Skip to main content Skip to complementary content

Allowing general egress with internal restrictions for Dynamic Engine

Last updated: 9/23/2026
Replace the default internet-egress policy with a custom policy that allows broader outbound traffic while preserving internal restrictions.

About this task

Apply this procedure when you want broader outbound access than the default policy set but still need to keep some internal destinations restricted.

Procedure

  1. Disable the default internet-egress policy and enable the broader egress policy.
    cat <<EOF > custom-network-policies-values.yaml
    configuration:
      networkPolicies:
        enabled: true # Enable network policies
        policies:
    # Disable default policy allowing all egress traffic to the internet
          default-allow-egress-to-internet:
            enabled: false
          allow-general-egress-with-internal-restrictions:
            enabled: true
            spec:
              podSelector: {} # applied to all pods without any restrictions
              egress:
                - to:
                    - ipBlock:
                        cidr: 0.0.0.0/0 # allow egress traffic to any destinations
                        except:  #exclude specific desitnations
                          - xx.xxx.0.0/24 
                          - xxx.xxx.xxx.xxx/32
              policyTypes:
                - Egress
    EOF
    Replace the IP placehoders with actual addresses.
  2. Install or upgrade the charts with the general-egress policy file.
    helm upgrade --install dynamic-engine-$DYNAMIC_ENGINE_ID \
      -f $DYNAMIC_ENGINE_ID-values.yaml \
      -f custom-network-policies-values.yaml \
      oci://ghcr.io/talend/helm/dynamic-engine \
      --version $DYNAMIC_ENGINE_VERSION
    
    helm upgrade --install dynamic-engine-environment-$DYNAMIC_ENGINE_ENVIRONMENT_ID \
      -f $DYNAMIC_ENGINE_ENVIRONMENT_ID-values.yaml \
      -f custom-network-policies-values.yaml \
      oci://ghcr.io/talend/helm/dynamic-engine-environment \
      --version $DYNAMIC_ENGINE_VERSION
  3. Verify the broader policy set.

    Confirm that the default internet-egress policy is disabled and the general-egress policy is active in the engine and environment namespaces.

    kubectl get networkpolicies -A -l "app.qlik.com/owned-by=qlik"
    The default-allow-egress-to-internet policy should be gone, and the custom egress policy, allow-general-egress-with-internal-restrictions, should appear instead.

Did this page help you?

If you find any issues with this page or its content – a typo, a missing step, or a technical error – please let us know!