Review network policy enforcement in GKE

Deploy required NetworkPolicies in GKE and verify that traffic restrictions take effect.

Description

Without enforced network policies, Pods can communicate more broadly than needed, making it easier for a compromised workload to reach other services. Both enforcement support and actual Kubernetes NetworkPolicy resources are required.

Potential impact

Unnecessary Pod communication gives an attacker more paths for lateral movement and access to sensitive services. Enabling the feature alone does not automatically block traffic.

Remediation

For Calico on Standard, configure network_policy.enabled: yes, provider: CALICO and addons_config.network_policy_config.disabled: no together. Deploy NetworkPolicies allowing required traffic and verify their effect. Autopilot and Dataplane V2 have built-in enforcement; focus on the policies rather than Calico settings there.

Examples

These excerpts configure Calico on a Standard cluster. Supply the project and JSON credential path. Enabling enforcement on an existing cluster recreates nodes, so plan maintenance and workload availability.

Before

yaml
- name: create a cluster2
  google.cloud.gcp_container_cluster:
    name: my-cluster2
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    network_policy:
      provider: CALICO
      enabled: yes

- name: create a cluster5
  google.cloud.gcp_container_cluster:
    name: my-cluster5
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    network_policy:
      provider: CALICO
      enabled: yes
    addons_config:
      network_policy_config:
        disabled: yes

The first task omits the add-on setting; the second disables it. Check both the Calico control-plane add-on and node enforcement settings.

After

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    network_policy:
      provider: CALICO
      enabled: yes
    addons_config:
      network_policy_config:
        disabled: no

Calico enforcement and the add-on are enabled together. Deploy separate NetworkPolicy resources to apply the intended traffic restrictions.

References