What are Network Policies?
Kubernetes Network Policies are firewall rules for your pods. They control:- Ingress: What can connect TO your pod
- Egress: What your pod can connect TO
Structure of a Network Policy
How kguardian Generates Policies
- Observes traffic continuously via eBPF (let several minutes of representative traffic accumulate before generating)
- Identifies peers — each peer IP is resolved to a pod, Service or node when the flow is ingested and stored on the row, so a recycled IP never points at its later owner (how peers are attributed)
- Groups rules by protocol and port
- Deduplicates to create minimal policies
- Generates YAML ready to apply
Host-network peers
ApodSelector matches a pod’s own network namespace. Pods running with hostNetwork: true (node-exporter, CNI agents, kube-proxy) share the node’s namespace and IP, so a selector built from their labels never matches — the CNI sees the node, not the pod. Where a peer resolves to a host-network pod, kguardian emits an ipBlock for the node IP (Kubernetes) or toEntities/fromEntities: [host, remote-node] (Cilium) instead. A policy whose target is host-network is emitted with a warning: no NetworkPolicy can select it; that needs a Cilium host policy (CiliumClusterwideNetworkPolicy + nodeSelector). Details and a Prometheus example: Host-network peers and targets.
Default-Deny Strategy
Best practice: Start with default-deny, then allowlist:Next steps: