adamant-kite-43734
06/07/2023, 1:33 PMquiet-fountain-46593
06/07/2023, 2:48 PMcrooked-terabyte-91046
06/07/2023, 2:52 PMtarget:
policymode: Monitor
selector:
comment: ""
criteria:
- key: domain
op: =
value: site-primary
- key: service
op: =
value: canton-participant.site-primary
name: nv.canton-participant.site-primary
original_name: ""
crooked-terabyte-91046
06/07/2023, 2:55 PMquiet-fountain-46593
06/07/2023, 3:00 PMkubectl get nvsecurityrules -n site-primary
and see if there are any other CRDs in there? I wonder if there is some conflict. what you have here looks to me like it should workcrooked-terabyte-91046
06/07/2023, 3:38 PMquiet-fountain-46593
06/07/2023, 4:05 PMcrooked-terabyte-91046
06/07/2023, 4:26 PMquiet-fountain-46593
06/07/2023, 4:26 PMkubectl get <http://nvclustersecurityrule.neuvector.com|nvclustersecurityrule.neuvector.com>
i think the one without the NV might be a non namespaced custom group. you cant set a mode on those, so it shouldn’t matter that it is therequiet-fountain-46593
06/07/2023, 4:26 PMquiet-fountain-46593
06/07/2023, 4:27 PMquiet-fountain-46593
06/07/2023, 4:40 PMcrooked-terabyte-91046
06/07/2023, 6:06 PMquiet-fountain-46593
06/07/2023, 10:00 PMquiet-fountain-46593
06/07/2023, 10:01 PMcrooked-terabyte-91046
06/08/2023, 12:50 PMquiet-fountain-46593
06/13/2023, 11:07 PMquiet-fountain-46593
06/14/2023, 5:34 PM