Conversation
✅ Deploy Preview for calico-docs-preview-next ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview succeeded!Built without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify project configuration. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Namespace-selector examples remain inconsistent, and label references omit supported global policy resources.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 10
Open (10)
Align Calico Cloud examples with the recommended namespace label · New Update EgressGatewayPolicy examples to use the recommended label · New Update EgressGatewayPolicy examples to use the recommended label · New Update EgressGatewayPolicy examples to use the recommended label · New Align Calico Enterprise examples with the recommended namespace label · New Update EgressGatewayPolicy examples to use the recommended label · New Update EgressGatewayPolicy examples to use the recommended label · New Update EgressGatewayPolicy examples to use the recommended label · New Align Calico examples with the recommended namespace label · New Update EgressGatewayPolicy examples to use the recommended label · New
What changed in this PR
This PR updates Calico, Calico Enterprise, and Calico Cloud documentation to recommend Kubernetes’ automatic namespace label while retaining the legacy label for compatibility and service-account selection.
Changes:
- Updates namespace selector examples.
- Revises label guidance and usage tables.
- Applies changes across egress gateway and policy documentation.
| File | Summary |
|---|---|
use-cases/egress-gateways.mdx |
Updated egress examples; some namespace selectors still use the legacy label. |
calico/network-policy/get-started/calico-policy/calico-labels.mdx |
Revised label guidance; global policy resources and other references need alignment. |
calico-enterprise/networking/egress/egress-gateway-on-prem.mdx |
Updated on-premises egress examples; legacy namespace selectors remain. |
calico-enterprise/networking/egress/egress-gateway-maintenance.mdx |
Updated maintenance documentation. |
calico-enterprise/networking/egress/egress-gateway-azure.mdx |
Updated Azure egress examples; legacy namespace selectors remain. |
calico-enterprise/networking/egress/egress-gateway-aws.mdx |
Updated AWS egress examples; legacy namespace selectors remain. |
calico-enterprise/network-policy/policy-best-practices.mdx |
Updated policy selector guidance. |
calico-enterprise/network-policy/beginners/calico-labels.mdx |
Revised label guidance; global policy resources and other references need alignment. |
calico-cloud/networking/egress/egress-gateway-on-prem.mdx |
Updated on-premises egress examples; legacy namespace selectors remain. |
calico-cloud/networking/egress/egress-gateway-maintenance.mdx |
Updated maintenance documentation. |
calico-cloud/networking/egress/egress-gateway-azure.mdx |
Updated Azure egress examples; legacy namespace selectors remain. |
calico-cloud/networking/egress/egress-gateway-aws.mdx |
Updated AWS egress examples; legacy namespace selectors remain. |
calico-cloud/network-policy/policy-best-practices.mdx |
Updated policy selector guidance. |
calico-cloud/network-policy/beginners/calico-labels.mdx |
Revised label guidance; global policy resources and other references need alignment. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Several namespace-selector examples and shared references still provide conflicting label guidance.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 13
Open (13)
Update preceding namespace annotation example · New Update preceding namespace annotation example · New Update preceding namespace annotation example · New Update EgressGatewayPolicy examples to use the recommended label Align Calico examples with the recommended namespace label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Align Calico Enterprise examples with the recommended namespace label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Align Calico Cloud examples with the recommended namespace label
kubernetes.io/metadata.name is set by Kubernetes on every namespace and is visible in kubectl output and in label pickers. projectcalico.org/name is not, so lead with the Kubernetes label for namespaceSelector. projectcalico.org/name stays documented. It is still valid for namespaces, and it is the only option for serviceAccountSelector, where Kubernetes has no equivalent automatic label. Updated Calico, Calico Enterprise, and Calico Cloud.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved conflicting namespace-selector examples remain across the documentation.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (2)
Resolved since last review (13)
Update preceding namespace annotation example Update preceding namespace annotation example Update preceding namespace annotation example Update EgressGatewayPolicy examples to use the recommended label Align Calico examples with the recommended namespace label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Align Calico Enterprise examples with the recommended namespace label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Update EgressGatewayPolicy examples to use the recommended label Align Calico Cloud examples with the recommended namespace label
| | ---------------------------------- | ------------------------------------------------------------ | --------------- | ------ | -------------- | | ||
| | `recStatus` | Defines the namespace policy recommendation engine status. | Enabled/Disabled | | Disabled | | ||
| | `selector` | Selects the namespaces for generating recommendations. Accepts any [label selector](#selectors) expression. | | | `!(projectcalico.org/name starts with ''tigera-'') && !(projectcalico.org/name starts with ''calico-'') && !(projectcalico.org/name starts with ''kube-'')` | | ||
| | `selector` | Selects the namespaces for generating recommendations. Accepts any [label selector](#selectors) expression. | | | `!(kubernetes.io/metadata.name starts with ''tigera-'') && !(kubernetes.io/metadata.name starts with ''calico-'') && !(kubernetes.io/metadata.name starts with ''kube-'')` | |
| name: deny-app-policy | ||
| spec: | ||
| namespaceSelector: has(projectcalico.org/name) && projectcalico.org/name not in {"kube-system", "calico-system", "tigera-system"} | ||
| namespaceSelector: has(kubernetes.io/metadata.name) && kubernetes.io/metadata.name not in {"kube-system", "calico-system", "tigera-system"} |


kubernetes.io/metadata.name is set by Kubernetes on every namespace and is visible in kubectl output and in label pickers. projectcalico.org/name is not, so lead with the Kubernetes label for namespaceSelector.
projectcalico.org/name stays documented. It is still valid for namespaces, and it is the only option for serviceAccountSelector, where Kubernetes has no equivalent automatic label.
Updated Calico, Calico Enterprise, and Calico Cloud.