Networking
NetworkPolicy
60 / 82

By default every Pod can talk to every Pod; isolation is opt-in.

Once any policy selects a Pod, that Pod accepts only what policies allow. Start with default deny and add explicit allows.

namespace shopcheckoutpaymentspostgresXXdefault-deny-all: nothing allowedallow-checkout-to-db: egress to postgres TCP 5432plus egress to CoreDNS on port 53
default deny, then allow
kind: NetworkPolicy
metadata: {name: default-deny-all, namespace: shop}
spec:
  podSelector: {}              # ALL Pods here
  policyTypes: [Ingress, Egress]  # no rules = deny

AND versus OR

namespaceSelector and podSelector in one list item are ANDed; in two items they are ORed. One dash decides.

Policies only add

Allows are the union of every policy selecting a Pod. One permissive policy undoes a strict baseline.

Needs a capable CNI

Calico, Cilium and GKE Dataplane V2 enforce policies. A CNI without enforcement ignores them silently.