Networking
Pod isolation
26 / 69

Kubernetes NetworkPolicy controls Pod to Pod; security groups for pods control Pod to AWS resources.

They work at different layers and are used together.

node (shared)db-client Podown security group sg-db-clientsweb Podnode security group onlyRDS databaseallows sg-db-clients onlyblocked

Security groups for pods

A SecurityGroupPolicy attaches an AWS security group to matching Pods using trunk ENIs. An RDS rule can then allow only that group instead of every Pod on the node.

NetworkPolicy on EKS

The VPC CNI can enforce Kubernetes NetworkPolicy itself (enable it on the add-on), or use Calico or Cilium. Default-deny plus explicit allows, as in Deck 1.

kind: SecurityGroupPolicy
spec:
  podSelector: {matchLabels: {role: db-client}}
  securityGroups: {groupIds: [sg-0123456789abcdef0]}

Limits

Needs supported instance types and has no support on Fargate-style isolation in the same way. Check the docs before designing around it.