Restricting what can talk to what.
WHAT THE DEFAULT IS
Every pod can reach every other pod, across namespaces.
WHY THAT IS A PROBLEM
One compromised workload reaches everything, including databases.
WHAT A NETWORK POLICY DOES
Restricts traffic to and from selected pods.
WHAT IT SELECTS ON
Pod labels Namespace labels Address ranges
WHAT TO ESTABLISH FIRST
Whether your cluster's networking supports them.
WHY
Policies are silently ignored by some implementations.
HOW TO CHECK
Apply a deny-all policy in a test namespace and confirm traffic stops.
WHAT TO IMPLEMENT
Deny by default, then permit what is needed.
WHAT ORDER TO WORK IN
Start with the most sensitive workloads: databases and anything holding secrets.
WHAT TO PERMIT
Only the specific workloads that must reach them.
WHAT TO REMEMBER ABOUT DIRECTION
Ingress and egress are separate, and both may need rules.
WHAT PEOPLE FORGET
Allowing resolution traffic, which breaks everything when denied.
WHAT THE SYMPTOM IS
Pods unable to resolve any name.
WHAT TO TEST AFTER EVERY POLICY
That intended traffic still flows.
HOW
From inside a pod, attempting the connection.
WHAT TO DOCUMENT
What each policy permits, and why.