logo

Kubernetes security fundamentals: Networking

ID: fb8c2b66-838e-50d3-ad10-067ad8820f5b

STIX ID: report--fb8c2b66-838e-50d3-ad10-067ad8820f5b

Feed Name: Datadog Security Labs

Date Published: 2025-01-28

Date Updated: 2026-04-27

...
...

The post explains Kubernetes network security fundamentals with an emphasis on network policies, comparing managed vs. unmanaged clusters, and the role of CNI plugins (e.g., Calico) in enforcing policy. It demonstrates moving from a default-allow model to a secure default-deny posture, then selectively allowing ingress/egress via namespace and label selectors, and highlights risks such as unrestricted egress (e.g., to cloud metadata) and host networking bypass. A hands-on example using kind and Calico shows deploying a web app and database, applying policies to restrict access, and validating enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.