M2 · VPC-native networking
Policy
15 / 61

NetworkPolicy closes Kubernetes' default-open east-west network

Namespaces do not isolate traffic. Start each application namespace with default deny, then permit only named dependencies and DNS.

Default open

Without a selecting policy, Pods can communicate freely.

Default deny

Select every Pod and allow no ingress or egress.

Explicit allow

checkout may call payments on the required port only.

Keep DNS

Egress policy must preserve name resolution to the cluster DNS service.

Policy is additive: audit every policy selecting a Pod to know the effective allow set.