Review GKE network policy support

Configure both Pod traffic policies and the network capability that enforces them.

Description

Network policies use namespaces and Pod selectors to define permitted traffic, helping limit the spread of a compromised workload. Both enforcement support and actual Kubernetes NetworkPolicy resources are required.

For Calico on Standard, review network_policy and the add-on settings. Autopilot and Dataplane V2 provide built-in enforcement, so focus on the policies instead of adding Calico settings.

Potential impact

  • Unnecessary Pod communication may remain unrestricted at the network layer.
  • A compromised workload may have more opportunities for lateral movement and internal service discovery.

Remediation

  • For Calico on Standard, check network_policy.enabled = true, provider = "CALICO" and the enabled network policy add-on together.
  • Use Kubernetes NetworkPolicy resources to allow required traffic and introduce default-deny policies in stages.
  • Changes to an existing cluster can recreate nodes; prepare for disruption and test actual allowed and denied traffic.

Examples

These are settings excerpts for Calico on Standard. Supply node counts, project, networking and addons_config.network_policy_config.disabled = false separately. Do not apply these Calico settings unchanged to Autopilot or Dataplane V2.

Before

hcl
resource "google_container_cluster" "example" {
  name     = "example-cluster"
  location = "asia-northeast3"

  network_policy {
    enabled = false
  }
}

After

hcl
resource "google_container_cluster" "example" {
  name     = "example-cluster"
  location = "asia-northeast3"

  network_policy {
    enabled  = true
    provider = "CALICO"
  }
}

Explanation:

  • Before: Calico node enforcement is disabled. No actual NetworkPolicy resources are included here.
  • After: Enforcement is enabled with the required CALICO provider. Separate NetworkPolicies must restrict the actual traffic scope.

References