Description
Without enforced network policies, Pods can communicate more broadly than needed, making it easier for a compromised workload to reach other services. Both enforcement support and actual Kubernetes NetworkPolicy resources are required.
Potential impact
Unnecessary Pod communication gives an attacker more paths for lateral movement and access to sensitive services. Enabling the feature alone does not automatically block traffic.
Remediation
For Calico on Standard, configure network_policy.enabled: yes, provider: CALICO and addons_config.network_policy_config.disabled: no together. Deploy NetworkPolicies allowing required traffic and verify their effect. Autopilot and Dataplane V2 have built-in enforcement; focus on the policies rather than Calico settings there.
Examples
These excerpts configure Calico on a Standard cluster. Supply the project and JSON credential path. Enabling enforcement on an existing cluster recreates nodes, so plan maintenance and workload availability.
Before
- name: create a cluster2
google.cloud.gcp_container_cluster:
name: my-cluster2
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
network_policy:
provider: CALICO
enabled: yes
- name: create a cluster5
google.cloud.gcp_container_cluster:
name: my-cluster5
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
network_policy:
provider: CALICO
enabled: yes
addons_config:
network_policy_config:
disabled: yes
The first task omits the add-on setting; the second disables it. Check both the Calico control-plane add-on and node enforcement settings.
After
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
network_policy:
provider: CALICO
enabled: yes
addons_config:
network_policy_config:
disabled: no
Calico enforcement and the add-on are enabled together. Deploy separate NetworkPolicy resources to apply the intended traffic restrictions.