Review GKE NetworkPolicy enforcement

Configure both network policy enforcement and the policies defining permitted traffic.

Description

Without enforced network policies, workloads in the same cluster may communicate more broadly than necessary. NetworkPolicy limits communication between services and can reduce the spread of a compromise.

Calico on Standard requires both node enforcement and its add-on. Autopilot and Dataplane V2 provide built-in enforcement, but actual Kubernetes NetworkPolicy resources are still required in every case.

Potential impact

  • Unnecessary Pod communication can increase opportunities for lateral movement.
  • Sensitive workloads can become more accessible to other services in the cluster.

Remediation

  • For Calico on Standard, verify network_policy.enabled = true, provider = "CALICO" and addons_config.network_policy_config.disabled = false.
  • Allow required traffic with NetworkPolicies and test actual allowed and denied connections.
  • Plan for node recreation and workload disruption when changing enforcement on an existing cluster.

Examples

These are excerpts for Calico on Standard. Deploy actual NetworkPolicy resources separately. Do not apply these Calico settings unchanged to Autopilot or Dataplane V2.

Before

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3

  network_policy {
    enabled = false
  }

  addons_config {
    network_policy_config {
      disabled = false
    }
  }

  timeouts {
    create = "30m"
    update = "40m"
  }
}

After

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  networking_mode    = "VPC_NATIVE"

  network_policy {
    enabled  = true
    provider = "CALICO"
  }

  addons_config {
    network_policy_config {
      disabled = false
    }
  }

  timeouts {
    create = "30m"
    update = "40m"
  }
}

Explanation:

  • Before: The add-on is enabled, but Calico node enforcement is disabled.
  • After: The CALICO provider and both node and add-on capabilities are enabled. Separate NetworkPolicies restrict the actual traffic scope.

References