peerauthentication-port-level-exception
Enforce STRICT mTLS for the api-gateway workload except disable mTLS on port 8080.
A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: app-port-exception
namespace: default
annotations:
cenroq.io/displayName: "mTLS Port Exception"
cenroq.io/description: "Enforce STRICT mTLS for the api-gateway workload except disable mTLS on port 8080."
spec:
selector:
matchLabels:
app: api-gateway
mtls:
mode: STRICT
portLevelMtls:
8080:
mode: DISABLESave it as peerauthentication-port-level-exception.yaml — the commands below assume that name.
This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:
$ kubectl apply -f ./peerauthentication-port-level-exception.yaml