Kubernetes NetworkPolicy controls Pod to Pod; security groups for pods control Pod to AWS resources.
They work at different layers and are used together.
Security groups for pods
A SecurityGroupPolicy attaches an AWS security group to matching Pods using trunk ENIs. An RDS rule can then allow only that group instead of every Pod on the node.
NetworkPolicy on EKS
The VPC CNI can enforce Kubernetes NetworkPolicy itself (enable it on the add-on), or use Calico or Cilium. Default-deny plus explicit allows, as in Deck 1.
kind: SecurityGroupPolicy spec: podSelector: {matchLabels: {role: db-client}} securityGroups: {groupIds: [sg-0123456789abcdef0]}
Limits
Needs supported instance types and has no support on Fargate-style isolation in the same way. Check the docs before designing around it.