--- apiVersion: networking.k8s.io/v1 items: - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: internal.config.kubernetes.io/previousKinds: NetworkPolicy internal.config.kubernetes.io/previousNames: kserve-controller-manager internal.config.kubernetes.io/previousNamespaces: opendatahub platform.opendatahub.io/instance.generation: "1" platform.opendatahub.io/instance.name: default-kserve platform.opendatahub.io/instance.uid: 4cb5dcb5-89c7-4731-8a3e-99b8df169069 platform.opendatahub.io/type: Open Data Hub platform.opendatahub.io/version: 3.4.0-ea.1 creationTimestamp: "2026-04-20T13:38:14Z" generation: 1 labels: app.kubernetes.io/part-of: kserve app.opendatahub.io/kserve: "true" platform.opendatahub.io/part-of: kserve managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: f:internal.config.kubernetes.io/previousKinds: {} f:internal.config.kubernetes.io/previousNames: {} f:internal.config.kubernetes.io/previousNamespaces: {} f:platform.opendatahub.io/instance.generation: {} f:platform.opendatahub.io/instance.name: {} f:platform.opendatahub.io/instance.uid: {} f:platform.opendatahub.io/type: {} f:platform.opendatahub.io/version: {} f:labels: f:app.kubernetes.io/part-of: {} f:app.opendatahub.io/kserve: {} f:platform.opendatahub.io/part-of: {} f:ownerReferences: k:{"uid":"4cb5dcb5-89c7-4731-8a3e-99b8df169069"}: {} f:spec: f:ingress: {} f:podSelector: {} manager: kserve operation: Apply time: "2026-04-20T13:38:14Z" name: kserve-controller-manager namespace: opendatahub ownerReferences: - apiVersion: components.platform.opendatahub.io/v1alpha1 blockOwnerDeletion: true controller: true kind: Kserve name: default-kserve uid: 4cb5dcb5-89c7-4731-8a3e-99b8df169069 resourceVersion: "15705" uid: f6d9174d-15c1-44bd-9201-b4967cfeaee1 spec: ingress: - {} podSelector: matchLabels: control-plane: kserve-controller-manager policyTypes: - Ingress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: internal.config.kubernetes.io/previousKinds: NetworkPolicy internal.config.kubernetes.io/previousNames: maas-api-cleanup-restrict internal.config.kubernetes.io/previousNamespaces: opendatahub creationTimestamp: "2026-04-20T13:40:38Z" generation: 9 labels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service app.opendatahub.io/modelsasservice: "true" maas.opendatahub.io/tenant-name: default-tenant maas.opendatahub.io/tenant-namespace: models-as-a-service managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: f:internal.config.kubernetes.io/previousKinds: {} f:internal.config.kubernetes.io/previousNames: {} f:internal.config.kubernetes.io/previousNamespaces: {} f:labels: f:app.kubernetes.io/component: {} f:app.kubernetes.io/name: {} f:app.kubernetes.io/part-of: {} f:app.opendatahub.io/modelsasservice: {} f:maas.opendatahub.io/tenant-name: {} f:maas.opendatahub.io/tenant-namespace: {} f:spec: f:egress: {} f:ingress: {} f:podSelector: {} f:policyTypes: {} manager: maas-controller operation: Apply time: "2026-04-20T13:59:34Z" name: maas-api-cleanup-restrict namespace: opendatahub resourceVersion: "38598" uid: 95e95645-94bd-4046-965e-602c46ce5915 spec: egress: - ports: - port: 8080 protocol: TCP to: - podSelector: matchLabels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service - ports: - port: 53 protocol: UDP - port: 53 protocol: TCP podSelector: matchLabels: app: maas-api-cleanup app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service policyTypes: - Egress - Ingress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: internal.config.kubernetes.io/previousKinds: NetworkPolicy internal.config.kubernetes.io/previousNames: maas-authorino-allow internal.config.kubernetes.io/previousNamespaces: opendatahub creationTimestamp: "2026-04-20T13:40:38Z" generation: 1 labels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service app.opendatahub.io/modelsasservice: "true" maas.opendatahub.io/tenant-name: default-tenant maas.opendatahub.io/tenant-namespace: models-as-a-service managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: f:internal.config.kubernetes.io/previousKinds: {} f:internal.config.kubernetes.io/previousNames: {} f:internal.config.kubernetes.io/previousNamespaces: {} f:labels: f:app.kubernetes.io/component: {} f:app.kubernetes.io/name: {} f:app.kubernetes.io/part-of: {} f:app.opendatahub.io/modelsasservice: {} f:maas.opendatahub.io/tenant-name: {} f:maas.opendatahub.io/tenant-namespace: {} f:spec: f:ingress: {} f:podSelector: {} f:policyTypes: {} manager: maas-controller operation: Apply time: "2026-04-20T13:40:38Z" name: maas-authorino-allow namespace: opendatahub resourceVersion: "21507" uid: 6da6ce26-9239-4a88-802d-2c3571caf8fb spec: ingress: - from: - namespaceSelector: matchExpressions: - key: kubernetes.io/metadata.name operator: In values: - kuadrant-system - openshift-operators podSelector: matchLabels: authorino-resource: authorino podSelector: matchLabels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service policyTypes: - Ingress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: creationTimestamp: "2026-04-20T13:37:27Z" generation: 1 managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:ownerReferences: k:{"uid":"3cf84140-deda-474b-9923-aac1a11ece4d"}: {} f:spec: f:ingress: {} f:podSelector: {} f:policyTypes: {} manager: dscinitialization.opendatahub.io operation: Apply time: "2026-04-20T13:37:27Z" name: opendatahub namespace: opendatahub ownerReferences: - apiVersion: dscinitialization.opendatahub.io/v2 blockOwnerDeletion: true controller: true kind: DSCInitialization name: default-dsci uid: 3cf84140-deda-474b-9923-aac1a11ece4d resourceVersion: "13565" uid: 047ec253-53ef-4f72-b19f-4732a421f753 spec: ingress: - from: - namespaceSelector: matchLabels: opendatahub.io/generated-namespace: "true" - from: - namespaceSelector: matchLabels: opendatahub.io/application-namespace: "true" - from: - namespaceSelector: matchLabels: network.openshift.io/policy-group: ingress - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: openshift-host-network - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: openshift-monitoring - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: openshift-cluster-observability-operator podSelector: {} policyTypes: - Ingress kind: NetworkPolicyList metadata: resourceVersion: "41055"