diff --git a/k8s/awoooi-prod/02-network-policy.yaml b/k8s/awoooi-prod/02-network-policy.yaml index 678ba287..40719a32 100644 --- a/k8s/awoooi-prod/02-network-policy.yaml +++ b/k8s/awoooi-prod/02-network-policy.yaml @@ -107,6 +107,19 @@ spec: - protocol: TCP port: 8123 + # 允許訪問 192.168.0.110 監控服務 (Harbor + Sentry) + # 2026-03-24 新增: Sentry Self-Hosted (透過 Sentry Tunnel API Route) + - to: + - ipBlock: + cidr: 192.168.0.110/32 + ports: + # Sentry Self-Hosted HTTP API + - protocol: TCP + port: 9000 + # Harbor Registry (已在 CD pipeline 使用) + - protocol: TCP + port: 5000 + # 允許訪問 192.168.0.112 安全掃描服務 - to: - ipBlock: