57dc91585d
Internal SmartGift build of a Claude Code monitoring dashboard. Lanes: a durable unit of parallel agent work, one per working directory, tracked across session restarts. Managed lanes are git worktrees the dashboard provisions and can reset or remove behind a three-check destroy guard and a counted preflight; adopted lanes are directories you already own and are never destroyable. Pipelines: a lane moves through pipeline stages. A stage the agent declares with evidence renders green; a stage inferred from the tool-event stream renders dashed amber and never counts as done. Detection is forward-only within a 30-minute window, and never writes the declared stage. Workspace: one page at /run with a lane grid, the selected lane's pipeline, and a full Claude console behind a disclosure.
54 lines
1.4 KiB
YAML
54 lines
1.4 KiB
YAML
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: agent-monitor
|
|
namespace: agent-monitor
|
|
labels:
|
|
app.kubernetes.io/name: agent-monitor
|
|
app.kubernetes.io/instance: agent-monitor
|
|
app.kubernetes.io/version: "1.0.0"
|
|
app.kubernetes.io/component: network
|
|
app.kubernetes.io/managed-by: kustomize
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: agent-monitor
|
|
app.kubernetes.io/instance: agent-monitor
|
|
policyTypes:
|
|
- Ingress
|
|
- Egress
|
|
ingress:
|
|
# Allow traffic from ingress controller
|
|
- from:
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: ingress-nginx
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: ingress-nginx
|
|
ports:
|
|
- protocol: TCP
|
|
port: 4820
|
|
# Allow intra-namespace traffic (pod-to-pod)
|
|
- from:
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: agent-monitor
|
|
ports:
|
|
- protocol: TCP
|
|
port: 4820
|
|
egress:
|
|
# Allow DNS resolution (required for service discovery)
|
|
- ports:
|
|
- port: 53
|
|
protocol: UDP
|
|
- port: 53
|
|
protocol: TCP
|
|
# Allow outbound HTTPS (for external API calls if needed)
|
|
- ports:
|
|
- port: 443
|
|
protocol: TCP
|
|
# Allow internal communication within the namespace (pod-to-pod)
|
|
- to:
|
|
- podSelector: {}
|