DevOps Bootcamp · Lesson

Network Policies and Least-Privilege Networking

Lock down container-to-container traffic with default-deny network policies, explicit allow rules, and the principle of least privilege applied to networking.

Lesson 4 of 413 steps

Network Policies and Least-Privilege Networking is a free DevOps Bootcamp lesson on CoddyKit. This is lesson 4 of 4. Any 3 lessons of this learning path are free to read in full — after that, CoddyKit PRO unlocks every lesson, plus hands-on practice with a built-in code editor and a 24/7 AI tutor. It is part of the DevOps Bootcamp learning path, and your progress syncs across the web and the CoddyKit app. The DevOps Bootcamp course includes 4 lessons in total.

Default-Open Is Risky

By default, containers in a cluster can usually talk to every other container. A compromised pod can then reach databases and internal services freely. Network policies close that door.

Least Privilege for Networking

The principle of least privilege applies to traffic: a service should accept and make only the connections it truly needs - nothing more.

What Is a Network Policy?

A NetworkPolicy is a Kubernetes object that selects pods by label and specifies which ingress and egress traffic is allowed. A CNI plugin (Calico, Cilium) enforces it.

You Need an Enforcing CNI

Like Ingress needs a controller, NetworkPolicies need a CNI that supports them. On a plugin that ignores them, the rules silently do nothing.

Default Deny Ingress

Start by denying all incoming traffic to a namespace, then open only what you need. An empty podSelector matches every pod.

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-ingress
spec:
  podSelector: {}
  policyTypes:
  - Ingress

Allow Specific Traffic

Now allow only frontend pods to reach the API on port 8080. Everything else stays blocked.

spec:
  podSelector:
    matchLabels:
      app: api
  ingress:
  - from:
    - podSelector:
        matchLabels:
          app: frontend
    ports:
    - port: 8080

Restricting Egress

You can also limit outbound traffic, e.g. allow a pod to reach only the database, preventing a hijacked pod from phoning home.

spec:
  podSelector:
    matchLabels:
      app: api
  policyTypes:
  - Egress
  egress:
  - to:
    - podSelector:
        matchLabels:
          app: db

Namespace Selectors

Rules can match by namespaceSelector to allow cross-namespace traffic only from trusted namespaces - useful for shared platform services.

from:
- namespaceSelector:
    matchLabels:
      team: platform

Allowing DNS

A common gotcha: a strict default-deny egress also blocks DNS, breaking name resolution. Remember to allow UDP/TCP 53 to kube-dns.

egress:
- to: []
  ports:
  - protocol: UDP
    port: 53

Beyond Kubernetes

Docker users get a related benefit from user-defined networks: only containers on the same network can reach each other, isolating unrelated apps.

docker network create --internal backend

Zero Trust Mindset

Least-privilege networking moves you toward zero trust: assume the network is hostile, authenticate and authorize every connection, allow nothing by default.

Quick Check

What is a sensible starting strategy for network policies?

Recap

You can now restrict traffic safely:

  • Apply default-deny, then explicit allow rules
  • Control both ingress and egress by label/namespace
  • Remember to allow DNS; an enforcing CNI is required
  • Docker internal networks give similar isolation

Least-privilege networking shrinks the blast radius of any breach.

Free to start

Learn DevOps Bootcamp with an AI tutor — free

Write and run real code in your browser, get instant help from a 24/7 AI tutor, and pick up where you left off on the web or in the app.

Courses
142
Lessons
568

Frequently Asked Questions

Is the “Network Policies and Least-Privilege Networking” lesson free?

Yes — any 3 lessons of the DevOps Bootcamp learning path, including “Network Policies and Least-Privilege Networking”, are free to read in full here on the web. After that, CoddyKit PRO unlocks every lesson, plus interactive practice with a built-in code editor and a 24/7 AI tutor. The DevOps Bootcamp course includes 4 lessons in total.

What will I learn in “Network Policies and Least-Privilege Networking”?

Lock down container-to-container traffic with default-deny network policies, explicit allow rules, and the principle of least privilege applied to networking. You practise DevOps Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start DevOps Bootcamp?

No prior experience is required. DevOps Bootcamp on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 4 of 4.

How long does the “Network Policies and Least-Privilege Networking” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this DevOps Bootcamp lesson?

Yes. Every DevOps Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Container Image Security Scanning
  2. Runtime Container Security
  3. Secrets Management & RBAC
  4. Network Policies and Least-Privilege Networking
← Back to DevOps Bootcamp