Project Templates์ถ์ฒ: Show HN์กฐํ์ 7
Show HN: Generate baseline Kubernetes NetworkPolicies from rendered manifests
By dormstern2026๋
2์ 19์ผ
**Show HN: Generate baseline Kubernetes NetworkPolicies from rendered manifests**
A lot of clusters still run โallow-allโ east/west because NetworkPolicies arenโt enforced everywhere. I built a small static analyzer that reads rendered manifests (Helm/Argo CD/Kustomize output) and emits baseline NetworkPolicy YAML you can commit + diff in PRs.Workflow:PR changes manifestsCI regenerates policiesreviewers see โnewly allowedโ connections as a normal permission diffCurious how others handle this: would you rather review generated policy diffs, or a connectivity-graph diff. Any edge cases youโve seen bite in real clusters (headless services, shared namespaces, DNS/egress, service meshes, etc.). Comments URL: https://news.ycombinator.com/item?id=47067580 Points: 1 # Comments: 0
---
**[devsupporter ํด์ค]**
์ด ๊ธฐ์ฌ๋ Show HN์์ ์ ๊ณตํ๋ ์ต์ ๊ฐ๋ฐ ๋ํฅ์ ๋๋ค. ๊ด๋ จ ๋๊ตฌ๋ ๊ธฐ์ ์ ๋ํด ๋ ์์๋ณด์๋ ค๋ฉด ์๋ณธ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ์ธ์.
A lot of clusters still run โallow-allโ east/west because NetworkPolicies arenโt enforced everywhere. I built a small static analyzer that reads rendered manifests (Helm/Argo CD/Kustomize output) and emits baseline NetworkPolicy YAML you can commit + diff in PRs.Workflow:PR changes manifestsCI regenerates policiesreviewers see โnewly allowedโ connections as a normal permission diffCurious how others handle this: would you rather review generated policy diffs, or a connectivity-graph diff. Any edge cases youโve seen bite in real clusters (headless services, shared namespaces, DNS/egress, service meshes, etc.). Comments URL: https://news.ycombinator.com/item?id=47067580 Points: 1 # Comments: 0
---
**[devsupporter ํด์ค]**
์ด ๊ธฐ์ฌ๋ Show HN์์ ์ ๊ณตํ๋ ์ต์ ๊ฐ๋ฐ ๋ํฅ์ ๋๋ค. ๊ด๋ จ ๋๊ตฌ๋ ๊ธฐ์ ์ ๋ํด ๋ ์์๋ณด์๋ ค๋ฉด ์๋ณธ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ์ธ์.
