--- apiVersion: networking.k8s.io/v1 items: - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: internal.config.kubernetes.io/previousKinds: NetworkPolicy internal.config.kubernetes.io/previousNames: kserve-controller-manager internal.config.kubernetes.io/previousNamespaces: opendatahub platform.opendatahub.io/instance.generation: "1" platform.opendatahub.io/instance.name: default-kserve platform.opendatahub.io/instance.uid: 0b4875a6-564c-44f8-a9d2-d77593449d1a platform.opendatahub.io/type: Open Data Hub platform.opendatahub.io/version: 3.4.0-ea.1 creationTimestamp: "2026-04-17T20:11:29Z" generation: 1 labels: app.kubernetes.io/part-of: kserve app.opendatahub.io/kserve: "true" platform.opendatahub.io/part-of: kserve managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: f:internal.config.kubernetes.io/previousKinds: {} f:internal.config.kubernetes.io/previousNames: {} f:internal.config.kubernetes.io/previousNamespaces: {} f:platform.opendatahub.io/instance.generation: {} f:platform.opendatahub.io/instance.name: {} f:platform.opendatahub.io/instance.uid: {} f:platform.opendatahub.io/type: {} f:platform.opendatahub.io/version: {} f:labels: f:app.kubernetes.io/part-of: {} f:app.opendatahub.io/kserve: {} f:platform.opendatahub.io/part-of: {} f:ownerReferences: k:{"uid":"0b4875a6-564c-44f8-a9d2-d77593449d1a"}: {} f:spec: f:ingress: {} f:podSelector: {} manager: kserve operation: Apply time: "2026-04-17T20:11:29Z" name: kserve-controller-manager namespace: opendatahub ownerReferences: - apiVersion: components.platform.opendatahub.io/v1alpha1 blockOwnerDeletion: true controller: true kind: Kserve name: default-kserve uid: 0b4875a6-564c-44f8-a9d2-d77593449d1a resourceVersion: "16184" uid: 61c00b5f-f5ff-44cd-be13-90d4f92a1eea spec: ingress: - {} podSelector: matchLabels: control-plane: kserve-controller-manager policyTypes: - Ingress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: internal.config.kubernetes.io/previousKinds: NetworkPolicy internal.config.kubernetes.io/previousNames: maas-api-cleanup-restrict internal.config.kubernetes.io/previousNamespaces: opendatahub creationTimestamp: "2026-04-17T20:14:05Z" generation: 6 labels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service app.opendatahub.io/modelsasservice: "true" maas.opendatahub.io/tenant-name: default-tenant maas.opendatahub.io/tenant-namespace: models-as-a-service managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: f:internal.config.kubernetes.io/previousKinds: {} f:internal.config.kubernetes.io/previousNames: {} f:internal.config.kubernetes.io/previousNamespaces: {} f:labels: f:app.kubernetes.io/component: {} f:app.kubernetes.io/name: {} f:app.kubernetes.io/part-of: {} f:app.opendatahub.io/modelsasservice: {} f:maas.opendatahub.io/tenant-name: {} f:maas.opendatahub.io/tenant-namespace: {} f:spec: f:egress: {} f:ingress: {} f:podSelector: {} f:policyTypes: {} manager: maas-controller operation: Apply time: "2026-04-17T20:19:44Z" name: maas-api-cleanup-restrict namespace: opendatahub resourceVersion: "27204" uid: f0c5e797-aa65-4e7d-ab67-43f0afc43b8f spec: egress: - ports: - port: 8080 protocol: TCP to: - podSelector: matchLabels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service - ports: - port: 53 protocol: UDP - port: 53 protocol: TCP podSelector: matchLabels: app: maas-api-cleanup app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service policyTypes: - Egress - Ingress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: internal.config.kubernetes.io/previousKinds: NetworkPolicy internal.config.kubernetes.io/previousNames: maas-authorino-allow internal.config.kubernetes.io/previousNamespaces: opendatahub creationTimestamp: "2026-04-17T20:14:05Z" generation: 1 labels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service app.opendatahub.io/modelsasservice: "true" maas.opendatahub.io/tenant-name: default-tenant maas.opendatahub.io/tenant-namespace: models-as-a-service managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: f:internal.config.kubernetes.io/previousKinds: {} f:internal.config.kubernetes.io/previousNames: {} f:internal.config.kubernetes.io/previousNamespaces: {} f:labels: f:app.kubernetes.io/component: {} f:app.kubernetes.io/name: {} f:app.kubernetes.io/part-of: {} f:app.opendatahub.io/modelsasservice: {} f:maas.opendatahub.io/tenant-name: {} f:maas.opendatahub.io/tenant-namespace: {} f:spec: f:ingress: {} f:podSelector: {} f:policyTypes: {} manager: maas-controller operation: Apply time: "2026-04-17T20:14:05Z" name: maas-authorino-allow namespace: opendatahub resourceVersion: "22164" uid: 519d86fc-1112-44d8-93d0-d0e496d524d5 spec: ingress: - from: - namespaceSelector: matchExpressions: - key: kubernetes.io/metadata.name operator: In values: - kuadrant-system - openshift-operators podSelector: matchLabels: authorino-resource: authorino podSelector: matchLabels: app.kubernetes.io/component: api app.kubernetes.io/name: maas-api app.kubernetes.io/part-of: models-as-a-service policyTypes: - Ingress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: creationTimestamp: "2026-04-17T20:10:39Z" generation: 1 managedFields: - apiVersion: networking.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:ownerReferences: k:{"uid":"6e34e736-4159-4b2e-a604-d642fd9fb946"}: {} f:spec: f:ingress: {} f:podSelector: {} f:policyTypes: {} manager: dscinitialization.opendatahub.io operation: Apply time: "2026-04-17T20:10:39Z" name: opendatahub namespace: opendatahub ownerReferences: - apiVersion: dscinitialization.opendatahub.io/v2 blockOwnerDeletion: true controller: true kind: DSCInitialization name: default-dsci uid: 6e34e736-4159-4b2e-a604-d642fd9fb946 resourceVersion: "13990" uid: 6b091704-2cbc-4a59-bcb0-cca5c09d1e93 spec: ingress: - from: - namespaceSelector: matchLabels: opendatahub.io/generated-namespace: "true" - from: - namespaceSelector: matchLabels: opendatahub.io/application-namespace: "true" - from: - namespaceSelector: matchLabels: network.openshift.io/policy-group: ingress - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: openshift-host-network - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: openshift-monitoring - from: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: openshift-cluster-observability-operator podSelector: {} policyTypes: - Ingress kind: NetworkPolicyList metadata: resourceVersion: "27467"