---
# Network policy for Metabase analytics service
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: metabase-policy
  namespace: vibecarbon
spec:
  podSelector:
    matchLabels:
      app: metabase
  policyTypes:
    - Ingress
    - Egress
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: vibecarbon-traefik
        - podSelector:
            matchLabels:
              app: vibecarbon-app
      ports:
        - protocol: TCP
          port: 3000
  egress:
    # DNS resolution
    - ports:
        - protocol: UDP
          port: 53
        - protocol: TCP
          port: 53
    # PostgreSQL
    - to:
        - podSelector:
            matchLabels:
              app: vibecarbon-postgres
      ports:
        - protocol: TCP
          port: 5432
    # External HTTP/HTTPS (for license checks, plugin downloads, etc.)
    - to:
        - ipBlock:
            cidr: 0.0.0.0/0
            except:
              - 10.0.0.0/8
              - 172.16.0.0/12
              - 192.168.0.0/16
      ports:
        - protocol: TCP
          port: 443
        - protocol: TCP
          port: 80
---
# Allow metabase to connect to postgres
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: metabase-database-ingress
  namespace: vibecarbon
spec:
  podSelector:
    matchLabels:
      app: vibecarbon-postgres
  policyTypes:
    - Ingress
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: metabase
      ports:
        - protocol: TCP
          port: 5432
