Allow SecurityService egress to the dev machine agent, and apply policies from CI

FixKlusterServices
Ya
15 Agosti 2026, 21:45 UTC
Mwandishi
Kamo
Ahadi ya
872743e

Cilium egress is default-deny for every endpoint it selects, and toEndpoints:[{}] is scoped to the policy's OWN namespace — so SecurityService could not reach desktop-1-agent:9800 and reported the machine offline while it was healthy. The symptom is a connect timeout, not a refusal, so it reads as the far end being down. Also removes **************** it declared the SAME object as kamo-egress.yaml, so applying the directory made the two fight with alphabetical order deciding the winner. It was the stale copy — it still listed the retired CockroachDB port 26257. networkpolicies/ is now a CI apply target; it was applied by hand before, which is how that drift survived.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei