diff --git a/nix/kubernetes/keys/scope.nix b/nix/kubernetes/keys/scope.nix index 47ee352c..1414f6e2 100644 --- a/nix/kubernetes/keys/scope.nix +++ b/nix/kubernetes/keys/scope.nix @@ -259,6 +259,8 @@ makeScope newScope ( }; }; + "policyEnforcementMode" = "never"; + # TODO: Read and maybe apply https://docs.cilium.io/en/stable/operations/performance/tuning/ # --set hostFirewall.enabled=true diff --git a/nix/kubernetes/roles/firewall/default.nix b/nix/kubernetes/roles/firewall/default.nix index b983de65..3630b5c7 100644 --- a/nix/kubernetes/roles/firewall/default.nix +++ b/nix/kubernetes/roles/firewall/default.nix @@ -53,9 +53,9 @@ # Check logs for blocked connections: # journalctl -k or dmesg - networking.nftables.tables."my-fw" = { - family = "inet"; - content = (builtins.readFile ./files/my-fw.nft); - }; + # networking.nftables.tables."my-fw" = { + # family = "inet"; + # content = (builtins.readFile ./files/my-fw.nft); + # }; }; }