Skip to main content

What are Network Policies?

Kubernetes Network Policies are firewall rules for your pods. They control:
  • Ingress: What can connect TO your pod
  • Egress: What your pod can connect TO
Without Network Policies, all pods can communicate with all other pods (flat network).

Structure of a Network Policy

How kguardian Generates Policies

  1. Observes traffic continuously via eBPF (let several minutes of representative traffic accumulate before generating)
  2. Identifies peers — each peer IP is resolved to a pod, Service or node when the flow is ingested and stored on the row, so a recycled IP never points at its later owner (how peers are attributed)
  3. Groups rules by protocol and port
  4. Deduplicates to create minimal policies
  5. Generates YAML ready to apply

Host-network peers

A podSelector matches a pod’s own network namespace. Pods running with hostNetwork: true (node-exporter, CNI agents, kube-proxy) share the node’s namespace and IP, so a selector built from their labels never matches — the CNI sees the node, not the pod. Where a peer resolves to a host-network pod, kguardian emits an ipBlock for the node IP (Kubernetes) or toEntities/fromEntities: [host, remote-node] (Cilium) instead. A policy whose target is host-network is emitted with a warning: no NetworkPolicy can select it; that needs a Cilium host policy (CiliumClusterwideNetworkPolicy + nodeSelector). Details and a Prometheus example: Host-network peers and targets.

Default-Deny Strategy

Best practice: Start with default-deny, then allowlist:

Next steps: