SECURITY / A CONCEPT NOTE

Network Policies

in-cluster firewall controls for isolating pod traffic

~70 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Pod-level firewalls. By default, any application inside a cluster can freely talk to any other. Network policies let you define traffic isolation rules so that only designated components (like your frontend) are allowed to access sensitive databases.

02 / FOLLOW THE MECHANISM

How traffic blocking flows

  1. Default state

    all applications in the cluster communicate on a completely open network.

  2. Lockdown policy

    is applied to isolate database pods, dropping all unlisted incoming calls.

  3. Approval rule

    allows incoming connections only from pods carrying the 'role: backend' label.

  4. Network agent

    compiles this rule into kernel-level blocks (iptables or eBPF) on the host machine.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

list all active firewalls in the cluster

kubectl get netpol -A

EXAMPLE 02 · REFERENCE

view ingress/egress firewall rules

kubectl describe netpol database-isolation

Explore command anatomy in the CLI lab