Repository navigation
feat(eks): enable VPC CNI NetworkPolicy enforcement (DND-1082) - #52
Merged
Merged
Conversation
CRThaze
force-pushed
the
CRThaze/DND-1082/eks-enable-network-policy
branch
2 times, most recently
from
July 29, 2026 13:39
dfb159f to
298e48b
Compare
CRThaze
marked this pull request as ready for review
July 29, 2026 14:07
Add eks_enable_network_policy (default true), wired into the vpc-cni
managed addon as configuration_values={enableNetworkPolicy:"true"}.
Without this the CNI runs at AWS defaults and NetworkPolicy objects are
created but silently not enforced — so the opik-python-backend, PP-engine
and Ollie-engine egress policies (DND-1082) have no effect. Enforcement is
a safe superset: a NetworkPolicy only restricts pods it explicitly selects;
unselected pods remain fully open.
Overridable per env (set false to keep enforcement off).
CRThaze
force-pushed
the
CRThaze/DND-1082/eks-enable-network-policy
branch
from
July 29, 2026 14:10
298e48b to
b940ac0
Compare
This was referenced Jul 31, 2026
This was referenced Aug 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
What
Adds
eks_enable_network_policy(defaulttrue) and wires it into thevpc-cnimanaged addon asconfiguration_values = jsonencode({ enableNetworkPolicy = "true" }).Why (DND-1082)
Audit of the STSaaS fleet found the
vpc-cniaddon has noconfigurationValueson every cluster → Kubernetes NetworkPolicy enforcement is off fleet-wide. NetworkPolicy objects are created but silently ignored — e.g. cisco's existing PP-engine egress policy (DND-1396) is currently inert. This flips the CNI on so the planned opik-python-backend / PP-engine / Ollie-engine egress policies actually take effect.Behavior / rollout note
Default
truemeans: on the next apply (or module-ref bump) for any consumer, the CNI node-agent (aws-eks-nodeagent) turns on. Enforcement is a safe superset — a NetworkPolicy only restricts pods it explicitly selects; pods with no matching policy stay fully open. The one live effect today is that cisco's existing PP-engine policy becomes enforced. Seteks_enable_network_policy = falseper env to opt out.Changes
modules/comet_eks/main.tf—vpc-cniaddon entry becomes amerge()that addsconfiguration_values = jsonencode({ enableNetworkPolicy = "true" })when the toggle is on (stillbefore_compute = true).modules/comet_eks/variables.tf+ rootvariables.tf— neweks_enable_network_policy(bool, defaulttrue).main.tf— passthrough intomodule "comet_eks".Validation
CI (
terraform_validate+tflint) covers this. Underlyingterraform-aws-modules/eks/aws ~> 21.24.0supportsconfiguration_valuesonbefore_computeaddons.Ref: DND-1082
Generated description
Below is a concise technical summary of the changes proposed in this PR:
Enable Kubernetes NetworkPolicy enforcement in the
comet_eksmodule by settingenableNetworkPolicy=trueon thevpc-cnimanaged addon. Add and pass through theeks_enable_network_policytoggle, defaulting totrue, so consumers can opt out while the rootmain.tfwires the new input into the module.vpc-cniNetworkPolicy enforcement by merging addonconfiguration_valueswheneks_enable_network_policyis on.Modified files (1)
Latest Contributors(2)
eks_enable_network_policyvariable and thread it from the root module intocomet_eks.Modified files (3)
Latest Contributors(2)