NetworkPolicy resources that
restrict which traffic can reach the controller manager pod — the operator
process itself, not the ClickHouse server or Keeper pods. They are off by
default, so you opt in only when you want to isolate the operator’s ingress.
The policies cover the two ports the operator exposes to other clients: the metrics
endpoint and the admission webhook.
A
NetworkPolicy is only enforced when the cluster’s CNI plugin implements it
(for example Calico or Cilium). On a CNI without NetworkPolicy enforcement the
resources are created but silently have no effect — Kubernetes does not return an
error. Confirm your CNI enforces policies before relying on them.What the Helm chart creates
When enabled, the chart creates up to two ingress-only policies, both selecting the controller manager pod:
Both policies declare only
policyTypes: [Ingress]. They do not restrict egress
from the operator, and they do not touch ClickHouse server or Keeper pods.
Default-deny behavior
Selecting a pod with an ingressNetworkPolicy switches that pod to default
deny for ingress: once either policy applies, any inbound traffic to the
controller manager pod that is not explicitly allowed is dropped. After enabling,
the only ingress that reaches the operator is:
- a metrics scrape from a namespace labeled
metrics: enabled, and - an admission webhook call from a namespace labeled
webhook: enabled.
Enabling the policies
With Helm, set the gate in your values:allow-webhook-traffic additionally requires webhook.enabled: true (the
default), so disabling the webhook also removes its policy.
With the raw kubectl manifests, uncomment the [NETWORK POLICY] section as
described in the kubectl install guide.
The raw manifests ship the same two policies.
Labeling client namespaces
Because both policies match the source bynamespaceSelector, every namespace
that needs to reach the operator must carry the matching label. A scrape or
webhook call from an unlabeled namespace is dropped.
Verifying
- Prometheus still scrapes the metrics endpoint (its namespace is labeled
metrics: enabledand bound to the metrics-reader ClusterRole). - Creating or updating a
ClickHouseClusterstill passes admission (the webhook is reachable).
Related guides
- Monitoring the operator — the metrics endpoint, its RBAC, and securing scrapes.
- Install with kubectl — where to uncomment the network policy section.
- Install with Helm — chart values relevant to the operator.