Kubernetes NetworkPolicy
Kubernetes NetworkPolicy
Beginner
Q1: What is a Kubernetes NetworkPolicy?
A NetworkPolicy is a Kubernetes resource that controls how Pods can communicate with each other and with network endpoints.
Q2: Why do we need NetworkPolicies?
They provide network-level isolation and enforce who can talk to whom inside the cluster.
Q3: What is network segmentation?
Network segmentation divides network traffic into trust zones or boundaries to reduce lateral movement.
Q4: Why is segmentation important?
It helps restrict blast radius if a workload is compromised.
Q5: What is a Pod policy?
A Pod policy defines network traffic rules for a set of Pods.
Q6: What are ingress rules?
Ingress rules define which connections are allowed into a Pod.
Q7: What are egress rules?
Egress rules define which connections a Pod is allowed to initiate outbound.
Q8: What is default-deny?
Default-deny means no traffic is allowed unless a specific policy allows it.
Q9: Why is default-deny a common secure posture?
It reduces accidental or malicious network access to a workload.
Q10: What does NetworkPolicy apply to?
A NetworkPolicy applies to Pods selected by labels and optional namespace selectors.
Q11: What is a `podSelector`?
A `podSelector` selects the Pods that the policy applies to.
Q12: What is a `policyTypes` field?
It defines whether the policy applies to ingress, egress, or both.
Q13: What is an ingress rule?
An ingress rule allows incoming connections to matching Pods.
Q14: What is an egress rule?
An egress rule allows outgoing connections from matching Pods.
Q15: What are `from` rules?
`from` rules specify who may connect to the selected Pods in ingress policies.
Q16: What are `to` rules?
`to` rules specify what destinations are allowed for egress traffic.
Q17: What is a namespace selector?
A namespace selector matches Pods in specific namespaces.
Q18: What is a pod selector in a network policy?
A pod selector can select specific workloads in the same or other namespaces.
Q19: What is an IPBlock?
An IPBlock allows or denies traffic to and from specific CIDR ranges.
Q20: What is a CIDR?
A CIDR is a network range such as 10.0.0.0/8 or 192.168.1.0/24.
Q21: Why use IPBlock?
It allows policies to permit or deny traffic to known external networks or internal ranges.
Q22: What is a namespace + pod selector combination?
It selects Pods in specific namespaces that match labels, useful for multi-tenant policies.
Q23: Why are NetworkPolicies namespaced?
A NetworkPolicy is created in a namespace and applies only to Pods in that namespace unless cross-namespace selectors are used.
Q24: What is a Pod not selected by any policy?
If no policies apply, the default pod network behavior depends on the cluster CNI and default policy settings.
Q25: What is the default network behavior without NetworkPolicies?
Many clusters allow unrestricted pod-to-pod communication unless a CNI or security policy restricts it.
Q26: What is a CNI?
CNI (Container Network Interface) is the network plugin standard for Kubernetes networking.
Q27: Why does CNI matter for NetworkPolicies?
Because NetworkPolicy support depends on the CNI plugin implementing the policy enforcement.
Q28: What is a network plugin with NetworkPolicy support?
Examples include Calico, Cilium, Antrea, and others.
Q29: What is an ingress allowlist?
An ingress allowlist is a set of allowed sources for incoming traffic to a service or pod.
Q30: What is an egress allowlist?
An egress allowlist is a set of allowed destinations for outbound traffic.
Q31: What is a default allow policy?
A default allow policy allows traffic unless specifically denied by other rules.
Q32: Why is default allow often discouraged?
Because it exposes workloads to more network access than needed.
Q33: What is pod-to-pod communication?
Traffic between different Pods in the same or different namespaces.
Q34: Why do security teams care about pod-to-pod communication?
Because compromised workloads can otherwise talk to many other workloads.
Q35: What is cluster egress?
Traffic leaving the cluster to external systems or services.
Q36: Why restrict cluster egress?
Because it helps prevent data exfiltration or communication with malicious endpoints.
Q37: What is cluster ingress?
Traffic entering the cluster from outside or from another namespace.
Q38: Why restrict ingress?
Because the same principle applies: reduce the attack surface and lateral movement.
Q39: What is a network policy match label?
A label is used to group Pods and match them to a NetworkPolicy.
Q40: What is a `namespaceSelector` match?
It selects Pods or namespaces by label rather than by exact namespace name.
Q41: What is a `podSelector` match in the same namespace?
It selects pods in the same namespace as the policy.
Q42: What is a `podSelector` match in a different namespace?
It can select Pods from other namespaces using a namespace selector and pod selector combination.
Q43: What is a `ports` list in NetworkPolicy?
It lists the destination ports allowed by an ingress or egress rule.
Q44: Why list ports explicitly?
Because policies should permit only the required ports and protocols.
Q45: What is protocol in a NetworkPolicy?
It is usually TCP, UDP, or SCTP.
Q46: Why are protocols important?
Because a policy may allow HTTP on TCP but not UDP on the same port.
Q47: Why might a workload need both ingress and egress policies?
Because some apps must accept inbound traffic and also initiate outbound connections to dependencies.
Q48: What is a database policy?
A database policy may allow only the application tier to reach the database port.
Q49: What is an application tier policy?
It may allow inbound traffic only from the frontend or API tier.
Q50: What is an ingress from a namespace?
A policy may allow ingress from pods in a specific namespace.
Q51: What is egress to a DNS service?
Pods often need egress to DNS services on UDP/TCP port 53 for name resolution.
Q52: Why allow DNS in egress policies?
Without DNS, pods may not resolve service names or external hostnames.
Q53: Why do network policies often include DNS exceptions?
Because many workloads still need to resolve names but should not contact arbitrary external endpoints.
Q54: What is a `service` port and a network policy port?
The port in a policy is typically a destination port on the target pod or destination address.
Q55: Why is policy portability important?
Because the same app should behave consistently across dev, test, and prod.
Q56: What is a namespace boundary for network policy?
A namespace is a security boundary for policies, even when the network plugin supports cross-namespace rules.
Q57: What is a selected Pod?
A selected Pod is one that matches the policy selectors.
Q58: Why is label design critical for policies?
Because labels are how policies select Pods and groups.
Q59: What is a label pattern for service tiers?
Examples: `app: frontend`, `app: api`, `db: postgres`.
Q60: What is a `NetworkPolicy` YAML object?
It has metadata, spec, podSelector, policyTypes, ingress, and egress.
Q61: What is a Kubernetes network plugin model?
The plugin implements enforcement of NetworkPolicies and low-level networking.
Q62: Why are some policies ignored if the CNI lacks support?
NetworkPolicy enforcement depends on the CNI plugin and cluster configuration.
Q63: Why should network policies be reviewed with the cluster architecture?
Because some features require special CNI or network settings.
Q64: What is a cluster-managed firewall?
It is the network policy system enforced by the CNI plugin.
Q65: What is an inbound deny by default?
No traffic enters the pod unless allowed.
Q66: What is an outbound deny by default?
No traffic leaves the pod unless allowed.
Q67: Why do not all policies deny by default?
Because some workloads need to talk to public APIs or dependencies.
Q68: Why is it easier to reason about policies when selectors are explicit?
Because every allowed path is tied to specific labels or CIDR ranges.
Q69: What is a network policy for a database?
It may permit ingress only from app pods on database port 5432.
Q70: What is a network policy for a web server?
It may allow ingress from the ingress controller or load balancer on HTTP/HTTPS ports.
Q71: What is a network policy for a worker job?
It may allow egress to a queue or database while restricting inbound traffic.
Q72: Why is network policy a control for lateral movement?
Because compromised workloads cannot easily reach or use other workloads.
Q73: What is a security boundary in Kubernetes?
It is a boundary such as namespace, pod group, or trust zone used to isolate workloads.
Q74: Why is namespace-based isolation useful?
It separates workloads, teams, or environments and makes policy simpler.
Q75: What is `policyTypes: [Ingress]`?
It means the policy only applies to ingress traffic.
Q76: What is `policyTypes: [Egress]`?
It means the policy only applies to egress traffic.
Q77: What is `policyTypes: [Ingress, Egress]`?
It applies both ingress and egress rules.
Q78: Why should egress policies be used carefully?
Because apps may require outbound calls to databases, APIs, or DNS.
Q79: What is a egress network policy for DNS?
Usually allow UDP/TCP 53 to the cluster DNS service or upstream DNS resolvers.
Q80: What is an ingress network policy for a load balancer?
It allows traffic from the load balancer or ingress controller only on relevant ports.
Q81: What is a namespace label used in policies?
It selects namespaces by labels such as `team: payments` or `environment: prod`.
Q82: Why are namespace labels useful in policy design?
They allow team- or environment-specific traffic rules.
Q83: What is a multi-tenant cluster?
A cluster where multiple teams or workloads share the same infrastructure but require isolation.
Q84: Why are network policies common in multi-tenant clusters?
Because they provide strong isolation between teams and workloads.
Q85: What is a service mesh vs NetworkPolicy?
A service mesh handles L7 routing and security, while NetworkPolicy works at L3/L4 network enforcement.
Q86: What is a cluster-level network policy default?
It may be implemented for all workloads in a namespace or across namespaces.
Q87: Why monitor network policy behavior in troubleshooting?
Because policy violations may show as connection resets or timeouts without obvious application errors.
Q88: Why does debugging network policy require pod labels and selectors?
Because the policy is based on labels, namespace selectors, and IP rules.
Q89: What is a policy mismatch?
It happens when a pod is selected incorrectly or a label is not matching the expected pattern.
Q90: Why do network policies often need coordination with ingress controllers?
Because ingress controllers need to be allowed to reach the service ports.
Q91: What is an ingress controller source?
It is usually the ingress controller pod or service IPs or a CIDR range.
Q92: Why is egress to database important?
Application pods need to reach their database service, often on a specific port.
Q93: Why might a policy block a startup dependency?
If a pod depends on a database or external API and the policy is too restrictive.
Q94: Why are policies usually tested in staging before production?
Because connectivity mistakes can create outages or unexpected service breakage.
Q95: Why is performance not the main concern in NetworkPolicies?
Security and traffic control are primary; performance is secondary but still matters.
Q96: What is a network policy path to an external service?
It may allow egress to a specific external IP or CIDR and port.
Q97: What is a DNS or metadata endpoint egress rule?
Some systems need egress to cloud metadata endpoints or internal DNS services.
Q98: What is a port 443 outbound API call?
A policy may allow HTTPS to certain endpoints while blocking all others.
Q99: Why allow only necessary ports?
It reduces the number of possible attack paths from a workload.
Q100: What is a `podSelector` and a namespace selector combination used for?
To allow traffic only from selected pods in specific namespaces.
Intermediate
Q101: What is a network policy precedence?
Kubernetes evaluates policies based on matching pods and the selected rules; traffic allowed must match at least one allowed policy.
Q102: What is implied deny?
If no matching ingress or egress policy allows traffic, the traffic is denied.
Q103: Why is a default deny policy easiest to reason about?
Because it creates a clean list of allowed communications.
Q104: What is a `deny` rule in NetworkPolicy?
Kubernetes does not have a direct deny rule object; instead, you define allow rules and default deny by omission.
Q105: What is zero-trust network design?
It assumes no workload is trusted by default and restricts communication tightly.
Q106: Why is zero-trust relevant in Kubernetes?
Because container-to-container communication often occurs within the same cluster with no natural trust boundary.
Q107: What is an anti-affinity pattern in network policy?
It uses specific selectors and policies to ensure workloads do not talk to each other when they should not.
Q108: What is a pod-to-pod trust boundary?
It is a logical boundary such as app tier, data tier, or external exposure layer.
Q109: Why should database tier not accept all inbound traffic?
Because only application services should reach the database on its proper port.
Q110: What is a frontend/backend isolation pattern?
It restricts frontend ingress to public traffic but blocks backend communication except from allowed APIs.
Q111: Why is the ingress controller allowed through policies?
Because it handles external traffic into application services.
Q112: What is a service-to-service isolation pattern?
It isolates different service groups to reduce lateral movement.
Q113: What is a queue consumer policy?
A worker or consumer may only egress to the queue, database, and DNS while denying all else.
Q114: What is a DNS egress exception?
It allows DNS lookup to cluster or upstream resolvers while restricting other egress.
Q115: What is TLS and NetworkPolicy interaction?
A NetworkPolicy does not inspect HTTPS payload; it only controls traffic paths and ports.
Q116: Why does NetworkPolicy not replace app security?
Because an app still needs to validate inputs, APIs, and access control.
Q117: What is a port 80 and 443 service policy?
A frontend might allow ingress from the world to HTTP/HTTPS but not to internal management ports.
Q118: Why is it better to keep management ports private?
Because management or admin ports should not be publicly reachable.
Q119: What is `namespaceSelector` and `podSelector` cross-namespace policy?
It allows a Pod in namespace A to allow traffic from selected Pods in namespace B.
Q120: Why is cross-namespace policy useful?
For shared services or multi-team architectures that need controlled communication.
Q121: What is a policy for external monitoring?
Monitoring daemons may need egress to metrics systems or collecting endpoints while all other egress is denied.
Q122: Why does traffic selection depend on labels?
Labels are the stable identity used by selectors in policy rules.
Q123: What is a pod label mismatch issue?
It occurs when labels do not match the intended policy and the Pod ends up with blocked or missing traffic.
Q124: What is a debug command for policies?
It often involves checking the pod labels, the NetworkPolicy manifest, and the CNI plugin logs.
Q125: Why do policy debug issues sometimes look like app failures?
Because the app may be unreachable or unable to talk to dependencies even though the workload is running.
Q126: What is a cluster CNI log?
It can show policy evaluation, packet drops, or agent decisions.
Q127: Why do some CNI plugins implement egress and ingress differently?
Because the plugin-specific data plane has different support and semantics.
Q128: What is application traffic timing and NetworkPolicy?
Policy checks happen in the data plane, so configuration changes may take effect after a short delay.
Q129: What is an ingress rule with `ipBlock`?
It can explicitly allow traffic from a CIDR while denying everything else.
Q130: Why use `ipBlock` for external dependencies?
Because the service may be a specific internal or vendor network range.
Q131: What is traffic allowed by default when no policies exist?
This depends on the CNI plugin and cluster setup.
Q132: Why is default behavior before policy often not enough for security?
Because it does not enforce least privilege or allowlist communication.
Q133: What is a “deny all by default” posture?
It is the set of policies that only allows explicitly permitted traffic paths.
Q134: Why is explicit allow-listing better than broad access?
It reduces misconfiguration and prevents unvetted access.
Q135: What is a service dependency policy?
It restricts which workloads can reach a service, like only the API tier to the database.
Q136: What is a health check policy?
Some CNI or load balancers need allowed ingress for health probes or liveness checks.
Q137: Why should health probes be considered in policy design?
Because if the health check port is blocked, the workload may appear unhealthy or unready.
Q138: What is the relation between NetworkPolicy and Service ports?
Policies usually allow traffic to Service ports and Pod ports, which are often the same or mapped.
Q139: What is a pod port requirement?
The policy’s `ports` field should reflect the application’s listening port.
Q140: Why use port restrictions?
Because allowing all ports would expose unnecessary application functionality.
Q141: What is a malicious lateral movement path?
It is an unintended path between compromised and valuable workloads.
Q142: Why is namespace policy important for team isolation?
Because it prevents teams from inadvertently reaching each other’s services in a shared cluster.
Q143: What is a multi-namespace policy?
It allows one namespace’s workloads to communicate with selected workloads in another namespace.
Q144: Why is egress restriction sometimes the source of application failures?
Because a workload may need to talk to a database, a cloud service, or a queue.
Q145: Why should policies be tested at runtime?
Because policy can block traffic even when an app appears to start correctly.
Q146: Why is logging and monitoring needed with policies?
To identify dropped connections or unreachable dependencies.
Q147: What is `kubectl describe networkpolicy`?
It displays the details and intent of NetworkPolicies in the cluster.
Q148: Why is `kubectl get networkpolicy` useful?
It helps validate the actual policy set applied to a namespace.
Q149: What is a pod service account and network policy relation?
Service accounts are identity-level controls, while NetworkPolicies control network reachability.
Q150: Why is a zero-trust posture a good default for Kubernetes?
Because it requires explicit traffic decisions rather than assuming trust.
Q151: What is a default deny plus explicit allow pattern?
It is a security approach where only permitted traffic is allowed.
Q152: Why use explicit allow-lists for DBs and queues?
Because they are mission-critical and should be reachable only by expected workloads.
Q153: What is a worker egress restriction?
A worker may only egress to the queue and internal APIs while everything else is blocked.
Q154: Why are CNI plugins so important for NetworkPolicies?
The plugin is the actual enforcement point, and different plugins may behave differently.
Q155: Why do some policies appear not to apply?
Because the workload might not be selected by the policy, or the CNI may not support the feature.
Q156: What is a policy-limited external dependency?
A pod may have explicit rules to permit egress to a specific CIDR or DNS endpoint.
Q157: Why should egress policies consider DNS resolution?
Because DNS is required for service discovery and name-based access.
Q158: What is introspection of dropped connections?
It often uses logs, packet analysis, or CNI diagnostic outputs to find traffic that is being denied.
Q159: What is a network policy for cronjobs?
A cron job may need outbound access to a database or external API but does not need inbound traffic.
Q160: What is a network policy for sidecars?
Sidecars may need specific traffic rules based on whether they serve metrics, proxy traffic, or act as a security agent.
Q161: Why is network policy design often part of platform hardening?
Because it reduces the risk of attack paths within a cluster.
Q162: What is an identity and network boundary?
An identity is the workload or user; a network boundary restricts traffic between identities.
Q163: Why is cluster CNI support a prerequisite?
Without support, network policies cannot be enforced.
Q164: What is control plane vs data plane in NetworkPolicy?
The control plane manages policy objects; the data plane enforces packet filtering.
Q165: Why is policy enforcement at the data plane important?
Because it stops traffic as it moves between pods rather than only at the app layer.
Q166: Why do teams often start with default-deny in dev/test?
It uncovers app dependencies early and avoids hidden network assumptions.
Q167: Why is policy allowlist generation important?
Because it ensures all required communication paths are explicitly accounted for.
Q168: What is a pod port for metrics scraping?
Monitoring or metrics systems often need a policy exception to reach metrics endpoints.
Q169: Why allow only required ports to monitoring systems?
Because metrics endpoints are often not security-sensitive, but they still should be controlled.
Q170: Why should internal service traffic be explicit?
Because internal service names and ports can otherwise be used in unexpected ways.
Q171: What is a Pod traffic map?
It is a diagram or inventory of which pods can talk to which workloads.
Q172: Why is traffic mapping useful for policy design?
Because it makes security design easier to reason about.
Q173: What is a network policy for a queue consumer?
It could allow ingress from the queue service and egress to the database and internal APIs.
Q174: What is a network policy for a service mesh sidecar?
It may allow inbound traffic from the mesh and outbound to backend services.
Q175: What is a network policy for a logging agent?
It may allow egress to logging endpoints while denying inbound access.
Q176: What is the typical pattern for web applications?
Allow ingress from ingress controllers or external ranges, egress to dependencies and DNS, deny all else.
Q177: What is a policy design challenge?
It must be strict enough for security but flexible enough for the app to function.
Q178: What is a liveness and readiness check effect on policy?
If probes or monitoring systems are blocked, the service may appear unhealthy or fail health checks.
Q179: Why is K8s network policy considered a control plane and data plane element?
Because the policy exists in Kubernetes but is enforced in the network data plane by the CNI.
Q180: What is the core lesson of NetworkPolicy?
NetworkPolicy is the Kubernetes mechanism for network isolation: it defines allowed ingress and egress paths so workloads can communicate only on explicitly permitted paths.
Advanced / Expert
Q181: What is packet filtering in the CNI?
The CNI plugin filters packets based on source/destination labels, namespaces, and ports.
Q182: What is L3/L4 enforcement in NetworkPolicy?
It enforces at the IP and port layer, not application content layer.
Q183: Why is L3/L4 not enough for all security?
Because it does not inspect HTTP paths, bodies, or application-level semantics.
Q184: What is a service mesh for L7 policy?
A service mesh provides L7-aware routing, authorization, and observability.
Q185: Why use both NetworkPolicy and service mesh?
Because NetworkPolicy controls pod-to-pod network reachability while service mesh can control HTTP semantics and mTLS.
Q186: What is mTLS and NetworkPolicy interaction?
mTLS secures service-to-service traffic; NetworkPolicy restricts which endpoints can talk to each other.
Q187: What is policy enforcement drift?
It happens when policy rules no longer match the actual network design or workload labels.
Q188: Why do labels matter for policy stability?
Because if labels change, the policy may inadvertently select or stop selecting workloads.
Q189: What is policy-based segmentation?
It is the use of NetworkPolicies to define boundaries and controls between workloads.
Q190: Why is policy at the cluster boundary important?
Because it reduces cross-namespace blast radius and helps maintain multi-tenant isolation.
Q191: What is cross-namespace policy design?
It allows controlled communication between namespaces without fully open traffic.
Q192: Why are cross-namespace policies security-sensitive?
Because they intentionally allow traffic across namespace boundaries and should be reviewed carefully.
Q193: What is egress to internet or external services?
It requires explicit IPBlock or external endpoint policy, often with DNS exceptions.
Q194: What is the challenge of restricting internet egress?
Because many workloads legitimately need outbound access to external APIs or package managers.
Q195: What is a restricted egress model?
It allows only specific destinations and protocols and blocks all others.
Q196: Why do some clusters restrict egress by default?
To prevent compromised workloads from contacting command-and-control endpoints or exfiltrating data.
Q197: What is a trusted subnet?
A trusted subnet is a CIDR range allowed for internal service access.
Q198: Why is IPBlock used for trusted subnet policies?
Because internal networks or service ranges are often more trusted and can be explicitly allowed.
Q199: Why are NetworkPolicies often paired with kube-proxy or CNI observability?
Because they help diagnose whether traffic is being dropped or allowed unexpectedly.
Q200: What is the ultimate point of NetworkPolicy?
It is Kubernetes’ way to control the network trust boundaries between workloads, enforcing least privilege and reducing lateral movement risk inside the cluster.