🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 3 Min Lesezeit
0

Network Policy in Kubernetes: A Comprehensive Guide for DevOps

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht




Introduction



Network Policies are Kubernetes resources that control pod-to-pod communication within a cluster. They act as a firewall, enabling fine-grained control over how pods communicate with each other and external endpoints.






Key Concepts






Pod Selection



Network policies use labels to select pods and define rules. Two key selectors:




  • podSelector: Defines which pods the policy applies to

  • namespaceSelector: Filters pods based on their namespace






Policy Types




  • Ingress: Controls incoming traffic

  • Egress: Controls outgoing traffic






Default Behavior



By default, pods accept traffic from any source. Once a Network Policy selects a pod, it denies all traffic not explicitly allowed by that policy.






Common Network Policy Patterns






1. Deny All Traffic






CODE
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny
namespace: prod
spec:
podSelector: {}
policyTypes:
- Ingress
- Egress









2. Allow Traffic from Specific Namespace






CODE
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-from-dev
namespace: prod
spec:
podSelector:
matchLabels:
app: web
policyTypes:
- Ingress
ingress:
- from:
- namespaceSelector:
matchLabels:
environment: dev









3. Allow Specific Port Access






CODE
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-api-access
spec:
podSelector:
matchLabels:
app: api
policyTypes:
- Ingress
ingress:
- ports:
- protocol: TCP
port: 8080
from:
- podSelector:
matchLabels:
role: frontend









4. Allow External Traffic






CODE
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-external-traffic
spec:
podSelector:
matchLabels:
app: web
policyTypes:
- Ingress
ingress:
- from:
- ipBlock:
cidr: 172.17.0.0/16
except:
- 172.17.1.0/24









Best Practices






1. Isolation Strategy




  • Start with deny-all policies

  • Gradually add allow rules based on requirements

  • Use namespaces for logical grouping

  • Label pods consistently






2. Security Considerations




  • Implement least privilege access

  • Regular audit of network policies

  • Document policy intentions

  • Use network policy logs for troubleshooting






3. Performance Impact




  • Minimize complex selectors

  • Use efficient CIDR blocks

  • Regular monitoring of network policy performance

  • Consider CNI plugin capabilities






Troubleshooting Guide






Common Issues





  1. Policy Not Applied




    • Verify CNI plugin supports Network Policies

    • Check label selectors match intended pods

    • Confirm policy is in correct namespace




  2. Unexpected Blocking




    • Review all policies affecting the pod

    • Check for conflicting rules

    • Verify namespace labels

    • Test with temporary allow-all policy








Debugging Commands






CODE
# List all network policies
kubectl get networkpolicy --all-namespaces

# Describe specific policy
kubectl describe networkpolicy <policy-name> -n <namespace>

# Check pod labels
kubectl get pods --show-labels

# Verify pod connectivity
kubectl exec -it <pod-name> -- wget -qO- http://<service-name>









Advanced Configurations






1. Combining Multiple Rules






CODE
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: complex-policy
spec:
podSelector:
matchLabels:
app: web
policyTypes:
- Ingress
- Egress
ingress:
- from:
- namespaceSelector:
matchLabels:
environment: prod
- podSelector:
matchLabels:
role: frontend
ports:
- protocol: TCP
port: 80
egress:
- to:
- namespaceSelector:
matchLabels:
environment: prod
ports:
- protocol: TCP
port: 5432









2. Using Multiple Port Ranges






CODE
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: multi-port-policy
spec:
podSelector:
matchLabels:
app: service
policyTypes:
- Ingress
ingress:
- ports:
- protocol: TCP
port: 80
- protocol: TCP
port: 443
- protocol: UDP
port: 53









Monitoring and Compliance






Tools and Metrics




  • Network Policy Advisor

  • Calico Network Policy Logs

  • Prometheus metrics for policy evaluation

  • Regular compliance audits






Best Practices for Production




  1. Version control all network policies

  2. Implement change management process

  3. Regular security reviews

  4. Automated policy testing

  5. Documentation of policy intentions






Conclusion



Network Policies are essential for securing Kubernetes clusters. Proper implementation requires understanding of pod networking, careful planning, and regular maintenance. Start with basic policies and gradually implement more complex rules based on security requirements.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Network Policy in Kubernetes: A Comprehensive Guide for DevOps

Thematisch verwandte Begriffe: Network, Policy, Kubernetes, Comprehensive · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...