Docs/pages site and cleanup - #10
Merged
Merged
Conversation
…Action Remove the per-rule match.pod field (and api/v1.PodSelector) from the CRD: source-pod selection is now solely the NetworkPolicy-style top-level spec.podSelector. ToPolicy leaves Match.Pod zero and Aggregate/Flatten fold the subject into it, so the internal enforcement primitive is unchanged. Also document that defaultAction is optional (empty => Allow/blocklist) and picks the posture rather than being inferred from rule presence. Regenerate deepcopy + CRDs and sync the Helm chart copies.
Reframe ROADMAP.md into Today + Planned and drop the leftover "Stage 3" marker from the CRD e2e job comment.
A self-contained Jekyll site (custom layouts + honeycomb dark theme) that renders the existing markdown docs and adds a branded landing page using the logo. Enable via Settings > Pages (branch main, folder /docs). Point the few cross-repo doc links at GitHub so they don't 404 on the published site, and add a website badge to the README.
…ch.pod Test 3 scoped its deny rule with the per-rule match.pod field, which the CRD no longer accepts (strict decode: unknown field spec.rules[0].match.pod). Label the probe pod app=probe and scope the policy via the top-level spec.podSelector — the same label-based selection Test 6 already exercises.
The chart defaulted images to appVersion (0.1.0), but CI only publishes :0.1.0 on a vX.Y.Z git tag (none exists), so a default helm install hit ImagePullBackOff. Default the tag to :latest (published on every main push). pullPolicy now defaults to Always for the floating :latest tag and IfNotPresent for a pinned tag, so locally-imported dev images (test/crd.sh, the k3d dev loop) are still used instead of a registry pull; an explicit pullPolicy is honored.
Replace the ASCII architecture diagram with a Mermaid flowchart (GitHub renders it; the README isn't part of the Jekyll docs site). Add headers to the visibility list and a scoped note that ebfw sees HTTP paths/headers and matches method/path in policy, with in-kernel L7 enforcement on the roadmap (it's observe/evaluate-only today, not a kernel drop).
The README noted L7 path/method enforcement is planned, but the roadmap only listed the Host/SNI drop backstop and request modify. Add an explicit 'L7 (method/path) policy enforcement' item (kernel Host/SNI backstop + terminating L7 proxy for full path/header semantics), and drop 'in-kernel' from the README clause since full method/path enforcement needs the proxy, not just the kernel.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.