Kubernetes security fundamentals: Networking
ID: fb8c2b66-838e-50d3-ad10-067ad8820f5b
STIX ID: report--fb8c2b66-838e-50d3-ad10-067ad8820f5b
Feed Name: Datadog Security Labs
The post explains Kubernetes network security fundamentals with an emphasis on network policies, comparing managed vs. unmanaged clusters, and the role of CNI plugins (e.g., Calico) in enforcing policy. It demonstrates moving from a default-allow model to a secure default-deny posture, then selectively allowing ingress/egress via namespace and label selectors, and highlights risks such as unrestricted egress (e.g., to cloud metadata) and host networking bypass. A hands-on example using kind and Calico shows deploying a web app and database, applying policies to restrict access, and validating enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
