diff --git a/pkg/resourcegenerator/networkpolicy/defaultdeny/default_deny_network_policy.go b/pkg/resourcegenerator/networkpolicy/defaultdeny/default_deny_network_policy.go index 823841d6..49c518f7 100644 --- a/pkg/resourcegenerator/networkpolicy/defaultdeny/default_deny_network_policy.go +++ b/pkg/resourcegenerator/networkpolicy/defaultdeny/default_deny_network_policy.go @@ -34,6 +34,24 @@ func Generate(r reconciliation.Reconciliation) error { CIDR: "10.40.0.0/16", }, }, + // Egress rule for internal load balancer on atgcp1-sandbox + { + IPBlock: &networkingv1.IPBlock{ + CIDR: "10.142.5.0/28", + }, + }, + // Egress rule for internal load balancer on atgcp1-dev + { + IPBlock: &networkingv1.IPBlock{ + CIDR: "10.142.3.0/28", + }, + }, + // Egress rule for internal load balancer on atgcp1-prod + { + IPBlock: &networkingv1.IPBlock{ + CIDR: "10.142.1.0/28", + }, + }, // Egress rule for Internet { IPBlock: &networkingv1.IPBlock{ diff --git a/tests/namespace/default-deny/assert.yaml b/tests/namespace/default-deny/assert.yaml index 3a89ccb7..05482de9 100644 --- a/tests/namespace/default-deny/assert.yaml +++ b/tests/namespace/default-deny/assert.yaml @@ -13,6 +13,12 @@ spec: - to: - ipBlock: cidr: 10.40.0.0/16 + - ipBlock: + cidr: 10.142.5.0/28 + - ipBlock: + cidr: 10.142.3.0/28 + - ipBlock: + cidr: 10.142.1.0/28 - ipBlock: cidr: 0.0.0.0/0 except: