SECURITY / A CONCEPT NOTE
Network Policies
in-cluster firewall controls for isolating pod traffic
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Pod-level firewalls. By default, any application inside a cluster can freely talk to any other. Network policies let you define traffic isolation rules so that only designated components (like your frontend) are allowed to access sensitive databases.
02 / FOLLOW THE MECHANISM
How traffic blocking flows
Default state
all applications in the cluster communicate on a completely open network.
Lockdown policy
is applied to isolate database pods, dropping all unlisted incoming calls.
Approval rule
allows incoming connections only from pods carrying the 'role: backend' label.
Network agent
compiles this rule into kernel-level blocks (iptables or eBPF) on the host machine.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
list all active firewalls in the cluster
kubectl get netpol -Aview ingress/egress firewall rules
kubectl describe netpol database-isolation05 / CHECK YOURSELF
Could you explain Network Policies to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityAuthN vs AuthZwho you are vs what you may do