Description
Network policies use namespaces and Pod selectors to define permitted traffic, helping limit the spread of a compromised workload. Both enforcement support and actual Kubernetes NetworkPolicy resources are required.
For Calico on Standard, review network_policy and the add-on settings. Autopilot and Dataplane V2 provide built-in enforcement, so focus on the policies instead of adding Calico settings.
Potential impact
- Unnecessary Pod communication may remain unrestricted at the network layer.
- A compromised workload may have more opportunities for lateral movement and internal service discovery.
Remediation
- For Calico on Standard, check
network_policy.enabled = true,provider = "CALICO"and the enabled network policy add-on together. - Use Kubernetes
NetworkPolicyresources to allow required traffic and introduce default-deny policies in stages. - Changes to an existing cluster can recreate nodes; prepare for disruption and test actual allowed and denied traffic.
Examples
These are settings excerpts for Calico on Standard. Supply node counts, project, networking and addons_config.network_policy_config.disabled = false separately. Do not apply these Calico settings unchanged to Autopilot or Dataplane V2.
Before
hcl
resource "google_container_cluster" "example" {
name = "example-cluster"
location = "asia-northeast3"
network_policy {
enabled = false
}
}
After
hcl
resource "google_container_cluster" "example" {
name = "example-cluster"
location = "asia-northeast3"
network_policy {
enabled = true
provider = "CALICO"
}
}
Explanation:
- Before: Calico node enforcement is disabled. No actual NetworkPolicy resources are included here.
- After: Enforcement is enabled with the required CALICO provider. Separate NetworkPolicies must restrict the actual traffic scope.