Files
homeprod/kubernetes/personal/openclaw/networkpolicy-mail-egress.yaml
vhaudiquet ced1042fc1 openclaw: update secrets
<beep boop, I'm a bot>
2026-08-24 14:01:23 +02:00

32 lines
924 B
YAML

# Supplementary egress policy: the operator's managed default-deny NetworkPolicy
# only allows DNS + TCP 443 outbound, which blocks IMAP/SMTP to Stalwart.
# The CR field spec.networkPolicy.additionalEgress would be the native fix,
# but it is not in the CRD bundled with chart 0.39.0 yet (silently pruned).
# Revisit after upgrading the operator.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: openclaw-mail-egress
namespace: openclaw
spec:
podSelector:
matchLabels:
app.kubernetes.io/instance: openclaw
app.kubernetes.io/name: openclaw
policyTypes:
- Egress
egress:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: stalwart
ports:
- port: 143
protocol: TCP
- port: 993
protocol: TCP
- port: 587
protocol: TCP
- port: 465
protocol: TCP