Review GKE Network Policy enforcement

Check how GKE enforces network policies and which workload connections are allowed.

Description

Network Policy helps restrict communication between pods and control the cluster network. Both an enforcement mechanism and actual NetworkPolicy rules are needed; enabling the feature alone does not automatically restrict traffic.

Network Policy is always enabled with GKE Dataplane V2. Check the cluster’s effective networking configuration rather than assuming an omitted setting means policies are not enforced.

Potential impact

  • Unnecessary pod-to-pod access can help a compromise spread to other workloads.
  • Incorrect policies can block legitimate service communication.

Remediation

  • Use the enforcement mechanism appropriate to the cluster and define NetworkPolicy rules for required service connections. Test essential traffic such as DNS.
  • Plan for node recreation and maintenance effects when enabling Calico on an existing Standard cluster. Do not apply the Calico configuration directly to a Dataplane V2 cluster.

Examples

Deployment Manager support has ended; use supported management tooling. These are partial GKE cluster request bodies, not complete deployment templates. The after example is for a Standard cluster using Calico. Node configuration and actual NetworkPolicy rules are omitted.

Before

yaml
name: cluster
description: my-cluster

After

yaml
name: cluster
description: my-cluster
networkPolicy:
  enabled: true
  provider: CALICO
addonsConfig:
  networkPolicyConfig:
    disabled: false

Explanation:

  • Before: Policy settings are omitted. Check the effective enforcement mechanism and existing rules.
  • After: Calico policy enforcement is requested. Separate NetworkPolicy rules are required to restrict communication.

References