Kubernetes NetworkPolicy with Ingress and Egress
A NetworkPolicy with both policy types: an ingress rule combining namespace and pod selectors, and two egress rules, one of which uses an ipBlock with an except range. For testing policy engines that reason about allowed traffic.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: orders-restrict
namespace: example-apps
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: orders
policyTypes:
- Ingress
- Egress
ingress:
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: example-gateway
- podSelector:
matchLabels:
app.kubernetes.io/name: gateway
ports:
- protocol: TCP
port: 8080
egress:
- to:
- podSelector:
matchLabels:
app.kubernetes.io/name: ledger
ports:
- protocol: TCP
port: 5432
- to:
- ipBlock:
cidr: 10.20.0.0/16
except:
- 10.20.9.0/24
Specifications
- Kind
- NetworkPolicy
- Policy Types
- 2
- Ingress Rules
- 1
- Egress Rules
- 2
- Ip Block Exceptions
- 1
Testing contract
Expected to pass- Scenario
- Evaluate which traffic a NetworkPolicy admits, including an ipBlock with an exception range
- Expected result
- The egress ipBlock admits 10.20.0.0/16 while excluding 10.20.9.0/24, and the ingress rule resolves two separate peer selectors
What is a .yaml file?
YAML (YAML Ain't Markup Language) is a human-readable data-serialization format using indentation, key-value pairs, and lists, and is a superset of JSON. It supports comments, anchors, and multiple documents per file, favoring readability for configuration. Its indentation sensitivity makes it error-prone to hand-edit.
How to use this file
Use an example YAML file to test config parsers, indentation and anchor handling, multi-document streams, and safe-loading to avoid arbitrary object construction.
How to use this file for testing
“Kubernetes NetworkPolicy with Ingress and Egress” is a deterministic Novus Examples fixture for Config testing, Config parsing, Editor testing. TOML, INI, YAML, .env, and dotfile configuration samples with nested sections and typed values — for testing config parsers, loaders, and environment tooling.
Documented properties for this file: YAML · 798 bytes. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
Pipeline and infrastructure fixtures are inert configuration: steps reference fictional images and scripts, and nothing here executes. Run your linter, schema validator, migrator, or policy engine against them, and expect the deprecated-syntax and intentionally invalid variants to be rejected.
Point your config loader at the file and assert it reads the documented sections and typed values, including any deliberately-tricky nesting or comments.
Code examples
import yaml # pip install pyyaml
with open("networkpolicy.yaml") as f:
data = yaml.safe_load(f)
print(data)Related files
- yamlKubernetes CronJob Schedule and History LimitsA CronJob with an explicit timeZone, Forbid concurrency, a starting deadline, and history limits on both success and failure. For testing cron parsing and the scheduling fields policy engines most often check.

- yamlKubernetes HorizontalPodAutoscaler (autoscaling/v2)An autoscaling/v2 HPA with both a Resource and a Pods metric, plus scaleUp and scaleDown behaviour policies. The v2 metric shape differs sharply from v1 and v2beta, which is what makes it a useful conversion fixture.

- yamlKubernetes Kustomization OverlayA Kustomize overlay with a name prefix and suffix, common labels, an image tag override, a configMapGenerator merge, and a JSON-6902 patch embedded as a block scalar — YAML inside YAML, which naive rewriters mangle.

- yamlKubernetes Multi-Document Manifest BundleThree Kubernetes objects in one YAML stream, the shape kubectl apply consumes. A loader that calls the single-document API returns only the first object and silently drops the other two, which is exactly the failure this fixture is for.

- yamlKubernetes Namespace, ResourceQuota, and LimitRangeA three-document governance bundle. Its real edge case is quantity handling: values like "8", 16Gi and 250m are Kubernetes quantity strings, and a parser that coerces the quoted ones to numbers or normalises the suffixed ones changes their meaning.

- yamlKubernetes StatefulSet with Volume Claim TemplatesA StatefulSet with volumeClaimTemplates, an ordered pod-management policy, a partitioned rolling update, and a non-root pod security context. For testing manifest linters and admission policies that reason about storage and identity.

Generated by generation/pipelines.py. Free for any use, no attribution required — license.