Description
Network Policy helps restrict communication between pods and control the cluster network. Both an enforcement mechanism and actual NetworkPolicy rules are needed; enabling the feature alone does not automatically restrict traffic.
Network Policy is always enabled with GKE Dataplane V2. Check the cluster’s effective networking configuration rather than assuming an omitted setting means policies are not enforced.
Potential impact
- Unnecessary pod-to-pod access can help a compromise spread to other workloads.
- Incorrect policies can block legitimate service communication.
Remediation
- Use the enforcement mechanism appropriate to the cluster and define NetworkPolicy rules for required service connections. Test essential traffic such as DNS.
- Plan for node recreation and maintenance effects when enabling Calico on an existing Standard cluster. Do not apply the Calico configuration directly to a Dataplane V2 cluster.
Examples
Deployment Manager support has ended; use supported management tooling. These are partial GKE cluster request bodies, not complete deployment templates. The after example is for a Standard cluster using Calico. Node configuration and actual NetworkPolicy rules are omitted.
Before
name: cluster
description: my-cluster
After
name: cluster
description: my-cluster
networkPolicy:
enabled: true
provider: CALICO
addonsConfig:
networkPolicyConfig:
disabled: false
Explanation:
- Before: Policy settings are omitted. Check the effective enforcement mechanism and existing rules.
- After: Calico policy enforcement is requested. Separate NetworkPolicy rules are required to restrict communication.