请用户确保仅允许指定访问者(如:ISV前端,推理容器) 访问AI-VAULT的服务,以下为网络策略示例,用于限制对AI-VAULT的访问,用户应按照自身安全配置要求和网络配置情况进行相关修改。
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: ai-vault-network-policy namespace: mindx spec: podSelector: matchLabels: app: ai-vault policyTypes: - Ingress ingress: - from: - namespaceSelector: matchLabels: name: mindx podSelector: matchLabels: app: apigw ports: - protocol: TCP port: 8180
kubectl apply -f ai-vault-network-policy.yaml
kubectl get networkpolicy -n mindx