1.6. Disabling the default network policies


The OpenShift Serverless Operator generates the network policies by default. To disable the default network policy generation, you can add the serverless.openshift.io/disable-istio-net-policies-generation annotation in the KnativeEventing and KnativeServing custom resources (CRs).

Prerequisites

  • You have one of the following permissions to access the cluster:

    • Cluster administrator permissions on OpenShift Container Platform
    • Cluster administrator permissions on Red Hat OpenShift Service on AWS
    • Dedicated administrator permissions on OpenShift Dedicated
  • You have installed the OpenShift CLI (oc).
  • You have access to a project with the appropriate roles and permissions to create applications and other workloads.
  • You have installed the OpenShift Serverless Operator, Knative Serving, and Knative Eventing on your cluster.
  • You have installed Red Hat OpenShift Service Mesh with the mTLS functionality enabled.

Procedure

  • Add the serverless.openshift.io/disable-istio-net-policies-generation: "true" annotation to your Knative custom resources.

    注意

    The OpenShift Serverless Operator generates the required network policies by default. When you configure ServiceMeshControlPlane with manageNetworkPolicy: false, you must disable the default network policy generation to ensure proper event delivery. To disable the default network policy generation, you can add the serverless.openshift.io/disable-istio-net-policies-generation annotation in the KnativeEventing and KnativeServing custom resources (CRs).

    1. Annotate the KnativeEventing CR by running the following command:

      $ oc edit KnativeEventing -n knative-eventing

      Example KnativeEventing CR

      apiVersion: operator.knative.dev/v1beta1
      kind: KnativeEventing
      metadata:
        name: knative-eventing
        namespace: knative-eventing
        annotations:
          serverless.openshift.io/disable-istio-net-policies-generation: "true"

    2. Annotate the KnativeServing CR by running the following command:

      $ oc edit KnativeServing -n knative-serving

      Example KnativeServing CR

      apiVersion: operator.knative.dev/v1beta1
      kind: KnativeServing
      metadata:
        name: knative-serving
        namespace: knative-serving
        annotations:
          serverless.openshift.io/disable-istio-net-policies-generation: "true"

Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

关于红帽文档

Legal Notice

Theme

© 2026 Red Hat
返回顶部