Description
A NetworkPolicy does not apply to a Pod if it is in a different namespace or its podSelector does not select that Pod. A workload may therefore remain exposed despite appearing to have network protection.
Check the actual namespace, labels and selected Pods rather than only the presence of a policy. Enforcement requires a network plugin that supports NetworkPolicy, and the traffic allowed by multiple policies is combined.
Potential impact
- Pod-to-Pod or external communication may be broader than intended.
- Internal services may remain unprotected.
- Declared policies may not provide the expected network isolation.
Remediation
- Place the NetworkPolicy in the same namespace as the Pods it protects.
- Verify that
podSelectormatches the actual Pod labels. - Test that traffic restrictions are enforced after applying the policy.
Examples
Prepare the namespaces and application images separately. The old nginx version in the example is not a deployment recommendation.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: sample-pod
namespace: app-one
labels:
app: shouldmatch
spec:
containers:
- name: nginx
image: nginx:1.14.2
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: sample-policy
namespace: app-another
spec:
podSelector:
matchLabels:
app: shouldmatch
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: sample-pod
namespace: app-safe
spec:
containers:
- name: app
image: images.my-company.example/app:v4
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: sample-policy
namespace: app-safe
spec:
podSelector: {}
policyTypes:
- Ingress
- Egress
Explanation:
- Before: The policy is in a different namespace and does not select the illustrated Pod.
- After: Applies default-deny ingress and egress to all Pods in the same namespace. Other policies can still allow traffic; review the complete policy set and explicitly allow required DNS and application communication.