{"id":33724,"date":"2022-11-07T07:17:15","date_gmt":"2023-04-29T06:44:15","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/"},"modified":"2024-04-28T23:26:49","modified_gmt":"2024-04-28T15:26:49","slug":"%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/","title":{"rendered":"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09"},"content":{"rendered":"<h1>&#8220;Antrea\u662f\u4ec0\u4e48&#8221;<\/h1>\n<p>Antrea\u662f\u4e00\u4e2a\u5f00\u6e90\u7684Kubernetes CNI\uff0c\u4e3aKubernetes\u96c6\u7fa4\u63d0\u4f9bL3\/4\u7f51\u7edc\u529f\u80fd\u548c\u5b89\u5168\u6027\u3002\u5b83\u4f7f\u7528\u7ecf\u8fc7\u9a8c\u8bc1\u7684Open vSwitch\u4f5c\u4e3a\u6570\u636e\u5e73\u9762\u7684\u5f00\u653e\u5f0f\u865a\u62df\u4ea4\u6362\u673a\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u5728Antrea\u4e2d\uff0c\u6211\u4eec\u8bd5\u56fe\u5b9e\u73b0\u4e00\u4e9b\u5728\u6807\u51c6\u7684Kubernetes\u96c6\u7fa4\u7f51\u7edc\u4e2d\u4e0d\u652f\u6301\u7684\u529f\u80fd\uff0c\u4f46\u4ece\u7f51\u7edc\u5b89\u5168\u7684\u89d2\u5ea6\u6765\u770b\uff0cAntrea Cluster Network Policy (ACNP)\u975e\u5e38\u6709\u8da3\u3002<\/p>\n<p>Antrea\u4e0d\u4ec5\u652f\u6301\u6807\u51c6\u7684NetworkPolicy\uff0c\u8fd8\u901a\u8fc7ACNP\u63d0\u4f9b\u4ee5\u4e0b\u529f\u80fd\uff0c\u4ee5\u66f4\u597d\u5730\u6ee1\u8db3\u96c6\u7fa4\u7ba1\u7406\u5458\u7684\u8981\u6c42\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30dd\u30ea\u30b7\u30fc\u306e\u968e\u5c64\u5316\u3068\u512a\u5148\u5ea6\u8a2d\u5b9a<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Namespace \u306b\u9650\u5b9a\u3055\u308c\u306a\u3044\u3001\u30af\u30e9\u30b9\u30bf\u30fc\u30ec\u30d9\u30eb\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a2d\u5b9a<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u30a2\u30af\u30b7\u30e7\u30f3\u30eb\u30fc\u30eb\u306e\u30b5\u30dd\u30fc\u30c8: Allow, Drop, Reject \u306e\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u6307\u5b9a\u53ef\u80fd<\/ul>\n<p>\u6211\u5011\u5c07\u95dc\u6ce8Antrea\u53e2\u96c6\u7db2\u8def\u7b56\u7565\uff0c\u4ee5\u78ba\u8a8d\u5176\u529f\u80fd\u3002<\/p>\n<p>\u987a\u4fbf\u63d0\u4e00\u53e5\uff0c2021\u5e744\u670810\u65e5\uff0c\u5728\u672c\u6587\u64b0\u5199\u65f6\uff0cAntrea\u5df2\u7ecf\u8fbe\u5230\u4e861.0.0\u7248\u672c\u3002\u4e0b\u9762\u7684\u5185\u5bb9\u662f\u57fa\u4e8eAntrea 1.0.0\u8fdb\u884c\u64b0\u5199\u7684\u3002<br \/>\n\u53e6\u5916\uff0c\u9664\u4e86\u4e0a\u8ff0\u7684Project Antrea\u9875\u9762\u5916\uff0c\u6211\u8fd8\u53c2\u8003\u4e86\u4ee5\u4e0b\u6587\u7ae0\uff1a<br \/>\nhttps:\/\/blog.shin.do\/2020\/01\/antrea-yet-another-cni-plugin-for-kubernetes\/<\/p>\n<h1>Antrea \u96c6\u7fa4\u7684\u51c6\u5907<\/h1>\n<h2>\u51c6\u5907\u4e00\u4e2a\u65b0\u7684 K8s \u96c6\u7fa4<\/h2>\n<p>\u8fd9\u6b21\u6211\u4f7f\u7528 kubeadm \u6765\u51c6\u5907\u4e00\u4e2a\u65b0\u7684 Kubernetes \u96c6\u7fa4\uff0c\u7528\u4e8e Antrea\u3002\u6211\u53c2\u8003\u4e86\u4ee5\u4e0b\u94fe\u63a5\u7684\u5185\u5bb9\uff1a<br \/>\nhttps:\/\/thinkit.co.jp\/article\/18188<\/p>\n<p>\u6211\u914d\u7f6e\u4e861\u53f0Master\u548c2\u53f0Worker\uff0c\u4f46\u5728\u5e94\u7528CNI\u4e4b\u524d\uff0c\u5b83\u4eec\u5c06\u5904\u4e8eNotReady\u72b6\u6001\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl get node\r\nNAME          STATUS     ROLES                  AGE     VERSION\r\nk8s-master    NotReady   control-plane,master   1d      v1.20.5\r\nk8s-worker1   NotReady   &lt;none&gt;                 44m     v1.20.5\r\nk8s-worker2   NotReady   &lt;none&gt;                 2m41s   v1.20.5\r\n<\/code><\/pre>\n<h2>\u5c06 Antrea \u5e94\u7528\u5230\u96c6\u7fa4\u4e2d<\/h2>\n<p>\u4f5c\u4e3aCNI\uff0c\u6211\u4eec\u5c06\u5e94\u7528Antrea\u800c\u4e0d\u662fCalico\u3002\u6709\u5173Antrea\u7684\u521d\u59cb\u8bbe\u7f6e\uff0c\u8bf7\u53c2\u8003\u4ee5\u4e0b\u94fe\u63a5\uff1a<br \/>\nhttps:\/\/github.com\/vmware-tanzu\/antrea\/blob\/main\/docs\/getting-started.md<\/p>\n<p>\u7531\u4e8e\u672c\u6b21\u4f7f\u7528 Antrea v1.0.0\uff0c\u5c06\u6309\u7167\u4ee5\u4e0b\u65b9\u5f0f\u6307\u5b9a\u5e76\u5e94\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/github.com\/vmware-tanzu\/antrea\/releases\/download\/v1.0.0\/antrea.yml\r\n<\/code><\/pre>\n<p>\u5982\u679c\u60f3\u5e94\u7528\u6700\u65b0\u7684\u7248\u672c\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u4e0b\u9762\u7684\u65b9\u5f0f\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/vmware-tanzu\/antrea\/main\/build\/yamls\/antrea.yml\r\n<\/code><\/pre>\n<p>\u5e94\u7528 Antrea CNI \u540e\uff0c\u8282\u70b9\u5df2\u51c6\u5907\u5c31\u7eea\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl get node\r\nNAME          STATUS   ROLES                  AGE   VERSION\r\nk8s-master    Ready    control-plane,master   1d    v1.20.5\r\nk8s-worker1   Ready    &lt;none&gt;                 57m   v1.20.5\r\nk8s-worker2   Ready    &lt;none&gt;                 15m   v1.20.5\r\n<\/code><\/pre>\n<h3>antctl\u7684\u5b89\u88c5<\/h3>\n<p>antctl \u662f\u4e00\u4e2a\u901a\u8fc7\u63a7\u5236\u5668\u6765\u68c0\u67e5 Antrea \u914d\u7f6e\u548c\u72b6\u6001\u7684\u547d\u4ee4\u884c\u5de5\u5177\u3002\u4e3a\u4e86\u672a\u6765\u7684\u53ef\u80fd\u9700\u8981\uff0c\u5efa\u8bae\u5b89\u88c5\u6700\u65b0\u7248\u672c\u3002\u4ee5\u4e0b\u662f\u9002\u7528\u4e8e 1.0.0 \u7248\u672c\u7684 Linux\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl <span class=\"nt\">-Lo<\/span> .\/antctl <span class=\"s2\">\"https:\/\/github.com\/vmware-tanzu\/antrea\/releases\/download\/v1.0.0\/antctl-linux-x86_64\"<\/span>\r\n<span class=\"nv\">$ <\/span><span class=\"nb\">chmod<\/span> +x .\/antctl\r\n<span class=\"nv\">$ <\/span><span class=\"nb\">mv<\/span> .\/antctl \/usr\/local\/bin\r\n<span class=\"nv\">$ <\/span>antctl version\r\nantctlVersion: v1.0.0\r\ncontrollerVersion: v1.0.0\r\n<\/code><\/pre>\n<h3>\u786e\u8ba4\u8bbe\u7f6e<\/h3>\n<p>\u5728\u90e8\u7f72Antrea\u65f6\uff0c\u5c06\u4f1a\u521b\u5efaAntrea\u7684configmap\u3002\u60a8\u53ef\u4ee5\u786e\u8ba4\u5f53\u524d\u7684\u914d\u7f6e\u60c5\u51b5\u3002\u67e5\u770b\u5df2\u521b\u5efa\u7684antrea-config-xxxxxxxxx\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl get configmap antrea-config-5ct9ktdt77 <span class=\"nt\">-n<\/span> kube-system <span class=\"nt\">-o<\/span> yaml\r\n<\/code><\/pre>\n<p>\u8fd9\u91cc\u6211\u4eec\u5c06\u786e\u8ba4AntreaPolicy\u7684\u8bbe\u7f6e\u3002\u5728antrea-agent.conf\u548cantrea-controller.conf\u7684\u8bbe\u7f6e\u4e2d\uff0cAntreaPolicy\u88ab\u8bbe\u7f6e\u4e3aTrue\uff0c\u4f46\u88ab\u6ce8\u91ca\u6389\u3002\u7531\u4e8e\u4eceAntrea 1.0\u7248\u672c\u5f00\u59cb\uff0c\u9ed8\u8ba4\u60c5\u51b5\u4e0bAntrea Network Policy\u5df2\u542f\u7528\uff0c\u6240\u4ee5\u5df2\u7ecf\u88ab\u6fc0\u6d3b\u4e86\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">v1<\/span>\r\n<span class=\"na\">data<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">antrea-agent.conf<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">|<\/span>\r\n    <span class=\"s\"># FeatureGates is a map of feature names to bools that enable or disable experimental features.<\/span>\r\n    <span class=\"s\">featureGates:<\/span>\r\n    <span class=\"s\"># Enable AntreaProxy which provides ServiceLB for in-cluster Services in antrea-agent.<\/span>\r\n    <span class=\"s\"># It should be enabled on Windows, otherwise NetworkPolicy will not take effect on<\/span>\r\n    <span class=\"s\"># Service traffic.<\/span>\r\n    <span class=\"s\">#  AntreaProxy: true<\/span>\r\n\r\n    <span class=\"s\"># Enable EndpointSlice support in AntreaProxy. Don't enable this feature unless that EndpointSlice<\/span>\r\n    <span class=\"s\"># API version v1beta1 is supported and set as enabled in Kubernetes. If AntreaProxy is not enabled,<\/span>\r\n    <span class=\"s\"># this flag will not take effect.<\/span>\r\n    <span class=\"s\">#  EndpointSlice: false<\/span>\r\n\r\n    <span class=\"s\"># Enable traceflow which provides packet tracing feature to diagnose network issue.<\/span>\r\n    <span class=\"s\">#  Traceflow: true<\/span>\r\n\r\n    <span class=\"s\"># Enable NodePortLocal feature to make the pods reachable externally through NodePort<\/span>\r\n    <span class=\"s\">#  NodePortLocal: false<\/span>\r\n\r\n    <span class=\"s\"># Enable Antrea ClusterNetworkPolicy feature to complement K8s NetworkPolicy for cluster admins<\/span>\r\n    <span class=\"s\"># to define security policies which apply to the entire cluster, and Antrea NetworkPolicy<\/span>\r\n    <span class=\"s\"># feature that supports priorities, rule actions and externalEntities in the future.<\/span>\r\n    <span class=\"s\">#  AntreaPolicy: true<\/span>\r\n\r\n<span class=\"s\">(snip...)<\/span>\r\n\r\n  <span class=\"s\">antrea-controller.conf<\/span><span class=\"err\">:<\/span> <span class=\"pi\">|<\/span>\r\n    <span class=\"s\"># FeatureGates is a map of feature names to bools that enable or disable experimental features.<\/span>\r\n    <span class=\"s\">featureGates:<\/span>\r\n    <span class=\"s\"># Enable traceflow which provides packet tracing feature to diagnose network issue.<\/span>\r\n    <span class=\"s\">#  Traceflow: true<\/span>\r\n\r\n    <span class=\"s\"># Enable Antrea ClusterNetworkPolicy feature to complement K8s NetworkPolicy for cluster admins<\/span>\r\n    <span class=\"s\"># to define security policies which apply to the entire cluster, and Antrea NetworkPolicy<\/span>\r\n    <span class=\"s\"># feature that supports priorities, rule actions and externalEntities in the future.<\/span>\r\n    <span class=\"s\">#  AntreaPolicy: true<\/span>\r\n\r\n<span class=\"s\">(snip...)<\/span>\r\n<\/code><\/pre>\n<h1>\u5c1d\u8bd5\u4f7f\u7528Antrea\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565<\/h1>\n<p>\u6211\u5011\u73fe\u5728\u4f86\u5be6\u969b\u4f7f\u7528 Antrea Cluster Network Policy\uff0c\u4e26\u4e14\u6bd4\u8f03\u4e00\u4e0b\u5b83\u8207 K8s \u6a19\u6e96\u7684 NetworkPolicy \u7684\u5dee\u7570\u3002<\/p>\n<h2>\u90e8\u7f72\u793a\u4f8b\u5e94\u7528\u7a0b\u5f0f<\/h2>\n<p>\u9996\u5148\uff0c\u6211\u4eec\u5c06\u90e8\u7f72\u4e00\u4e2a\u7528\u4e8e\u8fdb\u884c\u64cd\u4f5c\u786e\u8ba4\u7684\u5e94\u7528\u7a0b\u5e8f\u3002\u5c06Guestbook\u5e94\u7528\u7a0b\u5e8f\u90e8\u7f72\u5230\u9ed8\u8ba4\u7684\u547d\u540d\u7a7a\u95f4\u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/redis-master-controller.json\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/redis-master-service.json\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/redis-slave-controller.json\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/redis-slave-service.json\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/guestbook-controller.json\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/guestbook-service.json\r\n<\/code><\/pre>\n<p>\u521b\u5efa\u4e86\u4e09\u79cd\u7c7b\u578b\u7684\u670d\u52a1\u548c\u5bb9\u5668\uff1aguestbook\u3001redis-master\u3001redis-slave\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl get all <span class=\"nt\">-n<\/span> default\r\nNAME                     READY   STATUS    RESTARTS   AGE\r\npod\/guestbook-hmsrw      1\/1     Running   0          23h\r\npod\/guestbook-nl7xv      1\/1     Running   0          23h\r\npod\/guestbook-s9spp      1\/1     Running   0          23h\r\npod\/redis-master-z2vjh   1\/1     Running   0          23h\r\npod\/redis-slave-cplgv    1\/1     Running   0          23h\r\npod\/redis-slave-r2tmz    1\/1     Running   0          23h\r\n\r\nNAME                                 DESIRED   CURRENT   READY   AGE\r\nreplicationcontroller\/guestbook      3         3         3       23h\r\nreplicationcontroller\/redis-master   1         1         1       23h\r\nreplicationcontroller\/redis-slave    2         2         2       23h\r\n\r\nNAME                   TYPE           CLUSTER-IP       EXTERNAL-IP   PORT<span class=\"o\">(<\/span>S<span class=\"o\">)<\/span>          AGE\r\nservice\/guestbook      LoadBalancer   10.109.117.193   &lt;pending&gt;     3000:30731\/TCP   23h\r\nservice\/kubernetes     ClusterIP      10.96.0.1        &lt;none&gt;        443\/TCP          2d\r\nservice\/redis-master   ClusterIP      10.98.195.90     &lt;none&gt;        6379\/TCP         23h\r\nservice\/redis-slave    ClusterIP      10.109.248.115   &lt;none&gt;        6379\/TCP         23h\r\n<\/code><\/pre>\n<p>\u8bbf\u5ba2\u7559\u8a00\u677f\u670d\u52a1\u662f\u8d1f\u8f7d\u5747\u8861\u7684\u7c7b\u578b\uff0c\u4f46\u7531\u4e8e\u6b64\u73af\u5883\u4e2d\u5c1a\u672a\u5b58\u5728\u63d0\u4f9b\u8005\u8d1f\u8f7d\u5747\u8861\u5668\uff0c\u56e0\u6b64EXTERNAL-IP\u4ecd\u5904\u4e8e\u5f85\u5b9a\u72b6\u6001\u3002\u6682\u65f6\uff0c\u8bf7\u4f7f\u7528NodePort\u901a\u8fc7\u4ee5\u4e0bURL\u8bbf\u95ee\uff0c\u5373\u53ef\u663e\u793a\u8bbf\u5ba2\u7559\u8a00\u677f\u7684\u7528\u6237\u754c\u9762\u3002192.168.110.91\u662f\u5de5\u4f5c\u8282\u70b9\u7684IP\u5730\u5740\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">http:\/\/192.168.110.91:30731\/\r\n<\/span><\/code><\/pre>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/37-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u5c06\u786e\u8ba4\u6bcf\u4e2a Pod \u7684\u6807\u7b7e\u8bbe\u7f6e\u3002\u524d\u7aef\u5bb9\u5668 guestbook \u5177\u6709 app: guestbook \u7684\u6807\u7b7e\uff0c\u540e\u7aef\u7684 redis-master \u548c redis-slave \u5177\u6709 app: redis \u7684\u6807\u7b7e\u3002\u8fd9\u4e9b\u6807\u7b7e\u5c06\u5728\u63a5\u4e0b\u6765\u7684 NetworkPolicy \u548c Antrea Network Policy \u7684 PodSelector \u8bbe\u7f6e\u4e2d\u4f7f\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl get pod <span class=\"nt\">-L<\/span> app\r\nNAME                 READY   STATUS    RESTARTS   AGE     APP\r\nguestbook-hmsrw      1\/1     Running   0          23h   guestbook\r\nguestbook-nl7xv      1\/1     Running   0          23h   guestbook\r\nguestbook-s9spp      1\/1     Running   0          23h   guestbook\r\nredis-master-z2vjh   1\/1     Running   0          23h     redis\r\nredis-slave-cplgv    1\/1     Running   0          23h     redis\r\nredis-slave-r2tmz    1\/1     Running   0          23h     redis\r\n<\/code><\/pre>\n<h2>\u7f51\u7edc\u7b56\u7565<\/h2>\n<p>\u5728\u5c1d\u8bd5 Antrea Cluster Network Policy \u4e4b\u524d\uff0c\u5148\u786e\u8ba4\u6807\u51c6 NetworkPolicy \u7684\u8fd0\u4f5c\u60c5\u51b5\u3002<\/p>\n<h3>\u5728\u547d\u540d\u7a7a\u95f4\u4e2d\u5bf9\u5bb9\u5668\u4e4b\u95f4\u7684\u63a7\u5236<\/h3>\n<p>\u5e94\u7528\u4ee5\u4e0b\u7b56\u7565\uff0c\u786e\u8ba4\u5728\u547d\u540d\u7a7a\u95f4\u5185\uff0c\u524d\u7aefguestbook\u4e0e\u540e\u7aefredis\u7684\u901a\u4fe1\u53d7\u5230\u963b\u788d\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">$ cat np1.yaml<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">NetworkPolicy<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">networking.k8s.io\/v1<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">drop-access-to-redis<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">policyTypes<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"s\">Ingress<\/span>\r\n  <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">redis<\/span>\r\n  <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">from<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">other<\/span>\r\n<span class=\"s\">$<\/span>\r\n<span class=\"s\">$ kubectl apply -f np1.yaml<\/span>\r\n<span class=\"s\">networkpolicy.networking.k8s.io\/drop-access-to-redis created<\/span>\r\n<\/code><\/pre>\n<p>\u5f53\u518d\u6b21\u8bbf\u95eeGuestbook\u7684URL\u65f6\uff0c\u4f1a\u663e\u793a\u4ee5\u4e0b\u5185\u5bb9\uff0c\u8868\u660e\u65e0\u6cd5\u8fde\u63a5\u5230\u540e\u7aef\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/46-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u5220\u9664\u6b64 NetworkPolicy \u540e\uff0c\u60a8\u5c06\u80fd\u591f\u91cd\u65b0\u8fde\u63a5\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl delete <span class=\"nt\">-f<\/span> np1.yaml\r\nnetworkpolicy.networking.k8s.io <span class=\"s2\">\"drop-access-to-redis\"<\/span> deleted\r\n<\/code><\/pre>\n<h3>\u547d\u540d\u7a7a\u95f4\u7528\u4e8e\u63a7\u5236\u5916\u90e8\u8bbf\u95ee\u3002<\/h3>\n<p>\u8fd9\u6b21\u6211\u4eec\u5c06\u521b\u5efa\u5e76\u5e94\u7528\u4e00\u4e2a\u7981\u6b62\u8bbf\u95ee\u524d\u7aefguestbook\u7684\u7b56\u7565\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span><span class=\"nb\">cat <\/span>np2.yaml\r\nkind: NetworkPolicy\r\napiVersion: networking.k8s.io\/v1\r\nmetadata:\r\n  name: drop-access-to-guestbook\r\nspec:\r\n  policyTypes:\r\n  - Ingress\r\n  podSelector:\r\n    matchLabels:\r\n      app: guestbook\r\n  ingress:\r\n  - from:\r\n    - podSelector:\r\n        matchLabels:\r\n          app: other\r\n<span class=\"err\">$<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> np2.yaml\r\nnetworkpolicy.networking.k8s.io\/drop-access-to-guestbook created\r\n<\/code><\/pre>\n<p>\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4ecd\u7136\u53ef\u4ee5\u901a\u8fc7NodePort\u4ece\u5916\u90e8\u8bbf\u95ee\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/53-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u7136\u800c\uff0c\u4e0d\u5141\u8bb8\u901a\u8fc7\u524d\u7aef\u5bb9\u5668\u8bbf\u95eeClusterIP\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl <span class=\"nb\">exec <\/span>guestbook-hmsrw <span class=\"nt\">-it<\/span> <span class=\"nt\">--<\/span> sh\r\n\r\n\r\nBusyBox v1.21.1 <span class=\"o\">(<\/span>Ubuntu 1:1.21.0-1ubuntu1<span class=\"o\">)<\/span> built-in shell <span class=\"o\">(<\/span>ash<span class=\"o\">)<\/span>\r\nEnter <span class=\"s1\">'help'<\/span> <span class=\"k\">for <\/span>a list of built-in commands.\r\n\r\n\/app <span class=\"c\"># wget -O - http:\/\/guestbook.default.svc.cluster.local:3000<\/span>\r\nConnecting to guestbook.default.svc.cluster.local:3000 <span class=\"o\">(<\/span>10.109.117.193:3000<span class=\"o\">)<\/span>\r\n^C\r\n\/app <span class=\"c\"># <\/span>\r\n<\/code><\/pre>\n<p>\u5220\u9664\u7b56\u7565\u540e\uff0c\u524d\u7aef\u4e5f\u53ef\u4ee5\u518d\u6b21\u8bbf\u95ee\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl delete <span class=\"nt\">-f<\/span> np2.yaml\r\nnetworkpolicy.networking.k8s.io <span class=\"s2\">\"drop-access-to-guestbook\"<\/span> deleted\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code>\/app <span class=\"c\"># wget -O - http:\/\/guestbook.default.svc.cluster.local:3000<\/span>\r\nConnecting to guestbook.default.svc.cluster.local:3000 <span class=\"o\">(<\/span>10.109.117.193:3000<span class=\"o\">)<\/span>\r\n&lt;<span class=\"o\">!<\/span>DOCTYPE html&gt;\r\n&lt;html <span class=\"nv\">lang<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"en\"<\/span><span class=\"o\">&gt;<\/span>\r\n  &lt;<span class=\"nb\">head<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;meta <span class=\"nv\">content<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"text\/html; charset=utf-8\"<\/span> http-equiv<span class=\"o\">=<\/span><span class=\"s2\">\"Content-Type\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;meta <span class=\"nv\">charset<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"utf-8\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;meta <span class=\"nv\">content<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"width=device-width\"<\/span> <span class=\"nv\">name<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"viewport\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;<span class=\"nb\">link <\/span><span class=\"nv\">href<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"style.css\"<\/span> <span class=\"nv\">rel<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"stylesheet\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;title&gt;Guestbook&lt;\/title&gt;\r\n  &lt;\/head&gt;\r\n  &lt;body&gt;\r\n    &lt;div <span class=\"nb\">id<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"header\"<\/span><span class=\"o\">&gt;<\/span>\r\n      &lt;h1&gt;Guestbook&lt;\/h1&gt;\r\n    &lt;\/div&gt;\r\n\r\n<span class=\"o\">(<\/span>snip...<span class=\"o\">)<\/span>\r\n<\/code><\/pre>\n<p>\u7528NodePort\u8fdb\u884c\u5916\u90e8\u63a7\u5236\u65f6\uff0c\u65e0\u6cd5\u4f7f\u7528NetworkPolicy\u3002<\/p>\n<h3>\u547d\u540d\u7a7a\u95f4\u7684\u63a7\u5236<\/h3>\n<p>\u8fd9\u6b21\uff0c\u6211\u4eec\u5c06\u521b\u5efa\u4ee5\u4e0b\u7b56\u7565\uff0c\u5141\u8bb8\u5176\u4ed6\u547d\u540d\u7a7a\u95f4\u7684\u8bbf\u95ee\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span><span class=\"nb\">cat <\/span>np3.yaml\r\nkind: NetworkPolicy\r\napiVersion: networking.k8s.io\/v1\r\nmetadata:\r\n  name: allow-access-from-other-ns\r\nspec:\r\n  policyTypes:\r\n  - Ingress\r\n  podSelector:\r\n    matchLabels:\r\n      app: guestbook\r\n  ingress:\r\n  - from:\r\n    - namespaceSelector:\r\n        matchLabels:\r\n          project: <span class=\"nb\">test<\/span>\r\n    - podSelector:\r\n        matchLabels:\r\n          app: other\r\n<span class=\"err\">$<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> np3.yaml\r\nnetworkpolicy.networking.k8s.io\/allow-access-from-other-ns created\r\n<\/code><\/pre>\n<p>\u4e3a\u4e86\u8fdb\u884c\u8fd9\u4e2a\u6d4b\u8bd5\uff0c\u6682\u65f6\u521b\u5efa\u4e00\u4e2a\u540d\u4e3atest\u7684\u547d\u540d\u7a7a\u95f4\uff0c\u5e76\u7ed9\u5176\u6dfb\u52a0\u9879\u76ee\uff1atest\u7684\u6807\u7b7e\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl create namespace <span class=\"nb\">test\r\n<\/span>namespace\/test created\r\n<span class=\"nv\">$ <\/span>kubectl label namespace <span class=\"nb\">test <\/span><span class=\"nv\">project<\/span><span class=\"o\">=<\/span><span class=\"nb\">test\r\n<\/span>namespace\/test labeled\r\n<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u5728testnamespace\u4e2d\u521b\u5efa\u4e00\u4e2a\u7528\u4e8e\u6d4b\u8bd5\u7684\u5bb9\u5668\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/examples\/master\/guestbook-go\/guestbook-controller.json <span class=\"nt\">-n<\/span> <span class=\"nb\">test<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl get pod <span class=\"nt\">-n<\/span> <span class=\"nb\">test\r\n<\/span>NAME              READY   STATUS    RESTARTS   AGE\r\nguestbook-5w6ft   1\/1     Running   0          79m\r\nguestbook-cfzfd   1\/1     Running   0          79m\r\nguestbook-jlfpw   1\/1     Running   0          79m\r\n<\/code><\/pre>\n<p>\u786e\u4fdd\u53ef\u4ee5\u4ece\u8be5\u5bb9\u5668\u8bbf\u95ee\u6700\u521d\u90e8\u7f72\u5728 defaultnamespace \u4e2d\u7684 Guestbook \u5e94\u7528\u7a0b\u5e8f\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl <span class=\"nb\">exec <\/span>guestbook-5w6ft <span class=\"nt\">-n<\/span> <span class=\"nb\">test<\/span>  <span class=\"nt\">-it<\/span> <span class=\"nt\">--<\/span> sh\r\n\r\n\r\nBusyBox v1.21.1 <span class=\"o\">(<\/span>Ubuntu 1:1.21.0-1ubuntu1<span class=\"o\">)<\/span> built-in shell <span class=\"o\">(<\/span>ash<span class=\"o\">)<\/span>\r\nEnter <span class=\"s1\">'help'<\/span> <span class=\"k\">for <\/span>a list of built-in commands.\r\n\r\n\/app <span class=\"c\"># wget -O - http:\/\/guestbook.default.svc.cluster.local:3000<\/span>\r\nConnecting to guestbook.default.svc.cluster.local:3000 <span class=\"o\">(<\/span>10.109.117.193:3000<span class=\"o\">)<\/span>\r\n&lt;<span class=\"o\">!<\/span>DOCTYPE html&gt;\r\n&lt;html <span class=\"nv\">lang<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"en\"<\/span><span class=\"o\">&gt;<\/span>\r\n  &lt;<span class=\"nb\">head<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;meta <span class=\"nv\">content<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"text\/html; charset=utf-8\"<\/span> http-equiv<span class=\"o\">=<\/span><span class=\"s2\">\"Content-Type\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;meta <span class=\"nv\">charset<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"utf-8\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;meta <span class=\"nv\">content<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"width=device-width\"<\/span> <span class=\"nv\">name<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"viewport\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;<span class=\"nb\">link <\/span><span class=\"nv\">href<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"style.css\"<\/span> <span class=\"nv\">rel<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"stylesheet\"<\/span><span class=\"o\">&gt;<\/span>\r\n    &lt;title&gt;Guestbook&lt;\/title&gt;\r\n  &lt;\/head&gt;\r\n  &lt;body&gt;\r\n    &lt;div <span class=\"nb\">id<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"header\"<\/span><span class=\"o\">&gt;<\/span>\r\n      &lt;h1&gt;Guestbook&lt;\/h1&gt;\r\n    &lt;\/div&gt;\r\n\r\n<span class=\"o\">(<\/span>snip...<span class=\"o\">)<\/span>\r\n<\/code><\/pre>\n<p>\u5c31\u5982\u4e0a\u6240\u8ff0\uff0cNetworkPolicy \u5141\u8bb8\u5728\u96c6\u7fa4\u5185\u5bf9\u6bcf\u4e2a\u547d\u540d\u7a7a\u95f4\u8fdb\u884c\u8bbf\u95ee\u63a7\u5236\uff0c\u4f46\u65e0\u6cd5\u5e94\u7528\u4e8e\u8de8\u547d\u540d\u7a7a\u95f4\u6216\u8de8\u96c6\u7fa4\u3002\u6b64\u5916\uff0c\u7b56\u7565\u4ec5\u5305\u62ec\u5141\u8bb8\u89c4\u5219\uff0c\u540c\u65f6\u4e5f\u4f1a\u81ea\u52a8\u6dfb\u52a0\u9690\u5f0f\u7684\u62d2\u7edd\u89c4\u5219\u3002\u56e0\u6b64\uff0c\u4f3c\u4e4e\u4e0d\u9002\u5408\u7f16\u5199\u8be6\u7ec6\u7684\u62d2\u7edd\u89c4\u5219\u4ee5\u8fdb\u884c\u66f4\u7cbe\u7ec6\u7684\u5b89\u5168\u63a7\u5236\u3002<\/p>\n<p>Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\u65e8\u5728\u89e3\u51b3\u8fd9\u4e9b\u95ee\u9898\u3002<\/p>\n<h2>Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565 (ACNP)<\/h2>\n<p>Antrea Cluster Network Policy \u7684\u8a2d\u5b9a\u73fe\u5728\u6b63\u5f0f\u958b\u59cb\u3002\u7531\u65bc Antrea 1.0 \u7248\u672c\u5df2\u7d93\u9810\u8a2d\u555f\u7528 Antrea Cluster Network Policy\uff0c\u6240\u4ee5\u60a8\u53ef\u4ee5\u7acb\u5373\u958b\u59cb\u9032\u884c\u8a2d\u5b9a\uff0c\u4f46\u9996\u5148\u6211\u5011\u9700\u8981\u4e86\u89e3\u4e00\u4e0b Antrea Cluster Network Policy \u5c08\u5c6c\u7684 Tier\u3002<\/p>\n<h3>\u9636\u5c42<\/h3>\n<p>\u5c42\u6b21\u7ed3\u6784\u5bf9\u4e8e\u7ba1\u7406\u7b56\u7565\u6765\u8bf4\u662f\u4e00\u4e2a\u6982\u5ff5\uff0c\u5728\u5e0c\u671b\u4e3a\u7b56\u7565\u8bbe\u5b9a\u4f18\u5148\u7ea7\u7684\u60c5\u51b5\u4e0b\u975e\u5e38\u6709\u7528\u3002\u5728\u521d\u59cb\u8bbe\u7f6e\u4e2d\uff0c\u5c42\u6b21\u7ed3\u6784\u901a\u5e38\u88ab\u8bbe\u5b9a\u5982\u4e0b\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl get tier <span class=\"nt\">--sort-by<\/span><span class=\"o\">=<\/span>.spec.priority\r\nNAME          PRIORITY   AGE\r\nemergency     50         37m\r\nsecurityops   100        37m\r\nnetworkops    150        37m\r\nplatform      200        37m\r\napplication   250        37m\r\nbaseline      253        37m\r\n<\/code><\/pre>\n<p>\u5404\u7ea7\u522b\u7684PRIORITY\u8868\u793a\u5b9e\u9645\u5904\u7406\u7684\u4f18\u5148\u7ea7\u3002\u6570\u503c\u8d8a\u5c0f\uff0c\u4f18\u5148\u7ea7\u8d8a\u9ad8\u3002\u4f8b\u5982\uff0c\u5982\u679c\u6709\u5e0c\u671b\u9996\u5148\u5904\u7406\u7684\u6700\u9ad8\u4f18\u5148\u7ea7\u7b56\u7565\uff0c\u53ef\u4ee5\u5c06\u5176\u8bbe\u7f6e\u4e3aemergency\uff0c\u8fd9\u6837\u5c06\u9996\u5148\u8fdb\u884c\u5904\u7406\u3002\u901a\u8fc7\u6807\u51c6\u7684NetworkPolicy\u8bbe\u7f6e\u7684\u7b56\u7565\u5c06\u5728application Tier\u4e4b\u540e\u5904\u7406\u3002<\/p>\n<p>Tier\u53ef\u4ee5\u901a\u8fc7\u81ea\u5df1\u521b\u5efa\u6765\u5b9e\u73b0\u3002\u5728\u8fd9\u91cc\uff0c\u8ba9\u6211\u4eec\u5c1d\u8bd5\u4f7f\u7528\u4ee5\u4e0b\u7684mytier.yaml\u6e05\u5355\u6587\u4ef6\u521b\u5efa\u4e00\u4e2a\u65b0\u7684Tier\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">security.antrea.tanzu.vmware.com\/v1alpha1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Tier<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">mytier<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">priority<\/span><span class=\"pi\">:<\/span> <span class=\"m\">10<\/span>\r\n  <span class=\"na\">description<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">my<\/span> <span class=\"s\">custom<\/span> <span class=\"s\">tier\"<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> mytier.yaml\r\ntier.security.antrea.tanzu.vmware.com\/mytier created\r\n<span class=\"err\">$<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl get tiers <span class=\"nt\">--sort-by<\/span><span class=\"o\">=<\/span>.spec.priority\r\nNAME          PRIORITY   AGE\r\nmytier        10         42s\r\nemergency     50         45m\r\nsecurityops   100        45m\r\nnetworkops    150        45m\r\nplatform      200        45m\r\napplication   250        45m\r\nbaseline      253        45m\r\n<\/code><\/pre>\n<h3>\u5e94\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565<\/h3>\n<p>\u6211\u4eec\u73b0\u5728\u8981\u5f00\u59cb\u521b\u5efaAntrea\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\u3002\u9996\u5148\uff0c\u521b\u5efa\u4ee5\u4e0b\u7684acnp1.yaml\u6587\u4ef6\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">crd.antrea.io\/v1alpha1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterNetworkPolicy<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">acnp-drop-access-to-redis<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">priority<\/span><span class=\"pi\">:<\/span> <span class=\"m\">5<\/span>\r\n  <span class=\"na\">tier<\/span><span class=\"pi\">:<\/span> <span class=\"s\">securityops<\/span>\r\n  <span class=\"na\">appliedTo<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">redis<\/span>\r\n  <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">action<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Allow<\/span>\r\n      <span class=\"na\">from<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n            <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n              <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">other<\/span>\r\n      <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">AllowFromOther<\/span>\r\n      <span class=\"na\">enableLogging<\/span><span class=\"pi\">:<\/span> <span class=\"kc\">false<\/span>\r\n<\/code><\/pre>\n<p>\u8fd9\u4e0e\u6211\u6700\u521d\u5728 NetworkPolicy \u4e2d\u521b\u5efa\u7684 np1.yaml \u975e\u5e38\u76f8\u4f3c\uff0c\u4f46\u5b9e\u9645\u64cd\u4f5c\u6709\u6240\u4e0d\u540c\u3002\u60a8\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u6765\u5e94\u7528\u6b64\u6e05\u5355\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> acnp1.yaml\r\nclusternetworkpolicy.crd.antrea.io\/acnp-drop-access-to-redis created\r\n<span class=\"nv\">$ <\/span>\r\n<span class=\"nv\">$ <\/span>kubectl get acnp\r\nNAME                        TIER          PRIORITY   DESIRED NODES   CURRENT NODES   AGE\r\nacnp-drop-access-to-redis   securityops   5          1               1               24s\r\n<\/code><\/pre>\n<p>\u4ee5\u8fd9\u79cd\u72b6\u6001\u8bbf\u95eeGuestbook\u5e94\u7528\u7a0b\u5e8f\u65f6\uff0c\u4e0d\u4f1a\u963b\u6b62\u5bf9\u540e\u7aef\u7684\u8bbf\u95ee\uff0c\u56e0\u6b64\u53ef\u4ee5\u6b63\u5e38\u663e\u793a\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/85-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u5f53\u4f7f\u7528 NetworkPolicy \u65f6\uff0c\u4e00\u65e6\u7b56\u7565\u751f\u6548\uff0c\u9690\u6027\u7684\u7684\u62d2\u7edd\u89c4\u5219\u5c06\u4f1a\u6fc0\u6d3b\uff0c\u88ab\u62d2\u7edd\u7684\u6d41\u91cf\u5c06\u4f1a\u88ab\u4e22\u5f03\u3002\u7136\u800c\uff0cACNP \u4e2d\uff0c\u9664\u975e\u663e\u6027\u5730\u5199\u660e Drop \u89c4\u5219\uff0c\u6d41\u91cf\u5c06\u4f1a\u88ab\u5141\u8bb8\u901a\u8fc7\u3002<br \/>\n\u9700\u8981\u6ce8\u610f\u7684\u662f\uff0cACNP \u7684\u7c7b\u578b\u4e3a ClusterNetworkPolicy\uff0c\u4f46\u662f\u53ef\u4ee5\u50cf\u4e0a\u9762\u7684 kubectl get acnp \u547d\u4ee4\u4e00\u6837\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528\u7f29\u5199 acnp \u6765\u8fdb\u884c\u64cd\u4f5c\u3002<\/p>\n<p>\u8fd9\u6b21\uff0c\u6211\u4eec\u5c06\u4fee\u6539acnp1.yaml\u5e76\u521b\u5efa\u5e76\u5e94\u7528\u4ee5\u4e0b\u7684acp11.yaml\u3002\u6211\u4eec\u5c06\u901a\u8fc7podSelector\u660e\u786e\u6307\u5b9a\u6e90Pod\uff0c\u5e76\u5c06action\u66f4\u6539\u4e3aDrop\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">crd.antrea.io\/v1alpha1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterNetworkPolicy<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">acnp-drop-access-to-redis<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">priority<\/span><span class=\"pi\">:<\/span> <span class=\"m\">5<\/span>\r\n  <span class=\"na\">tier<\/span><span class=\"pi\">:<\/span> <span class=\"s\">securityops<\/span>\r\n  <span class=\"na\">appliedTo<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">redis<\/span>\r\n  <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">action<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Drop<\/span>\r\n      <span class=\"na\">from<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n            <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n              <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">guestbook<\/span>\r\n      <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">DropFromGuestbook<\/span>\r\n      <span class=\"na\">enableLogging<\/span><span class=\"pi\">:<\/span> <span class=\"kc\">false<\/span>\r\n<\/code><\/pre>\n<p>\u5c06\u6b64\u540c\u6837\u9002\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> acnp11.yaml\r\nclusternetworkpolicy.crd.antrea.io\/acnp-drop-access-to-redis configured\r\n<\/code><\/pre>\n<p>\u7136\u540e\uff0c\u7531\u4e8e\u65e0\u6cd5\u8bbf\u95ee\u540e\u7aef\uff0c\u663e\u793a\u53d8\u6210\u4e86\u4ee5\u4e0b\u5185\u5bb9\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/92-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u5728\u8fd9\u4e2aACNP\u4e2d\uff0ctier\u88ab\u6307\u5b9a\u4e3asecurityops\uff0cpriority\u88ab\u6307\u5b9a\u4e3a5\u3002priority\u8868\u793a\u5728tier\u5185\u90e8\u7684\u5904\u7406\u4f18\u5148\u7ea7\u3002<br \/>\n\u4e0e\u4e0a\u8ff0\u60c5\u51b5\u76f8\u540c\uff0c\u6307\u5b9a\u7ed9securityops tier\u7684\u7b56\u7565\u5c06\u6bd4\u6807\u51c6\u7684\u7f51\u7edc\u7b56\u7565\u5177\u6709\u66f4\u9ad8\u7684\u4f18\u5148\u7ea7\u3002\u4f8b\u5982\uff0c\u6211\u4eec\u9996\u5148\u5e94\u7528np1.yaml\u4ee5\u521b\u5efa\u963b\u6b62\u5bf9\u540e\u7aef\u7684\u8bbf\u95ee\uff0c\u7136\u540e\u5e94\u7528acnp12.yaml\uff0c\u8fd9\u6837ACNP\u7684\u5904\u7406\u5c06\u4f18\u5148\u8fdb\u884c\uff0c\u4ece\u800c\u5141\u8bb8\u8bbf\u95ee\u540e\u7aef\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">crd.antrea.io\/v1alpha1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterNetworkPolicy<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">acnp-allow-access-to-redis<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">priority<\/span><span class=\"pi\">:<\/span> <span class=\"m\">5<\/span>\r\n  <span class=\"na\">tier<\/span><span class=\"pi\">:<\/span> <span class=\"s\">securityops<\/span>\r\n  <span class=\"na\">appliedTo<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">redis<\/span>\r\n  <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">action<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Allow<\/span>\r\n      <span class=\"na\">from<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"pi\">-<\/span> <span class=\"na\">podSelector<\/span><span class=\"pi\">:<\/span>\r\n            <span class=\"na\">matchLabels<\/span><span class=\"pi\">:<\/span>\r\n              <span class=\"na\">app<\/span><span class=\"pi\">:<\/span> <span class=\"s\">guestbook<\/span>\r\n      <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">AllowFromGuestbook<\/span>\r\n      <span class=\"na\">enableLogging<\/span><span class=\"pi\">:<\/span> <span class=\"kc\">false<\/span>\r\n<\/code><\/pre>\n<p>\u6211\u8ba4\u4e3a\u60a8\u73b0\u5728\u7406\u89e3\u4e86\u4f7f\u7528Antrea\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\u53ef\u4ee5\u6bd4\u6807\u51c6\u7684NetworkPolicy\u66f4\u6e05\u6670\u5730\u6307\u5b9a\u6e90\u548c\u76ee\u6807\u7684\u5b89\u5168\u7b56\u7565\u5b9a\u4e49\u3002<\/p>\n<h3>ACNP \u5bf9\u4e8e\u547d\u540d\u7a7a\u95f4\u4e4b\u95f4\u7684\u63a7\u5236<\/h3>\n<p>\u6211\u60f3\u5728\u8fd9\u91cc\u770b\u770b\u9694\u79bb\u547d\u540d\u7a7a\u95f4\u7684ACNP\u63a7\u5236\u3002\u5728\u6b64\u4e4b\u524d\uff0c\u8ba9\u6211\u4eec\u518d\u6b21\u786e\u8ba4\u4e00\u4e0bK8s NetworkPolicy\u7684\u884c\u4e3a\u3002\u590d\u5236\u4e4b\u524d\u4f7f\u7528\u7684np2.yaml\uff0c\u5e76\u521b\u5efa\u4e00\u4e2a\u540d\u4e3anp22.yaml\u7684\u526f\u672c\uff0c\u4ee5\u5141\u8bb8Guestbook\u5e94\u7528\u7a0b\u5e8f\u4e4b\u95f4\u7684\u6d41\u91cf\uff0c\u5e76\u5e94\u7528\u8be5\u526f\u672c\u3002<\/p>\n<pre class=\"post-pre\"><code>$ cat np22.yaml\r\nkind: NetworkPolicy\r\napiVersion: networking.k8s.io\/v1\r\nmetadata:\r\n  name: allow-access-from-to-guestbook\r\nspec:\r\n  policyTypes:\r\n  - Ingress\r\n  podSelector:\r\n    matchLabels:\r\n      app: guestbook\r\n  ingress:\r\n  - from:\r\n    - podSelector:\r\n        matchLabels:\r\n          app: guestbook\r\n$\r\n$ kubectl apply -f np22.yaml\r\nnetworkpolicy.networking.k8s.io\/allow-access-from-to-guestbook created\r\n$ \r\n<\/code><\/pre>\n<p>\u76ee\u524d\uff0c\u5df2\u90e8\u7f72\u5728 default \u548c test \u547d\u540d\u7a7a\u95f4\u4e2d\u7684 Pod \u7684\u72b6\u6001\u5982\u4e0b\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get pod -L app -n default\r\nNAME                 READY   STATUS    RESTARTS   AGE   APP\r\nguestbook-hmsrw      1\/1     Running   0          28d   guestbook\r\nguestbook-nl7xv      1\/1     Running   0          28d   guestbook\r\nguestbook-s9spp      1\/1     Running   0          28d   guestbook\r\nredis-master-blz4w   1\/1     Running   0          21d   redis\r\nredis-slave-fbsz6    1\/1     Running   0          21d   redis\r\nredis-slave-rpvqt    1\/1     Running   0          21d   redis\r\n$ \r\n$ kubectl get pod -L app -n test\r\nNAME              READY   STATUS    RESTARTS   AGE   APP\r\nguestbook-5w6ft   1\/1     Running   0          27d   guestbook\r\nguestbook-cfzfd   1\/1     Running   0          27d   guestbook\r\nguestbook-jlfpw   1\/1     Running   0          27d   guestbook\r\n$ \r\n<\/code><\/pre>\n<p>\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4e0d\u5141\u8bb8\u6765\u81eatest namespace\u4e2d\u7684Guestbook pod\u8bbf\u95eedefault namespace\u3002\u56e0\u4e3aK8s NetworkPolicy\u4e0d\u5141\u8bb8\u8de8\u8d8a\u547d\u540d\u7a7a\u95f4\u4f7f\u7528podSelector\u3002\u5b9e\u9645\u4e0a\uff0c\u4e0d\u5141\u8bb8test namespace\u4e2d\u7684Guestbook Pod\u8bbf\u95eedefault namespace\u4e2d\u7684Guestbook pod\uff0c\u5982\u4e0b\u6240\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl exec guestbook-5w6ft -n test  -it -- sh\r\n\r\n\r\nBusyBox v1.21.1 (Ubuntu 1:1.21.0-1ubuntu1) built-in shell (ash)\r\nEnter 'help' for a list of built-in commands.\r\n\r\n\/app # wget -O - http:\/\/guestbook.default.svc.cluster.local:3000\r\nConnecting to guestbook.default.svc.cluster.local:3000 (10.109.117.193:3000)\r\nwget: can't connect to remote host (10.109.117.193): Connection timed out\r\n\/app #\r\n\r\n<\/code><\/pre>\n<p>\u8ba9\u6211\u4eec\u5728\u4e2d\u56fd\u6587\u5316\u4ea7\u4e1a\u534f\u4f1a\u5c1d\u8bd5\u5236\u5b9a\u7c7b\u4f3c\u7684\u653f\u7b56\u5e76\u8fdb\u884c\u5b9e\u8df5\u3002<\/p>\n<pre class=\"post-pre\"><code>$ cat acnp2.yaml\r\napiVersion: crd.antrea.io\/v1alpha1\r\nkind: ClusterNetworkPolicy\r\nmetadata:\r\n  name: acnp-allow-access-from-to-guestbook\r\nspec:\r\n  priority: 5\r\n  tier: securityops\r\n  appliedTo:\r\n    - podSelector:\r\n        matchLabels:\r\n          app: guestbook\r\n  ingress:\r\n    - action: Allow\r\n      from:\r\n        - podSelector:\r\n            matchLabels:\r\n              app: guestbook\r\n      name: AllowFromGuestbook\r\n      enableLogging: false\r\n$\r\n$ kubectl apply -f acnp2.yaml\r\nclusternetworkpolicy.crd.antrea.io\/acnp-allow-access-from-to-guestbook created\r\n$ \r\n<\/code><\/pre>\n<p>\u4e0e np22.yaml \u76f8\u540c\uff0c\u6211\u4eec\u5728 appliedTo \u548c from \u7684 podSelector \u4e2d\u90fd\u6307\u5b9a\u4e86\u6807\u7b7e app: guestbook\uff0c\u4f46\u6ca1\u6709\u7279\u522b\u6307\u5b9a\u547d\u540d\u7a7a\u95f4\u3002\u53e6\u5916\uff0c\u4e4b\u524d\u521b\u5efa\u7684 K8s NetworkPolicy \u4e5f\u4fdd\u6301\u4e0d\u53d8\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get networkpolicy\r\nNAMESPACE   NAME                             POD-SELECTOR    AGE\r\ndefault     allow-access-from-to-guestbook   app=guestbook   32m\r\n$ \r\n$ kubectl get acnp\r\nNAME                                  TIER          PRIORITY   DESIRED NODES   CURRENT NODES   AGE\r\nacnp-allow-access-from-to-guestbook   securityops   5          2               2               10m\r\n<\/code><\/pre>\n<p>\u5f53\u4f7f\u7528\u6d4b\u8bd5\u7aef\u7684Pod\u518d\u6b21\u8bbf\u95ee\u9ed8\u8ba4\u7aef\u65f6\uff0c\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u5c06\u88ab\u6388\u6743\u5982\u4e0b\u3002<\/p>\n<pre class=\"post-pre\"><code>\/app # wget -O - http:\/\/guestbook.default.svc.cluster.local:3000\r\nConnecting to guestbook.default.svc.cluster.local:3000 (10.109.117.193:3000)\r\n&lt;!DOCTYPE html&gt;\r\n&lt;html lang=\"en\"&gt;\r\n  &lt;head&gt;\r\n    &lt;meta content=\"text\/html; charset=utf-8\" http-equiv=\"Content-Type\"&gt;\r\n    &lt;meta charset=\"utf-8\"&gt;\r\n    &lt;meta content=\"width=device-width\" name=\"viewport\"&gt;\r\n    &lt;link href=\"style.css\" rel=\"stylesheet\"&gt;\r\n    &lt;title&gt;Guestbook&lt;\/title&gt;\r\n  &lt;\/head&gt;\r\n  &lt;body&gt;\r\n    &lt;div id=\"header\"&gt;\r\n      &lt;h1&gt;Guestbook&lt;\/h1&gt;\r\n    &lt;\/div&gt;\r\n\r\n(snip...)\r\n\r\n  &lt;\/body&gt;\r\n&lt;\/html&gt;\r\n-                    100% |*******************************|   922   0:00:00 ETA\r\n\/app #\r\n<\/code><\/pre>\n<p>\u53e6\u5916\uff0c\u5728 ACNP \u4e2d\uff0c\u6211\u4eec\u53ef\u4ee5\u540c\u65f6\u4f7f\u7528 podSelector \u548c namespaceSelector \u6765\u660e\u786e\u6307\u5b9a\u9002\u7528\u4e8e\u6bcf\u4e2a\u547d\u540d\u7a7a\u95f4\u7684\u76ee\u6807\u548c\u6e90 pod\u3002\u6211\u4eec\u53ef\u4ee5\u7f16\u8f91 acnp2.yaml\uff0c\u5728\u5176\u4e2d\u6dfb\u52a0 namespaceSelector \u6761\u4ef6\uff0c\u4ece\u800c\u521b\u5efa acnp22.yaml\u3002<\/p>\n<pre class=\"post-pre\"><code>$ cat acnp22.yaml\r\napiVersion: crd.antrea.io\/v1alpha1\r\nkind: ClusterNetworkPolicy\r\nmetadata:\r\n  name: acnp-allow-access-from-to-guestbook\r\nspec:\r\n  priority: 5\r\n  tier: securityops\r\n  appliedTo:\r\n    - podSelector:\r\n        matchLabels:\r\n          app: guestbook\r\n      namespaceSelector:\r\n        matchLabels:\r\n          project: prod\r\n  ingress:\r\n    - action: Allow\r\n      from:\r\n        - podSelector:\r\n            matchLabels:\r\n              app: guestbook\r\n          namespaceSelector:\r\n            matchLabels:\r\n              project: test\r\n      name: AllowFromGuestbook\r\n      enableLogging: false\r\n$\r\n$ kubectl apply -f acnp22.yaml\r\nclusternetworkpolicy.crd.antrea.io\/acnp-allow-access-from-to-guestbook configured\r\n$ \r\n<\/code><\/pre>\n<p>\u901a\u8fc7\u8fd9\u4e2a\u4fee\u8ba2\uff0c\u63a5\u6536\u65b9\u547d\u540d\u7a7a\u95f4\u7684\u6807\u7b7e\u6761\u4ef6\u6dfb\u52a0\u4e86 project: prod\uff0c\u53d1\u9001\u65b9\u547d\u540d\u7a7a\u95f4\u7684\u6807\u7b7e\u6761\u4ef6\u6dfb\u52a0\u4e86 project: test\u3002\u7136\u800c\uff0c\u63a5\u6536\u65b9\u7684 Guestbook pod \u5b58\u5728\u4e8e\u9ed8\u8ba4\u7684\u547d\u540d\u7a7a\u95f4\u4e2d\uff0c\u4f46\u7531\u4e8e\u8fd8\u672a\u6dfb\u52a0\u6807\u7b7e\u5230\u547d\u540d\u7a7a\u95f4\u4e2d\uff0c\u6240\u4ee5\u901a\u4fe1\u5c06\u5931\u8d25\u3002<\/p>\n<pre class=\"post-pre\"><code>\/app # wget -O - http:\/\/guestbook.default.svc.cluster.local:3000\r\nConnecting to guestbook.default.svc.cluster.local:3000 (10.109.117.193:3000)\r\nwget: can't connect to remote host (10.109.117.193): Connection timed out\r\n\/app #\r\n<\/code><\/pre>\n<p>\u5728\u6b64\uff0c\u6211\u5011\u5c07\u5728\u9ed8\u8a8d\u547d\u540d\u7a7a\u9593\u4e2d\u6dfb\u52a0\u6a19\u7c64\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl label ns default project=prod\r\nnamespace\/default labeled\r\n$ \r\n$ kubectl get ns --show-labels\r\nNAME              STATUS   AGE   LABELS\r\ndefault           Active   29d   project=prod\r\nkube-node-lease   Active   29d   &lt;none&gt;\r\nkube-public       Active   29d   &lt;none&gt;\r\nkube-system       Active   29d   &lt;none&gt;\r\ntest              Active   27d   project=test\r\n<\/code><\/pre>\n<p>\u3059\u308b\u3068 test namespace \u5185\u306e Guestbook pod \u304b\u3089 default namespace \u5185\u306e Guestbook pod \u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<pre class=\"post-pre\"><code>\/app # wget -O - http:\/\/guestbook.default.svc.cluster.local:3000\r\nConnecting to guestbook.default.svc.cluster.local:3000 (10.109.117.193:3000)\r\n&lt;!DOCTYPE html&gt;\r\n&lt;html lang=\"en\"&gt;\r\n  &lt;head&gt;\r\n    &lt;meta content=\"text\/html; charset=utf-8\" http-equiv=\"Content-Type\"&gt;\r\n    &lt;meta charset=\"utf-8\"&gt;\r\n    &lt;meta content=\"width=device-width\" name=\"viewport\"&gt;\r\n    &lt;link href=\"style.css\" rel=\"stylesheet\"&gt;\r\n    &lt;title&gt;Guestbook&lt;\/title&gt;\r\n  &lt;\/head&gt;\r\n  &lt;body&gt;\r\n    &lt;div id=\"header\"&gt;\r\n      &lt;h1&gt;Guestbook&lt;\/h1&gt;\r\n    &lt;\/div&gt;\r\n\r\n(snip...)\r\n\r\n  &lt;\/body&gt;\r\n&lt;\/html&gt;\r\n-                    100% |*******************************|   922   0:00:00 ETA\r\n\/app #\r\n\r\n<\/code><\/pre>\n<p>\u3053\u306e\u3088\u3046\u306b\u3001Antrea Cluster Network Policy \u3067\u306f\u3001namespace \u306b\u9650\u5b9a\u3055\u308c\u306a\u3044\u30af\u30e9\u30b9\u30bf\u30fc\u30ec\u30d9\u30eb\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30dd\u30ea\u30b7\u30fc\u3092\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002\u30af\u30e9\u30b9\u30bf\u30fc\u7ba1\u7406\u8005\u306f namespace \u306b\u4f9d\u5b58\u3057\u306a\u3044\u30af\u30e9\u30b9\u30bf\u30fc\u30ec\u30d9\u30eb\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30dd\u30ea\u30b7\u30fc\u3092\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<h2>ClusterGroup<\/h2>\n<p>ClusterGroup \u306f ACNP \u306e\u7279\u5fb4\u7684\u306a\u6a5f\u80fd\u306e\u4e00\u3064\u3067\u3001\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3092\u30b0\u30eb\u30fc\u30d4\u30f3\u30b0\u3059\u308b\u30eb\u30fc\u30eb\u3092 NetworkPolicy \u306e\u5916\u3067\u4f5c\u6210\u3057\u518d\u5229\u7528\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u306b\u7d39\u4ecb\u3057\u305f podSelector \u3084 namespaceSelector\u3001\u304a\u306a\u3058\u307f\u306e ipBlock \u4ee5\u5916\u306b\u3001K8s Service \u3092\u5229\u7528\u3059\u308b serviceReference \u3084\u30b0\u30eb\u30fc\u30d4\u30f3\u30b0\u306e\u30cd\u30b9\u30c8\u69cb\u9020\u3092\u5b9a\u7fa9\u3067\u304d\u308b childGroups \u3068\u3044\u3063\u305f\u5b9a\u7fa9\u3092\u4f7f\u3046\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<p>\u5728\u4f7f\u7528ClusterGroup\u521b\u5efa\u89c4\u5219\u4e4b\u524d\uff0c\u9700\u8981\u5148\u5c06\u4ee5\u524d\u521b\u5efa\u7684\u6240\u6709\u7b56\u7565\u5168\u90e8\u5220\u9664\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get networkpolicy --no-headers | awk '{print $1}'| xargs kubectl delete networkpolicy\r\nnetworkpolicy.networking.k8s.io \"allow-access-from-to-guestbook\" deleted\r\n$ \r\n$ kubectl get acnp --no-headers | awk '{print $1}'| xargs kubectl delete acnp\r\nclusternetworkpolicy.crd.antrea.io \"acnp-allow-access-from-to-guestbook\" deleted\r\n<\/code><\/pre>\n<p>\u305d\u3057\u3066 default namespace \u5185\u306e Pod \u3078\u306e\u3059\u3079\u3066\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u6697\u9ed9\u7684\u306b\u4e0d\u8a31\u53ef\u306b\u3059\u308b\u305f\u3081\u306b\u4ee5\u4e0b\u306e acnp-dropany.yaml \u3092\u4f5c\u6210\u3057\u9069\u7528\u3057\u307e\u3059\u3002\u9069\u7528\u5148\u306e Tier \u3068\u3057\u3066 baseline \u3092\u6307\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u5834\u5408\u3001\u3053\u306e\u30eb\u30fc\u30eb\u306f K8s NetworkPolicy \u3092\u542b\u3080\u3059\u3079\u3066\u306e\u30dd\u30ea\u30b7\u30fc\u30eb\u30fc\u30eb\u304c\u8a55\u4fa1\u3055\u308c\u305f\u5f8c\u306b\u9069\u7528\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code>$ cat acnp-dropany.yaml\r\n\r\napiVersion: crd.antrea.io\/v1alpha1\r\nkind: ClusterNetworkPolicy\r\nmetadata:\r\n  name: acnp-drop-any-in-production\r\nspec:\r\n  priority: 100\r\n  tier: baseline\r\n  appliedTo:\r\n    - podSelector: {}\r\n      namespaceSelector:\r\n        matchLabels:\r\n          project: prod\r\n  ingress:\r\n    - action: Drop\r\n      from:\r\n        - podSelector: {}\r\n      name: DropFromAny\r\n      enableLogging: false\r\n$\r\n$ kubectl apply -f acnp-dropany.yaml\r\nclusternetworkpolicy.crd.antrea.io\/acnp-drop-any-in-production created\r\n$\r\n<\/code><\/pre>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/124-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u305d\u3053\u3067\u3001 \u30d5\u30ed\u30f3\u30c8\u30a8\u30f3\u30c9\u3068\u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u9593\u306e\u901a\u4fe1\u3092\u8a31\u53ef\u3059\u308b\u30dd\u30ea\u30b7\u30fc\u3092\u8a18\u8f09\u3057\u3066\u3044\u304d\u307e\u3059\u304c\u3001\u305d\u3053\u3067 ClusterGroup \u3092\u4f7f\u7528\u3057\u3066\u307f\u307e\u3059\u3002\u3053\u3053\u3067\u306f\u3001Redis \u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u30b5\u30fc\u30d3\u30b9\u306e\u30b0\u30eb\u30fc\u30d4\u30f3\u30b0\u306b serviceReference \u3068 childGroups \u3092\u4f7f\u3063\u3066\u307f\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code>$ cat cg1.yaml\r\napiVersion: crd.antrea.io\/v1alpha2\r\nkind: ClusterGroup\r\nmetadata:\r\n  name: cg-guestbook\r\nspec:\r\n  podSelector:\r\n    matchLabels:\r\n      app: guestbook\r\n---\r\napiVersion: crd.antrea.io\/v1alpha2\r\nkind: ClusterGroup\r\nmetadata:\r\n  name: cg-redis-master\r\nspec:\r\n  serviceReference:\r\n    name: redis-master\r\n    namespace: default\r\n---\r\napiVersion: crd.antrea.io\/v1alpha2\r\nkind: ClusterGroup\r\nmetadata:\r\n  name: cg-redis-slave\r\nspec:\r\n  serviceReference:\r\n    name: redis-slave\r\n    namespace: default\r\n---\r\napiVersion: crd.antrea.io\/v1alpha2\r\nkind: ClusterGroup\r\nmetadata:\r\n  name: cg-redis-nested\r\nspec:\r\n  childGroups: [cg-redis-master, cg-redis-slave]\r\n$\r\n$ kubectl apply -f cg1.yaml\r\nclustergroup.crd.antrea.io\/cg-guestbook created\r\nclustergroup.crd.antrea.io\/cg-redis-master created\r\nclustergroup.crd.antrea.io\/cg-redis-slave created\r\nclustergroup.crd.antrea.io\/cg-redis-nested created\r\n$ \r\n<\/code><\/pre>\n<p>\u6b21\u306b\u3053\u308c\u3089\u306e ClusterGroup \u3092\u5229\u7528\u3057\u305f ACNP \u3092 acnp3.yaml \u3068\u3057\u3066\u4f5c\u6210\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code>$ cat acnp3.yaml\r\napiVersion: crd.antrea.io\/v1alpha1\r\nkind: ClusterNetworkPolicy\r\nmetadata:\r\n  name: acnp-allow-access-to-guestbook\r\nspec:\r\n  priority: 5\r\n  tier: securityops\r\n  appliedTo:\r\n    - group: \"cg-guestbook\"\r\n  ingress:\r\n    - action: Allow\r\n      from:\r\n        - group: \"cg-guestbook\"\r\n      name: AllowToGuestbook\r\n      enableLogging: false\r\n---\r\napiVersion: crd.antrea.io\/v1alpha1\r\nkind: ClusterNetworkPolicy\r\nmetadata:\r\n  name: acnp-allow-access-to-redis\r\nspec:\r\n  priority: 5\r\n  tier: securityops\r\n  appliedTo:\r\n    - group: \"cg-redis-nested\"\r\n  ingress:\r\n    - action: Allow\r\n      from:\r\n        - group: \"cg-guestbook\"\r\n      name: AllowFromGuestbookToRedis\r\n      enableLogging: false\r\n---\r\napiVersion: crd.antrea.io\/v1alpha1\r\nkind: ClusterNetworkPolicy\r\nmetadata:\r\n  name: acnp-allow-access-to-redis-slave\r\nspec:\r\n  priority: 5\r\n  tier: securityops\r\n  appliedTo:\r\n    - group: \"cg-redis-slave\"\r\n  ingress:\r\n    - action: Allow\r\n      from:\r\n        - group: \"cg-redis-master\"\r\n      name: AllowToRedisSlave\r\n      enableLogging: false\r\n$\r\n$ kubectl apply -f acnp3.yaml\r\nclusternetworkpolicy.crd.antrea.io\/acnp-allow-access-to-guestbook created\r\nclusternetworkpolicy.crd.antrea.io\/acnp-allow-access-to-redis created\r\nclusternetworkpolicy.crd.antrea.io\/acnp-allow-access-to-redis-slave created\r\n$ \r\n<\/code><\/pre>\n<p>\u5728\u8fd9\u79cd\u72b6\u6001\u4e0b\u901a\u8fc7\u6d4f\u89c8\u5668\u8bbf\u95ee\uff0c\u5141\u8bb8\u8bbf\u95ee Redis \u540e\u7aef\u5e76\u6210\u529f\u8fd4\u56de\u6b63\u5e38\u54cd\u5e94\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/130-0.png\" alt=\"image.png\" \/><\/div>\n<p>\u3044\u304b\u304c\u3067\u3057\u305f\u3067\u3057\u3087\u3046\u304b\u3002Antrea Cluster Network Policy \u3067\u306f\u3001\u30af\u30e9\u30b9\u30bf\u30fc\u30ec\u30d9\u30eb\u3067\u67d4\u8edf\u306a\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306e\u30b0\u30eb\u30fc\u30d4\u30f3\u30b0\u304c\u53ef\u80fd\u306b\u306a\u3063\u3066\u3044\u308b\u3053\u3068\u3092\u7406\u89e3\u3044\u305f\u3060\u3051\u305f\u304b\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>\u6211\u5e0c\u671b\u5728\u63a5\u4e0b\u6765\u7684\u65f6\u95f4\u91cc\uff0c\u80fd\u591f\u4e3a\u5927\u5bb6\u4ecb\u7ecd\u66f4\u8be6\u7ec6\u7684Antrea\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\u64cd\u4f5c\u65b9\u6cd5\u7b49\u5185\u5bb9\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Antrea\u662f\u4ec0\u4e48&#8221; Antrea\u662f\u4e00\u4e2a\u5f00\u6e90\u7684Kubernetes CNI\uff0c\u4e3aKub [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-33724","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528-antrea-\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021-\u7248\uff09\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09\" \/>\n<meta property=\"og:description\" content=\"&#8220;Antrea\u662f\u4ec0\u4e48&#8221; Antrea\u662f\u4e00\u4e2a\u5f00\u6e90\u7684Kubernetes CNI\uff0c\u4e3aKub [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528-antrea-\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021-\u7248\uff09\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-29T06:44:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-28T15:26:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/37-0.png\" \/>\n<meta name=\"author\" content=\"\u79d1, \u9896\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u79d1, \u9896\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/\",\"name\":\"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-04-29T06:44:15+00:00\",\"dateModified\":\"2024-04-28T15:26:49+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e\",\"name\":\"\u79d1, \u9896\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g\",\"caption\":\"\u79d1, \u9896\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/keying\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528-antrea-\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021-\u7248\uff09\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09","og_description":"&#8220;Antrea\u662f\u4ec0\u4e48&#8221; Antrea\u662f\u4e00\u4e2a\u5f00\u6e90\u7684Kubernetes CNI\uff0c\u4e3aKub [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528-antrea-\u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021-\u7248\uff09\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-04-29T06:44:15+00:00","article_modified_time":"2024-04-28T15:26:49+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d193137434c4406c087a3\/37-0.png"}],"author":"\u79d1, \u9896","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u79d1, \u9896","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"12 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/","name":"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-04-29T06:44:15+00:00","dateModified":"2024-04-28T15:26:49+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528 Antrea \u96c6\u7fa4\u7f51\u7edc\u7b56\u7565\uff082021 \u7248\uff09"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e","name":"\u79d1, \u9896","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g","caption":"\u79d1, \u9896"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/keying\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8-antrea-%e9%9b%86%e7%be%a4%e7%bd%91%e7%bb%9c%e7%ad%96%e7%95%a5%ef%bc%882021-%e7%89%88%ef%bc%89\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=33724"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33724\/revisions"}],"predecessor-version":[{"id":64946,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33724\/revisions\/64946"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=33724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=33724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=33724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}