openclaw: add egress NetworkPolicy for Radicale CalDAV

Allow the openclaw pod to reach the Radicale CalDAV/CardDAV server
(namespace: radicale, port 5232) so Kosmos can read/write Valentin's
calendar via the in-cluster service. Mirrors networkpolicy-mail-egress.yaml.

Workaround for spec.networkPolicy.additionalEgress not being in the CRD
bundled with operator chart 0.39.0 yet (silently pruned).
This commit is contained in:
2026-08-25 00:08:03 +02:00
committed by vhaudiquet
parent 989a16b878
commit 6da9484fa3
2 changed files with 26 additions and 0 deletions
@@ -6,3 +6,4 @@ resources:
- openclaw-secrets.yaml
- networkpolicy.yaml
- networkpolicy-mail-egress.yaml
- networkpolicy-radicale-egress.yaml
@@ -0,0 +1,25 @@
# Supplementary egress policy: the operator's managed default-deny NetworkPolicy
# only allows DNS + TCP 443 outbound, which blocks HTTP/CalDAV to Radicale.
# The CR field spec.networkPolicy.additionalEgress would be the native fix,
# but it is not in the CRD bundled with chart 0.39.0 yet (silently pruned).
# Revisit after upgrading the operator.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: openclaw-radicale-egress
namespace: openclaw
spec:
podSelector:
matchLabels:
app.kubernetes.io/instance: openclaw
app.kubernetes.io/name: openclaw
policyTypes:
- Egress
egress:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: radicale
ports:
- port: 5232
protocol: TCP