Files
Claude-Code-Monitor/deployments/kubernetes/base/networkpolicy.yaml
T
nntrivi2001 57dc91585d feat: Claude Code Monitor — lanes, pipelines and a merged workspace
Internal SmartGift build of a Claude Code monitoring dashboard.

Lanes: a durable unit of parallel agent work, one per working directory,
tracked across session restarts. Managed lanes are git worktrees the
dashboard provisions and can reset or remove behind a three-check destroy
guard and a counted preflight; adopted lanes are directories you already
own and are never destroyable.

Pipelines: a lane moves through pipeline stages. A stage the agent declares
with evidence renders green; a stage inferred from the tool-event stream
renders dashed amber and never counts as done. Detection is forward-only
within a 30-minute window, and never writes the declared stage.

Workspace: one page at /run with a lane grid, the selected lane's pipeline,
and a full Claude console behind a disclosure.
2026-07-30 14:39:03 +07:00

54 lines
1.4 KiB
YAML

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: agent-monitor
namespace: agent-monitor
labels:
app.kubernetes.io/name: agent-monitor
app.kubernetes.io/instance: agent-monitor
app.kubernetes.io/version: "1.0.0"
app.kubernetes.io/component: network
app.kubernetes.io/managed-by: kustomize
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: agent-monitor
app.kubernetes.io/instance: agent-monitor
policyTypes:
- Ingress
- Egress
ingress:
# Allow traffic from ingress controller
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: ingress-nginx
- podSelector:
matchLabels:
app.kubernetes.io/name: ingress-nginx
ports:
- protocol: TCP
port: 4820
# Allow intra-namespace traffic (pod-to-pod)
- from:
- podSelector:
matchLabels:
app.kubernetes.io/name: agent-monitor
ports:
- protocol: TCP
port: 4820
egress:
# Allow DNS resolution (required for service discovery)
- ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
# Allow outbound HTTPS (for external API calls if needed)
- ports:
- port: 443
protocol: TCP
# Allow internal communication within the namespace (pod-to-pod)
- to:
- podSelector: {}