Network Policies Print

  • 0

Restricting what can talk to what.

WHAT THE DEFAULT IS

Every pod can reach every other pod, across namespaces.

WHY THAT IS A PROBLEM

One compromised workload reaches everything, including databases.

WHAT A NETWORK POLICY DOES

Restricts traffic to and from selected pods.

WHAT IT SELECTS ON

Pod labels Namespace labels Address ranges

WHAT TO ESTABLISH FIRST

Whether your cluster's networking supports them.

WHY

Policies are silently ignored by some implementations.

HOW TO CHECK

Apply a deny-all policy in a test namespace and confirm traffic stops.

WHAT TO IMPLEMENT

Deny by default, then permit what is needed.

WHAT ORDER TO WORK IN

Start with the most sensitive workloads: databases and anything holding secrets.

WHAT TO PERMIT

Only the specific workloads that must reach them.

WHAT TO REMEMBER ABOUT DIRECTION

Ingress and egress are separate, and both may need rules.

WHAT PEOPLE FORGET

Allowing resolution traffic, which breaks everything when denied.

WHAT THE SYMPTOM IS

Pods unable to resolve any name.

WHAT TO TEST AFTER EVERY POLICY

That intended traffic still flows.

HOW

From inside a pod, attempting the connection.

WHAT TO DOCUMENT

What each policy permits, and why.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot