Description
Without enforced network policies, workloads in the same cluster may communicate more broadly than necessary. NetworkPolicy limits communication between services and can reduce the spread of a compromise.
Calico on Standard requires both node enforcement and its add-on. Autopilot and Dataplane V2 provide built-in enforcement, but actual Kubernetes NetworkPolicy resources are still required in every case.
Potential impact
- Unnecessary Pod communication can increase opportunities for lateral movement.
- Sensitive workloads can become more accessible to other services in the cluster.
Remediation
- For Calico on Standard, verify
network_policy.enabled = true,provider = "CALICO"andaddons_config.network_policy_config.disabled = false. - Allow required traffic with NetworkPolicies and test actual allowed and denied connections.
- Plan for node recreation and workload disruption when changing enforcement on an existing cluster.
Examples
These are excerpts for Calico on Standard. Deploy actual NetworkPolicy resources separately. Do not apply these Calico settings unchanged to Autopilot or Dataplane V2.
Before
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
network_policy {
enabled = false
}
addons_config {
network_policy_config {
disabled = false
}
}
timeouts {
create = "30m"
update = "40m"
}
}
After
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
networking_mode = "VPC_NATIVE"
network_policy {
enabled = true
provider = "CALICO"
}
addons_config {
network_policy_config {
disabled = false
}
}
timeouts {
create = "30m"
update = "40m"
}
}
Explanation:
- Before: The add-on is enabled, but Calico node enforcement is disabled.
- After: The CALICO provider and both node and add-on capabilities are enabled. Separate NetworkPolicies restrict the actual traffic scope.