By default every Pod can talk to every Pod; isolation is opt-in.
Once any policy selects a Pod, that Pod accepts only what policies allow. Start with default deny and add explicit allows.
default deny, then allow
kind: NetworkPolicy metadata: {name: default-deny-all, namespace: shop} spec: podSelector: {} # ALL Pods here policyTypes: [Ingress, Egress] # no rules = deny
AND versus OR
namespaceSelector and podSelector in one list item are ANDed; in two items they are ORed. One dash decides.
Policies only add
Allows are the union of every policy selecting a Pod. One permissive policy undoes a strict baseline.
Needs a capable CNI
Calico, Cilium and GKE Dataplane V2 enforce policies. A CNI without enforcement ignores them silently.