Bug Reports
Planned

Shared cache chart: networkPolicy values render nothing

The shared cache Helm chart exposes a networkPolicy block (enabled, ingress, egress) and it produces no output at all.

The only NetworkPolicy template anywhere in the chart dependency tree belongs to the VPN addon and keys off addons.vpn.networkPolicy. Nothing reads the top-level networkPolicy values, so setting networkPolicy.enabled: true is silently inert - no error, no warning, no resource.

Verified by rendering the chart with the block fully populated: zero NetworkPolicy resources in the output.

Why it matters: restricting access to the cache port is step three of the platform security remediation, and it cannot currently be done through the chart as written. Every consumer would have to write the policy into its own chart instead.

This is the same class of defect as the authentication one - values that look supported, are accepted without complaint, and do nothing. The fix is a real NetworkPolicy template driven by the top-level values.

0 Comments

Sign in to comment

No comments yet. Be the first to share your thoughts!