Add support to configure kuryr with the network policy handler and the related drivers to provide fine grain isolation. It also enables the support to configure network policy together with the network per namespace feature -- but without enabling the namespace isolation as the network policies will be the ones defining the isolation between pods/projects.
juriarte, could you help to verify it ASAP? As you know, the bug has been attached in next coming 3.11.z release errata. Thanks
(In reply to shahan from comment #2) > juriarte, could you help to verify it ASAP? As you know, the bug has been > attached in next coming 3.11.z release errata. Thanks This OCP RFE depends on an OSP RFE [1], which is targeted for OSP 15, and we do not have a build with it for the moment. We will verify this one once the RFE in OSP is delivered. Thank you [1] https://bugzilla.redhat.com/show_bug.cgi?id=1504090
This will not be supported with 3.x but is being investigated for OpenShift 4.x
@Eric: Just to make it clear. The bits to support network policies on the openshift-ansible side are already there. The problem is there is also code that must be modified on kuryr-kubernetes side of things. That code is already there (the other bugzilla this one points) but still needs QE work and be released. So that is why the target for this work is not 3.11 but 4.X
At the moment kuryr images in 3.11 don't support NP features, only images taken from 4.x So if it's gonna be supported in 3.11 we need to have kuryr images to test it. Till those images are not in the repo the bz should not be on QA