cilium
1apiVersion: "cilium.io/v2"2kind: CiliumClusterwideNetworkPolicy3metadata:4name: "lock-down-ingress-worker-node"5spec:6description: "Allow a minimum set of required ports on ingress of worker nodes"7nodeSelector:8matchLabels:9type: ingress-worker10ingress:11- fromEntities:12- remote-node13- health14- toPorts:15- ports:16- port: "6443"17protocol: TCP18- port: "22"19protocol: TCP20- port: "2379"21protocol: TCP22- port: "4240"23protocol: TCP24- port: "8472"25protocol: UDP26- port: "REMOVE_ME_AFTER_DOUBLE_CHECKING_PORTS"27protocol: TCP28