"context_line":"the necessary updates to others Kubernetes resources."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_241442a0","line":41,"range":{"start_line":40,"start_character":0,"end_line":41,"end_character":53},"in_reply_to":"9fb8cfa7_790d2536","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":14885,"name":"Daniel Mellado","email":"dmellado@redhat.com","username":"daniel-mellado"},"change_message_id":"703e2a50aeed467362684172849dd39926d681a0","unresolved":false,"context_lines":[{"line_number":37,"context_line":"many calls to Neutron and helping to differentiate between the current Kubernetes"},{"line_number":38,"context_line":"status of the Network Policy and the last one Kuryr-Kubernetes enforced."},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"Kuryr controller has been modified to react to Network Policy events, and trigger"},{"line_number":41,"context_line":"the necessary updates to others Kubernetes resources."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_ff55751e","line":41,"range":{"start_line":40,"start_character":0,"end_line":41,"end_character":53},"in_reply_to":"9fb8cfa7_790d2536","updated":"2019-06-03 09:48:07.000000000","message":"Yeah, I do agree here, maybe it\u0027d be also cool to give out a quick summary about the handlers/drivers added on this feature.","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":40,"context_line":"Kuryr controller has been modified to react to Network Policy events, and trigger"},{"line_number":41,"context_line":"the necessary updates to others Kubernetes resources."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_f9183576","line":44,"range":{"start_line":43,"start_character":0,"end_line":44,"end_character":31},"updated":"2019-06-03 07:21:01.000000000","message":"perhaps worth to differentiate between handlers creation/modification, and drivers","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":40,"context_line":"Kuryr controller has been modified to react to Network Policy events, and trigger"},{"line_number":41,"context_line":"the necessary updates to others Kubernetes resources."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_42ae13e8","line":44,"range":{"start_line":43,"start_character":0,"end_line":44,"end_character":31},"in_reply_to":"9fb8cfa7_f9183576","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":14885,"name":"Daniel Mellado","email":"dmellado@redhat.com","username":"daniel-mellado"},"change_message_id":"703e2a50aeed467362684172849dd39926d681a0","unresolved":false,"context_lines":[{"line_number":40,"context_line":"Kuryr controller has been modified to react to Network Policy events, and trigger"},{"line_number":41,"context_line":"the necessary updates to others Kubernetes resources."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_bf35bdf9","line":44,"range":{"start_line":43,"start_character":0,"end_line":44,"end_character":31},"in_reply_to":"9fb8cfa7_f9183576","updated":"2019-06-03 09:48:07.000000000","message":"That\u0027s totally in line with my suggestion on the above comment. Let\u0027s modify this part!","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":48,"context_line":"This handler is responsible for triggering the Network Policy Spec processing,"},{"line_number":49,"context_line":"and the creation or removal of security group with appropriate security group"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_19ae69e7","line":46,"range":{"start_line":46,"start_character":0,"end_line":46,"end_character":26},"updated":"2019-06-03 07:21:01.000000000","message":"Not sure if here or on the proposed solution section, but we need to include what is supported, in our case:\n- Ingress and egress\n- namespaceSelector, podSelector, mix of namespace and pod selector, ipblock\n- named ports","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":43,"context_line":"Kuryr Controller Implementation"},{"line_number":44,"context_line":"+++++++++++++++++++++++++++++++"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":48,"context_line":"This handler is responsible for triggering the Network Policy Spec processing,"},{"line_number":49,"context_line":"and the creation or removal of security group with appropriate security group"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_0fe27704","line":46,"range":{"start_line":46,"start_character":0,"end_line":46,"end_character":26},"in_reply_to":"9fb8cfa7_19ae69e7","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":48,"context_line":"This handler is responsible for triggering the Network Policy Spec processing,"},{"line_number":49,"context_line":"and the creation or removal of security group with appropriate security group"},{"line_number":50,"context_line":"rules. It also, applies the security group to the pods and services affected"},{"line_number":51,"context_line":"by the policy."},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"The VIF handler"},{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_d9b7713a","line":51,"range":{"start_line":48,"start_character":0,"end_line":51,"end_character":14},"updated":"2019-06-03 07:21:01.000000000","message":"perhaps worth to add an example of the CRD generated. Here or at the proposed solution section","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":45,"context_line":""},{"line_number":46,"context_line":"The Network Policy handler"},{"line_number":47,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":48,"context_line":"This handler is responsible for triggering the Network Policy Spec processing,"},{"line_number":49,"context_line":"and the creation or removal of security group with appropriate security group"},{"line_number":50,"context_line":"rules. It also, applies the security group to the pods and services affected"},{"line_number":51,"context_line":"by the policy."},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"The VIF handler"},{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_4f306f57","line":51,"range":{"start_line":48,"start_character":0,"end_line":51,"end_character":14},"in_reply_to":"9fb8cfa7_d9b7713a","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":53,"context_line":"The VIF handler"},{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":55,"context_line":"As Network Policy rules can be defined based on pod labels, this handler"},{"line_number":56,"context_line":"has been incremented to trigger a security group rule creation or deletion,"},{"line_number":57,"context_line":"depending on the type of pod event and if the pod affects a Network Policy rule."},{"line_number":58,"context_line":"Also, it triggers the translation of the pod rules to the affected service."},{"line_number":59,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_9927b9b7","line":56,"range":{"start_line":56,"start_character":9,"end_line":56,"end_character":21},"updated":"2019-06-03 07:21:01.000000000","message":"extended?","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":53,"context_line":"The VIF handler"},{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":55,"context_line":"As Network Policy rules can be defined based on pod labels, this handler"},{"line_number":56,"context_line":"has been incremented to trigger a security group rule creation or deletion,"},{"line_number":57,"context_line":"depending on the type of pod event and if the pod affects a Network Policy rule."},{"line_number":58,"context_line":"Also, it triggers the translation of the pod rules to the affected service."},{"line_number":59,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_827deb6f","line":56,"range":{"start_line":56,"start_character":9,"end_line":56,"end_character":21},"in_reply_to":"9fb8cfa7_7f3f45d6","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":14885,"name":"Daniel Mellado","email":"dmellado@redhat.com","username":"daniel-mellado"},"change_message_id":"703e2a50aeed467362684172849dd39926d681a0","unresolved":false,"context_lines":[{"line_number":53,"context_line":"The VIF handler"},{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":55,"context_line":"As Network Policy rules can be defined based on pod labels, this handler"},{"line_number":56,"context_line":"has been incremented to trigger a security group rule creation or deletion,"},{"line_number":57,"context_line":"depending on the type of pod event and if the pod affects a Network Policy rule."},{"line_number":58,"context_line":"Also, it triggers the translation of the pod rules to the affected service."},{"line_number":59,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_7f3f45d6","line":56,"range":{"start_line":56,"start_character":9,"end_line":56,"end_character":21},"in_reply_to":"9fb8cfa7_9927b9b7","updated":"2019-06-03 09:48:07.000000000","message":"maybe just enhanced","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":55,"context_line":"As Network Policy rules can be defined based on pod labels, this handler"},{"line_number":56,"context_line":"has been incremented to trigger a security group rule creation or deletion,"},{"line_number":57,"context_line":"depending on the type of pod event and if the pod affects a Network Policy rule."},{"line_number":58,"context_line":"Also, it triggers the translation of the pod rules to the affected service."},{"line_number":59,"context_line":""},{"line_number":60,"context_line":"The Pod Label handler"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_792685ba","line":57,"range":{"start_line":57,"start_character":39,"end_line":57,"end_character":80},"updated":"2019-06-03 07:21:01.000000000","message":"if the pods is affected by the network policy and a new security group rule is needed","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":54,"context_line":"~~~~~~~~~~~~~~~"},{"line_number":55,"context_line":"As Network Policy rules can be defined based on pod labels, this handler"},{"line_number":56,"context_line":"has been incremented to trigger a security group rule creation or deletion,"},{"line_number":57,"context_line":"depending on the type of pod event and if the pod affects a Network Policy rule."},{"line_number":58,"context_line":"Also, it triggers the translation of the pod rules to the affected service."},{"line_number":59,"context_line":""},{"line_number":60,"context_line":"The Pod Label handler"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_04a49e56","line":57,"range":{"start_line":57,"start_character":39,"end_line":57,"end_character":80},"in_reply_to":"9fb8cfa7_792685ba","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":91,"context_line":"The LBaaS driver"},{"line_number":92,"context_line":"~~~~~~~~~~~~~~~~"},{"line_number":93,"context_line":"To restrict the incoming traffic to the backend pods, the LBaaS driver"},{"line_number":94,"context_line":"has been incremented to translate pods rules to the listener port, and react"},{"line_number":95,"context_line":"to Service ports updates. E.g., when the target port is not allowed by the"},{"line_number":96,"context_line":"policy enforced in the pod, the rule should not be added."},{"line_number":97,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_393d6dbb","line":94,"range":{"start_line":94,"start_character":9,"end_line":94,"end_character":21},"updated":"2019-06-03 07:21:01.000000000","message":"extended","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":14885,"name":"Daniel Mellado","email":"dmellado@redhat.com","username":"daniel-mellado"},"change_message_id":"703e2a50aeed467362684172849dd39926d681a0","unresolved":false,"context_lines":[{"line_number":91,"context_line":"The LBaaS driver"},{"line_number":92,"context_line":"~~~~~~~~~~~~~~~~"},{"line_number":93,"context_line":"To restrict the incoming traffic to the backend pods, the LBaaS driver"},{"line_number":94,"context_line":"has been incremented to translate pods rules to the listener port, and react"},{"line_number":95,"context_line":"to Service ports updates. E.g., when the target port is not allowed by the"},{"line_number":96,"context_line":"policy enforced in the pod, the rule should not be added."},{"line_number":97,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_df2d11a9","line":94,"range":{"start_line":94,"start_character":9,"end_line":94,"end_character":21},"in_reply_to":"9fb8cfa7_393d6dbb","updated":"2019-06-03 09:48:07.000000000","message":"ditto as last comment.","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":91,"context_line":"The LBaaS driver"},{"line_number":92,"context_line":"~~~~~~~~~~~~~~~~"},{"line_number":93,"context_line":"To restrict the incoming traffic to the backend pods, the LBaaS driver"},{"line_number":94,"context_line":"has been incremented to translate pods rules to the listener port, and react"},{"line_number":95,"context_line":"to Service ports updates. E.g., when the target port is not allowed by the"},{"line_number":96,"context_line":"policy enforced in the pod, the rule should not be added."},{"line_number":97,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_c2e8c317","line":94,"range":{"start_line":94,"start_character":9,"end_line":94,"end_character":21},"in_reply_to":"9fb8cfa7_df2d11a9","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":101,"context_line":"to the pods ports. It has been modified to embrace the fact that with Network"},{"line_number":102,"context_line":"Policies pods\u0027 ports changes their security group while being used, meaning the"},{"line_number":103,"context_line":"original pool does not fit them anymore, resulting in useless pools and ports"},{"line_number":104,"context_line":"reapplying the original security group. To avoid it, the security group id"},{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_f95fd50b","line":106,"range":{"start_line":104,"start_character":40,"end_line":106,"end_character":12},"updated":"2019-06-03 07:21:01.000000000","message":"nice that you included this! Please also add the next clarification: \"Thus if there is no ports on the pool with the needed security group id(s), one of the existing ports in the pool is updated to match the requested sg Id.\"","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":101,"context_line":"to the pods ports. It has been modified to embrace the fact that with Network"},{"line_number":102,"context_line":"Policies pods\u0027 ports changes their security group while being used, meaning the"},{"line_number":103,"context_line":"original pool does not fit them anymore, resulting in useless pools and ports"},{"line_number":104,"context_line":"reapplying the original security group. To avoid it, the security group id"},{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_a4b11292","line":106,"range":{"start_line":104,"start_character":40,"end_line":106,"end_character":12},"in_reply_to":"9fb8cfa7_f95fd50b","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"},{"line_number":110,"context_line":"This section describes some scenarios with a Network Policy being enforced,"},{"line_number":111,"context_line":"what Kuryr componenets gets triggered and what resources are created."}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_b9887d71","line":108,"range":{"start_line":108,"start_character":0,"end_line":108,"end_character":18},"updated":"2019-06-03 07:21:01.000000000","message":"perhaps worth to add the table we had at a google doc, with the different cases and the actions associated","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"fdf0bb0f2dbfa35fc166e1d3eaade155bc98edd9","unresolved":false,"context_lines":[{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"},{"line_number":110,"context_line":"This section describes some scenarios with a Network Policy being enforced,"},{"line_number":111,"context_line":"what Kuryr componenets gets triggered and what resources are created."}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_bd3a93e4","line":108,"range":{"start_line":108,"start_character":0,"end_line":108,"end_character":18},"in_reply_to":"9fb8cfa7_28cc3588","updated":"2019-06-04 06:52:21.000000000","message":"yes!","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":14885,"name":"Daniel Mellado","email":"dmellado@redhat.com","username":"daniel-mellado"},"change_message_id":"703e2a50aeed467362684172849dd39926d681a0","unresolved":false,"context_lines":[{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"},{"line_number":110,"context_line":"This section describes some scenarios with a Network Policy being enforced,"},{"line_number":111,"context_line":"what Kuryr componenets gets triggered and what resources are created."}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_bf1e1d6e","line":108,"range":{"start_line":108,"start_character":0,"end_line":108,"end_character":18},"in_reply_to":"9fb8cfa7_b9887d71","updated":"2019-06-03 09:48:07.000000000","message":"+1","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"bc59bb20de2dd9e79e85dd3e0781c2ecde7a3b3e","unresolved":false,"context_lines":[{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"},{"line_number":110,"context_line":"This section describes some scenarios with a Network Policy being enforced,"},{"line_number":111,"context_line":"what Kuryr componenets gets triggered and what resources are created."}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_28cc3588","line":108,"range":{"start_line":108,"start_character":0,"end_line":108,"end_character":18},"in_reply_to":"9fb8cfa7_b9887d71","updated":"2019-06-03 12:22:24.000000000","message":"Do you mean the one with the selector cases and policy types?","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":105,"context_line":"is removed from the pool merging all pools with same network, project"},{"line_number":106,"context_line":"and host id."},{"line_number":107,"context_line":""},{"line_number":108,"context_line":"Use cases examples"},{"line_number":109,"context_line":"++++++++++++++++++"},{"line_number":110,"context_line":"This section describes some scenarios with a Network Policy being enforced,"},{"line_number":111,"context_line":"what Kuryr componenets gets triggered and what resources are created."}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_8a6095d0","line":108,"range":{"start_line":108,"start_character":0,"end_line":108,"end_character":18},"in_reply_to":"9fb8cfa7_b9887d71","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":14885,"name":"Daniel Mellado","email":"dmellado@redhat.com","username":"daniel-mellado"},"change_message_id":"703e2a50aeed467362684172849dd39926d681a0","unresolved":false,"context_lines":[{"line_number":113,"context_line":"Deny all incoming traffic"},{"line_number":114,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"By default, Kubernetes clusters do no restrict traffic. Only once a network"},{"line_number":117,"context_line":"policy is enforced to a namespace, all traffic not explicitly allowed in the"},{"line_number":118,"context_line":"policy becomes denied. As specified in the following policy:"},{"line_number":119,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_7f18a580","line":116,"range":{"start_line":116,"start_character":32,"end_line":116,"end_character":37},"updated":"2019-06-03 09:48:07.000000000","message":"do not or don\u0027t","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":113,"context_line":"Deny all incoming traffic"},{"line_number":114,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"By default, Kubernetes clusters do no restrict traffic. Only once a network"},{"line_number":117,"context_line":"policy is enforced to a namespace, all traffic not explicitly allowed in the"},{"line_number":118,"context_line":"policy becomes denied. As specified in the following policy:"},{"line_number":119,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_6476ba09","line":116,"range":{"start_line":116,"start_character":32,"end_line":116,"end_character":37},"in_reply_to":"9fb8cfa7_7f18a580","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"ceae7abdf1fdf55edfc8ce3dbc3ecada08b73649","unresolved":false,"context_lines":[{"line_number":128,"context_line":"          policyTypes:"},{"line_number":129,"context_line":"          - Ingress"},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The following CRD is the translation of policy rules to security group rules."},{"line_number":132,"context_line":"No ingress rule was created, which means traffic is blocked, and since"},{"line_number":133,"context_line":"there is no restriction for egress traffic, it is allowed to everywhere."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"    .. code-block:: yaml"},{"line_number":136,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_79820552","line":133,"range":{"start_line":131,"start_character":0,"end_line":133,"end_character":72},"updated":"2019-06-03 07:21:01.000000000","message":"note the same will be try if the policyTypes are not included, as ingress is the default","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":27032,"name":"Maysa de Macedo Souza","email":"maysa.macedo95@gmail.com","username":"maysa"},"change_message_id":"d914b0a8b64892bb8a6a9ad0640b62456f7dcdff","unresolved":false,"context_lines":[{"line_number":128,"context_line":"          policyTypes:"},{"line_number":129,"context_line":"          - Ingress"},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The following CRD is the translation of policy rules to security group rules."},{"line_number":132,"context_line":"No ingress rule was created, which means traffic is blocked, and since"},{"line_number":133,"context_line":"there is no restriction for egress traffic, it is allowed to everywhere."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"    .. code-block:: yaml"},{"line_number":136,"context_line":""}],"source_content_type":"text/x-rst","patch_set":5,"id":"9fb8cfa7_afaecbe4","line":133,"range":{"start_line":131,"start_character":0,"end_line":133,"end_character":72},"in_reply_to":"9fb8cfa7_79820552","updated":"2019-06-04 20:10:11.000000000","message":"Done","commit_id":"5f454a6abf40a8139e3662bfd3e1eb1e8732f797"},{"author":{"_account_id":23567,"name":"Luis Tomas Bolivar","email":"ltomasbo@redhat.com","username":"ltomasbo"},"change_message_id":"e0bc7734a2a6d3b23ce9373a170bf974b1a4fd88","unresolved":false,"context_lines":[{"line_number":367,"context_line":"namespaceSelector: ns1                             Allow traffic from all pods at ns1"},{"line_number":368,"context_line":"namespaceSelector: {}     podSelector: pod1        Allow traffic from pod1 from all namespaces"},{"line_number":369,"context_line":"namespaceSelector: {}     podSelector: {}          Allow traffic from all namespaces"},{"line_number":370,"context_line":"namespaceSelector: {}                              Allow traffic from all namespaces"},{"line_number":371,"context_line":"                          podSelector: pod1        Allow traffic from pod1 from NP namespace"},{"line_number":372,"context_line":"                          podSelector: {}          Allow traffic from all pods from NP namespace"},{"line_number":373,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d  \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d  \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":374,"context_line":""},{"line_number":375,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d  \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":8,"id":"9fb8cfa7_3ec75d48","line":372,"range":{"start_line":370,"start_character":0,"end_line":372,"end_character":96},"updated":"2019-06-05 12:59:31.000000000","message":"this are not properly rendered:\nhttp://logs.openstack.org/89/661989/8/check/openstack-tox-docs/da5d37d/html/devref/network_policy.html","commit_id":"04c46af16397171c22b33f705aa0ee19773e1122"}]}
