Skip to content
2 changes: 1 addition & 1 deletion charts/rhdh/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
apiVersion: v2
name: redhat-developer-hub
type: application
version: 3.5.3
version: 3.5.4
appVersion: 2.2.0
annotations:
artifacthub.io/category: integration-delivery
Expand Down
17 changes: 15 additions & 2 deletions charts/rhdh/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@

# RHDH Helm Chart for OpenShift and Kubernetes

![Version: 3.5.3](https://img.shields.io/badge/Version-3.5.3-informational?style=flat-square)
![Version: 3.5.4](https://img.shields.io/badge/Version-3.5.4-informational?style=flat-square)
![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square)

A Helm chart for deploying Red Hat Developer Hub, which is a Red Hat supported version of Backstage.
Expand Down Expand Up @@ -36,7 +36,7 @@ For the **Generally Available** version of this chart, see:
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo add redhat-developer https://redhat-developer.github.io/rhdh-chart

helm install my-rhdh redhat-developer/redhat-developer-hub --version 3.5.3
helm install my-rhdh redhat-developer/redhat-developer-hub --version 3.5.4
```

## Introduction
Expand Down Expand Up @@ -564,6 +564,8 @@ extraDeploy:

This chart deploys a **default-deny** NetworkPolicy for the RHDH backend pod, blocking all ingress and egress traffic that is not explicitly allowed. When the built-in PostgreSQL is enabled (`postgresql.enabled=true`), the database pods also get their own default-deny policy with selective allow rules. When OKP is active, its pods receive a separate default-deny ingress and egress policy with rules allowing only the required HTTP ingress.

When `orchestrator.enabled=true`, the chart also creates NetworkPolicies for SonataFlow-managed pods (`app.kubernetes.io/managed-by: sonataflow-operator`) and for RHDH-to-SonataFlow access on port 80; when the built-in PostgreSQL is also enabled, it adds a PostgreSQL ingress allow for those SonataFlow pods and the Orchestrator create-db Job. These policies are label-scoped and do not use namespace-wide `podSelector: {}`.

The following traffic is allowed out of the box:

| Direction | Port | Destination / Source | Purpose |
Expand All @@ -577,11 +579,21 @@ The following traffic is allowed out of the box:
| Ingress | 7007 (TCP) | OpenShift router namespace or any namespace (non-OCP) | User traffic via Route / Ingress |
| Ingress | 8080 (TCP) | RHDH pods and the OpenShift router namespace or any namespace (non-OCP) | OKP queries and product-document citations via Route / Ingress |
| Ingress | 9464 (TCP) | `openshift-monitoring`, `openshift-user-workload-monitoring`, `gmp-system`, `gke-gmp-system`, `monitoring` | Prometheus metrics scraping |
| Ingress | 80 (TCP) | OpenShift router namespace → SonataFlow pods | Orchestrator / SonataFlow Routes (NP created only when `orchestrator.enabled=true`) |
| Ingress | 80 (TCP) | RHDH pods → SonataFlow pods | Orchestrator backend to Data Index / workflows (NP created only when `orchestrator.enabled=true`) |
| Ingress | 80 (TCP) | SonataFlow pods → SonataFlow pods | SonataFlow inter-pod traffic (NP created only when `orchestrator.enabled=true`) |
| Ingress | any | `knative-eventing`, `knative-serving`, `openshift-serverless-logic` → SonataFlow pods | Orchestrator infra namespaces (NP created only when `orchestrator.enabled=true`) |
| Ingress | any | `openshift-user-workload-monitoring` → SonataFlow pods | SonataFlow metrics scrape (NP created only when `orchestrator.enabled=true` and `orchestrator.sonataflowPlatform.monitoring.enabled=true`) |
| Egress | 80 (TCP) | RHDH pods → SonataFlow pods | Orchestrator backend HTTP to SonataFlow / Data Index (NP created only when `orchestrator.enabled=true`) |
| Egress | any | SonataFlow pods → any | SonataFlow / workflow outbound access (NP created only when `orchestrator.enabled=true`) |
| Ingress | 5432 (TCP) | SonataFlow pods and Orchestrator create-db Job → built-in PostgreSQL primary | Orchestrator / SonataFlow database access (NP created only when `orchestrator.enabled=true` and `postgresql.enabled=true`) |

OKP initiates no outbound connections: its HTTP server and Solr process run in the same pod and serve the documentation embedded in the image. Its default-deny policy therefore blocks all new egress connections. NetworkPolicy is stateful, so response traffic for allowed ingress connections remains permitted.

RHDH already permits HTTPS egress on port 443. When OKP uses HTTP instead, the chart permits RHDH egress on port 80 for a Kubernetes Ingress or restricts port 8080 egress to OKP pods for the internal Service fallback. No additional RHDH egress policy is created when `OKP_SERVICE_URL` uses HTTPS.

When Orchestrator is enabled (`orchestrator.enabled=true`), the chart creates additional NetworkPolicies scoped to pods labeled `app.kubernetes.io/managed-by: sonataflow-operator` (Data Index, Jobs Service, and workflow pods managed by the SonataFlow Operator). These allow ingress from the Knative Eventing/Serving and OpenShift Serverless Logic namespaces, from the OpenShift router on port 80, from other SonataFlow pods on port 80, and (when `orchestrator.sonataflowPlatform.monitoring.enabled=true`) from `openshift-user-workload-monitoring`. SonataFlow pods also receive unrestricted egress. Separately, the RHDH backend pod (selected via `rhdh.selectorLabels`) is allowed to reach SonataFlow pods on port 80 (RHDH egress and matching SonataFlow ingress) so the Orchestrator plugins can reach Data Index and workflow services. When the built-in PostgreSQL is enabled (`postgresql.enabled=true`), Postgres also admits TCP/5432 from SonataFlow-managed pods and from the Orchestrator create-db Job (labeled `rhdh.redhat.com/orchestrator-db-job: "true"`), in addition to the existing RHDH backend allow. The chart does not create a default-deny NetworkPolicy for SonataFlow pods.

**Redis egress is intentionally unscoped.** RHDH does not deploy Redis; users bring their own instance, which may live in the same namespace, a different namespace, or an external managed service. The rule therefore allows egress on port 6379 to any destination.

**Bitnami subchart NetworkPolicies are disabled** (`postgresql.primary.networkPolicy.enabled=false`, `postgresql.readReplicas.networkPolicy.enabled=false`) because this chart provides its own tighter policies for the built-in database pods.
Expand Down Expand Up @@ -672,6 +684,7 @@ helm install <release_name> redhat-developer/redhat-developer-hub-orchestrator-i
```
helm install <release_name> redhat-developer/redhat-developer-hub --set orchestrator.enabled=true
```
Enabling Orchestrator also creates label-scoped NetworkPolicies for SonataFlow-managed pods, for RHDH access to SonataFlow on port 80, and (when built-in PostgreSQL is enabled) for SonataFlow and create-db Job access to Postgres on TCP/5432; they are not namespace-wide. See [NetworkPolicies](#networkpolicies) for details.
Note that serverlessLogicOperator, and serverlessOperator are enabled by default. They can be disabled together or seperately by passing the following flags:
`--set orchestrator.serverlessLogicOperator.enabled=false --set orchestrator.serverlessOperator.enabled=false`

Expand Down
13 changes: 13 additions & 0 deletions charts/rhdh/README.md.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -392,6 +392,8 @@ extraDeploy:

This chart deploys a **default-deny** NetworkPolicy for the RHDH backend pod, blocking all ingress and egress traffic that is not explicitly allowed. When the built-in PostgreSQL is enabled (`postgresql.enabled=true`), the database pods also get their own default-deny policy with selective allow rules. When OKP is active, its pods receive a separate default-deny ingress and egress policy with rules allowing only the required HTTP ingress.

When `orchestrator.enabled=true`, the chart also creates NetworkPolicies for SonataFlow-managed pods (`app.kubernetes.io/managed-by: sonataflow-operator`) and for RHDH-to-SonataFlow access on port 80; when the built-in PostgreSQL is also enabled, it adds a PostgreSQL ingress allow for those SonataFlow pods and the Orchestrator create-db Job. These policies are label-scoped and do not use namespace-wide `podSelector: {}`.

The following traffic is allowed out of the box:

| Direction | Port | Destination / Source | Purpose |
Expand All @@ -405,11 +407,21 @@ The following traffic is allowed out of the box:
| Ingress | 7007 (TCP) | OpenShift router namespace or any namespace (non-OCP) | User traffic via Route / Ingress |
| Ingress | 8080 (TCP) | RHDH pods and the OpenShift router namespace or any namespace (non-OCP) | OKP queries and product-document citations via Route / Ingress |
| Ingress | 9464 (TCP) | `openshift-monitoring`, `openshift-user-workload-monitoring`, `gmp-system`, `gke-gmp-system`, `monitoring` | Prometheus metrics scraping |
| Ingress | 80 (TCP) | OpenShift router namespace → SonataFlow pods | Orchestrator / SonataFlow Routes (NP created only when `orchestrator.enabled=true`) |
| Ingress | 80 (TCP) | RHDH pods → SonataFlow pods | Orchestrator backend to Data Index / workflows (NP created only when `orchestrator.enabled=true`) |
| Ingress | 80 (TCP) | SonataFlow pods → SonataFlow pods | SonataFlow inter-pod traffic (NP created only when `orchestrator.enabled=true`) |
| Ingress | any | `knative-eventing`, `knative-serving`, `openshift-serverless-logic` → SonataFlow pods | Orchestrator infra namespaces (NP created only when `orchestrator.enabled=true`) |
| Ingress | any | `openshift-user-workload-monitoring` → SonataFlow pods | SonataFlow metrics scrape (NP created only when `orchestrator.enabled=true` and `orchestrator.sonataflowPlatform.monitoring.enabled=true`) |
| Egress | 80 (TCP) | RHDH pods → SonataFlow pods | Orchestrator backend HTTP to SonataFlow / Data Index (NP created only when `orchestrator.enabled=true`) |
| Egress | any | SonataFlow pods → any | SonataFlow / workflow outbound access (NP created only when `orchestrator.enabled=true`) |
| Ingress | 5432 (TCP) | SonataFlow pods and Orchestrator create-db Job → built-in PostgreSQL primary | Orchestrator / SonataFlow database access (NP created only when `orchestrator.enabled=true` and `postgresql.enabled=true`) |

OKP initiates no outbound connections: its HTTP server and Solr process run in the same pod and serve the documentation embedded in the image. Its default-deny policy therefore blocks all new egress connections. NetworkPolicy is stateful, so response traffic for allowed ingress connections remains permitted.

RHDH already permits HTTPS egress on port 443. When OKP uses HTTP instead, the chart permits RHDH egress on port 80 for a Kubernetes Ingress or restricts port 8080 egress to OKP pods for the internal Service fallback. No additional RHDH egress policy is created when `OKP_SERVICE_URL` uses HTTPS.

When Orchestrator is enabled (`orchestrator.enabled=true`), the chart creates additional NetworkPolicies scoped to pods labeled `app.kubernetes.io/managed-by: sonataflow-operator` (Data Index, Jobs Service, and workflow pods managed by the SonataFlow Operator). These allow ingress from the Knative Eventing/Serving and OpenShift Serverless Logic namespaces, from the OpenShift router on port 80, from other SonataFlow pods on port 80, and (when `orchestrator.sonataflowPlatform.monitoring.enabled=true`) from `openshift-user-workload-monitoring`. SonataFlow pods also receive unrestricted egress. Separately, the RHDH backend pod (selected via `rhdh.selectorLabels`) is allowed to reach SonataFlow pods on port 80 (RHDH egress and matching SonataFlow ingress) so the Orchestrator plugins can reach Data Index and workflow services. When the built-in PostgreSQL is enabled (`postgresql.enabled=true`), Postgres also admits TCP/5432 from SonataFlow-managed pods and from the Orchestrator create-db Job (labeled `rhdh.redhat.com/orchestrator-db-job: "true"`), in addition to the existing RHDH backend allow. The chart does not create a default-deny NetworkPolicy for SonataFlow pods.

**Redis egress is intentionally unscoped.** RHDH does not deploy Redis; users bring their own instance, which may live in the same namespace, a different namespace, or an external managed service. The rule therefore allows egress on port 6379 to any destination.

**Bitnami subchart NetworkPolicies are disabled** (`postgresql.primary.networkPolicy.enabled=false`, `postgresql.readReplicas.networkPolicy.enabled=false`) because this chart provides its own tighter policies for the built-in database pods.
Expand Down Expand Up @@ -500,6 +512,7 @@ helm install <release_name> redhat-developer/redhat-developer-hub-orchestrator-i
```
helm install <release_name> redhat-developer/redhat-developer-hub --set orchestrator.enabled=true
```
Enabling Orchestrator also creates label-scoped NetworkPolicies for SonataFlow-managed pods, for RHDH access to SonataFlow on port 80, and (when built-in PostgreSQL is enabled) for SonataFlow and create-db Job access to Postgres on TCP/5432; they are not namespace-wide. See [NetworkPolicies](#networkpolicies) for details.
Note that serverlessLogicOperator, and serverlessOperator are enabled by default. They can be disabled together or seperately by passing the following flags:
`--set orchestrator.serverlessLogicOperator.enabled=false --set orchestrator.serverlessOperator.enabled=false`

Expand Down
33 changes: 33 additions & 0 deletions charts/rhdh/templates/network-policies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -360,6 +360,39 @@ spec:
ports:
- port: 5432
protocol: TCP
{{- if .Values.orchestrator.enabled }}
---
# Allow SonataFlow-managed pods and the Orchestrator create-db job to reach the built-in PostgreSQL.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "rhdh.fullname" . }}-db-allow-sonataflow-ingress
labels:
{{- include "rhdh.labels" . | nindent 4 }}
{{- with .Values.commonAnnotations }}
annotations:
{{- include "common.tplvalues.render" (dict "value" . "context" $) | nindent 4 }}
{{- end }}
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: postgresql
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/component: primary
policyTypes:
- Ingress
ingress:
- from:
- podSelector:
matchLabels:
app.kubernetes.io/managed-by: sonataflow-operator
- podSelector:
matchLabels:
rhdh.redhat.com/orchestrator-db-job: "true"
ports:
- port: 5432
protocol: TCP
{{- end }}

{{- if $isReplication }}

Expand Down
Loading
Loading