Files
Claude-Code-Monitor/deployments/helm/agent-monitor/templates/networkpolicy.yaml
T
nntrivi2001 57dc91585d feat: Claude Code Monitor — lanes, pipelines and a merged workspace
Internal SmartGift build of a Claude Code monitoring dashboard.

Lanes: a durable unit of parallel agent work, one per working directory,
tracked across session restarts. Managed lanes are git worktrees the
dashboard provisions and can reset or remove behind a three-check destroy
guard and a counted preflight; adopted lanes are directories you already
own and are never destroyable.

Pipelines: a lane moves through pipeline stages. A stage the agent declares
with evidence renders green; a stage inferred from the tool-event stream
renders dashed amber and never counts as done. Detection is forward-only
within a 30-minute window, and never writes the declared stage.

Workspace: one page at /run with a lane grid, the selected lane's pipeline,
and a full Claude console behind a disclosure.
2026-07-30 14:39:03 +07:00

47 lines
1.3 KiB
YAML

{{- if .Values.networkPolicy.enabled -}}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "agent-monitor.fullname" . }}
labels:
{{- include "agent-monitor.labels" . | nindent 4 }}
spec:
podSelector:
matchLabels:
{{- include "agent-monitor.selectorLabels" . | nindent 6 }}
policyTypes:
- Ingress
- Egress
ingress:
# Allow HTTP traffic to the application port from any pod (ingress controllers, etc.)
- ports:
- port: {{ .Values.service.targetPort }}
protocol: TCP
{{- if .Values.mcp.enabled }}
# Allow MCP traffic when sidecar is enabled
- ports:
- port: {{ .Values.mcp.port }}
protocol: TCP
{{- end }}
{{- with .Values.networkPolicy.additionalIngressRules }}
{{- toYaml . | nindent 4 }}
{{- end }}
egress:
# Allow DNS resolution
- ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
# Allow outbound HTTPS (for external API calls)
- ports:
- port: 443
protocol: TCP
# Allow internal communication within the cluster
- to:
- podSelector: {}
{{- with .Values.networkPolicy.additionalEgressRules }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}