Network Policies and Least-Privilege Networking
Lock down container-to-container traffic with default-deny network policies, explicit allow rules, and the principle of least privilege applied to networking.
Network Policies and Least-Privilege Networking is a free DevOps Bootcamp lesson on CoddyKit. This is lesson 4 of 4. Any 3 lessons of this learning path are free to read in full — after that, CoddyKit PRO unlocks every lesson, plus hands-on practice with a built-in code editor and a 24/7 AI tutor. It is part of the DevOps Bootcamp learning path, and your progress syncs across the web and the CoddyKit app. The DevOps Bootcamp course includes 4 lessons in total.
Default-Open Is Risky
By default, containers in a cluster can usually talk to every other container. A compromised pod can then reach databases and internal services freely. Network policies close that door.
Least Privilege for Networking
The principle of least privilege applies to traffic: a service should accept and make only the connections it truly needs - nothing more.
What Is a Network Policy?
A NetworkPolicy is a Kubernetes object that selects pods by label and specifies which ingress and egress traffic is allowed. A CNI plugin (Calico, Cilium) enforces it.
You Need an Enforcing CNI
Like Ingress needs a controller, NetworkPolicies need a CNI that supports them. On a plugin that ignores them, the rules silently do nothing.
Default Deny Ingress
Start by denying all incoming traffic to a namespace, then open only what you need. An empty podSelector matches every pod.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-ingress
spec:
podSelector: {}
policyTypes:
- IngressAllow Specific Traffic
Now allow only frontend pods to reach the API on port 8080. Everything else stays blocked.
spec:
podSelector:
matchLabels:
app: api
ingress:
- from:
- podSelector:
matchLabels:
app: frontend
ports:
- port: 8080Restricting Egress
You can also limit outbound traffic, e.g. allow a pod to reach only the database, preventing a hijacked pod from phoning home.
spec:
podSelector:
matchLabels:
app: api
policyTypes:
- Egress
egress:
- to:
- podSelector:
matchLabels:
app: dbNamespace Selectors
Rules can match by namespaceSelector to allow cross-namespace traffic only from trusted namespaces - useful for shared platform services.
from:
- namespaceSelector:
matchLabels:
team: platformAllowing DNS
A common gotcha: a strict default-deny egress also blocks DNS, breaking name resolution. Remember to allow UDP/TCP 53 to kube-dns.
egress:
- to: []
ports:
- protocol: UDP
port: 53Beyond Kubernetes
Docker users get a related benefit from user-defined networks: only containers on the same network can reach each other, isolating unrelated apps.
docker network create --internal backendZero Trust Mindset
Least-privilege networking moves you toward zero trust: assume the network is hostile, authenticate and authorize every connection, allow nothing by default.
Quick Check
What is a sensible starting strategy for network policies?
Recap
You can now restrict traffic safely:
- Apply default-deny, then explicit allow rules
- Control both ingress and egress by label/namespace
- Remember to allow DNS; an enforcing CNI is required
- Docker internal networks give similar isolation
Least-privilege networking shrinks the blast radius of any breach.
Learn DevOps Bootcamp with an AI tutor — free
Write and run real code in your browser, get instant help from a 24/7 AI tutor, and pick up where you left off on the web or in the app.
- Courses
- 142
- Lessons
- 568
Frequently Asked Questions
Is the “Network Policies and Least-Privilege Networking” lesson free?
Yes — any 3 lessons of the DevOps Bootcamp learning path, including “Network Policies and Least-Privilege Networking”, are free to read in full here on the web. After that, CoddyKit PRO unlocks every lesson, plus interactive practice with a built-in code editor and a 24/7 AI tutor. The DevOps Bootcamp course includes 4 lessons in total.
What will I learn in “Network Policies and Least-Privilege Networking”?
Lock down container-to-container traffic with default-deny network policies, explicit allow rules, and the principle of least privilege applied to networking. You practise DevOps Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start DevOps Bootcamp?
No prior experience is required. DevOps Bootcamp on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 4 of 4.
How long does the “Network Policies and Least-Privilege Networking” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this DevOps Bootcamp lesson?
Yes. Every DevOps Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Container Image Security Scanning
- Runtime Container Security
- Secrets Management & RBAC
- Network Policies and Least-Privilege Networking