Skip to content

feat(eks): enable VPC CNI NetworkPolicy enforcement (DND-1082) - #52

Merged
CRThaze merged 1 commit into
mainfrom
CRThaze/DND-1082/eks-enable-network-policy
Jul 29, 2026
Merged

CRThaze merged 1 commit into
mainfrom
CRThaze/DND-1082/eks-enable-network-policy

Conversation

@CRThaze

@CRThaze CRThaze commented Jul 29, 2026 •

Copy link
Copy Markdown

User description

What

Adds eks_enable_network_policy (default true) and wires it into the vpc-cni managed addon as configuration_values = jsonencode({ enableNetworkPolicy = "true" }).

Why (DND-1082)

Audit of the STSaaS fleet found the vpc-cni addon has no configurationValues on every cluster → Kubernetes NetworkPolicy enforcement is off fleet-wide. NetworkPolicy objects are created but silently ignored — e.g. cisco's existing PP-engine egress policy (DND-1396) is currently inert. This flips the CNI on so the planned opik-python-backend / PP-engine / Ollie-engine egress policies actually take effect.

Behavior / rollout note

Default true means: on the next apply (or module-ref bump) for any consumer, the CNI node-agent (aws-eks-nodeagent) turns on. Enforcement is a safe superset — a NetworkPolicy only restricts pods it explicitly selects; pods with no matching policy stay fully open. The one live effect today is that cisco's existing PP-engine policy becomes enforced. Set eks_enable_network_policy = false per env to opt out.

Changes

  • modules/comet_eks/main.tf — vpc-cni addon entry becomes a merge() that adds configuration_values = jsonencode({ enableNetworkPolicy = "true" }) when the toggle is on (still before_compute = true).
  • modules/comet_eks/variables.tf + root variables.tf — new eks_enable_network_policy (bool, default true).
  • root main.tf — passthrough into module "comet_eks".

Validation

CI (terraform_validate + tflint) covers this. Underlying terraform-aws-modules/eks/aws ~> 21.24.0 supports configuration_values on before_compute addons.

Note: README ## Inputs is terraform-docs-style but already stale (missing eks_enable_metrics_server and other recent eks_enable_* vars) and pre-commit does not run terraform-docs, so it was left untouched to match prior additions. Regenerate separately if desired.

Ref: DND-1082


Generated description

Below is a concise technical summary of the changes proposed in this PR:
Enable Kubernetes NetworkPolicy enforcement in the comet_eks module by setting enableNetworkPolicy=true on the vpc-cni managed addon. Add and pass through the eks_enable_network_policy toggle, defaulting to true, so consumers can opt out while the root main.tf wires the new input into the module.

TopicDetails
Policy enforcement Enable vpc-cni NetworkPolicy enforcement by merging addon configuration_values when eks_enable_network_policy is on.
Modified files (1)
  • modules/comet_eks/main.tf
Latest Contributors(2)
UserCommitDate
diego@crthaze.comfeat(eks): enable VPC ...July 29, 2026
alexb@comet.comfeat(eks): Auto Mode, ...July 28, 2026
Input wiring Add the eks_enable_network_policy variable and thread it from the root module into comet_eks.
Modified files (3)
  • main.tf
  • modules/comet_eks/variables.tf
  • variables.tf
Latest Contributors(2)
UserCommitDate
diego@crthaze.comfeat(eks): enable VPC ...July 29, 2026
darenjacobs@msn.comdefault rds_backup_ret...July 28, 2026
Review this PR on Baz | Customize your next review

@CRThaze
CRThaze force-pushed the CRThaze/DND-1082/eks-enable-network-policy branch 2 times, most recently from dfb159f to 298e48b Compare July 29, 2026 13:39
@CRThaze
CRThaze marked this pull request as ready for review July 29, 2026 14:07
Add eks_enable_network_policy (default true), wired into the vpc-cni
managed addon as configuration_values={enableNetworkPolicy:"true"}.

Without this the CNI runs at AWS defaults and NetworkPolicy objects are
created but silently not enforced — so the opik-python-backend, PP-engine
and Ollie-engine egress policies (DND-1082) have no effect. Enforcement is
a safe superset: a NetworkPolicy only restricts pods it explicitly selects;
unselected pods remain fully open.

Overridable per env (set false to keep enforcement off).
@CRThaze
CRThaze force-pushed the CRThaze/DND-1082/eks-enable-network-policy branch from 298e48b to b940ac0 Compare July 29, 2026 14:10

@jms200 jms200 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants