Skip to content

Docs/pages site and cleanup - #10

Merged
dvrkn merged 7 commits into
mainfrom
docs/pages-site-and-cleanup
Jun 29, 2026
Merged

dvrkn merged 7 commits into
mainfrom
docs/pages-site-and-cleanup

Conversation

@dvrkn

@dvrkn dvrkn commented Jun 29, 2026

Copy link
Copy Markdown
Owner

No description provided.

dvrkni added 7 commits June 29, 2026 13:36
…Action

Remove the per-rule match.pod field (and api/v1.PodSelector) from the CRD: source-pod selection is now solely the NetworkPolicy-style top-level spec.podSelector. ToPolicy leaves Match.Pod zero and Aggregate/Flatten fold the subject into it, so the internal enforcement primitive is unchanged.

Also document that defaultAction is optional (empty => Allow/blocklist) and picks the posture rather than being inferred from rule presence. Regenerate deepcopy + CRDs and sync the Helm chart copies.
Reframe ROADMAP.md into Today + Planned and drop the leftover "Stage 3" marker from the CRD e2e job comment.
A self-contained Jekyll site (custom layouts + honeycomb dark theme) that renders the existing markdown docs and adds a branded landing page using the logo. Enable via Settings > Pages (branch main, folder /docs).

Point the few cross-repo doc links at GitHub so they don't 404 on the published site, and add a website badge to the README.
…ch.pod

Test 3 scoped its deny rule with the per-rule match.pod field, which the CRD no longer accepts (strict decode: unknown field spec.rules[0].match.pod). Label the probe pod app=probe and scope the policy via the top-level spec.podSelector — the same label-based selection Test 6 already exercises.
The chart defaulted images to appVersion (0.1.0), but CI only publishes :0.1.0 on a vX.Y.Z git tag (none exists), so a default helm install hit ImagePullBackOff. Default the tag to :latest (published on every main push).

pullPolicy now defaults to Always for the floating :latest tag and IfNotPresent for a pinned tag, so locally-imported dev images (test/crd.sh, the k3d dev loop) are still used instead of a registry pull; an explicit pullPolicy is honored.
Replace the ASCII architecture diagram with a Mermaid flowchart (GitHub renders it; the README isn't part of the Jekyll docs site). Add headers to the visibility list and a scoped note that ebfw sees HTTP paths/headers and matches method/path in policy, with in-kernel L7 enforcement on the roadmap (it's observe/evaluate-only today, not a kernel drop).
The README noted L7 path/method enforcement is planned, but the roadmap only listed the Host/SNI drop backstop and request modify. Add an explicit 'L7 (method/path) policy enforcement' item (kernel Host/SNI backstop + terminating L7 proxy for full path/header semantics), and drop 'in-kernel' from the README clause since full method/path enforcement needs the proxy, not just the kernel.
@dvrkn
dvrkn merged commit fb2a5dd into main Jun 29, 2026
5 checks passed
dvrkn added a commit that referenced this pull request Jun 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants