Local Policy Enforcement

How Network Policies Are Enforced in a Local Cluster

Only the network plugin enforces NetworkPolicies; plain Flannel 9,549 , for example, ignores them silently, so test enforcement as Default-Deny Policies to Isolating the Database did. kind 14,561 's kindnetd embeds SIG Network's kube-network-policies (github.com/kubernetes-sigs/kube-network-policies (https://github.com/kubernetes-sigs/kube-network-policies 82 ), v1.1.1): nftables 40,292 sends packets of policy-selected Pods to a userspace queue for a verdict, and marks accepted connections so later packets skip the check:

kindnetd's nftables hooks on the worker, with PostgreSQL's Pod selectedShell
kubectl get pod postgres-0 -o jsonpath='{.status.podIP}{"\n"}'
docker exec l3-booknest-worker nft list set inet kindnet-network-policies podips-v4 \
  | grep elements | tr -d '\t'
docker exec l3-booknest-worker nft list chain inet kindnet-network-policies postrouting \
  | grep -e 'ct label' -e 'queue' | head -3 | tr -d '\t'
Output
10.244.1.17
elements = { 10.244.1.17 }
ct label 28 ct state established,related counter packets 3 bytes 236 accept
ip saddr @podips-v4 queue flags bypass to 101
ip daddr @podips-v4 queue flags bypass to 101

Because kindnetd enforces them, BookNest needs no Calico 111,267 here. k3s 51,195 (and k3d) routes with Flannel and embeds kube-router's policy controller, which writes iptables 40,292 rules and ipsets; it is on by default and turned off with --disable-network-policy. Calico adds its own cluster-wide policy types, and Cilium 96,364 compiles policies into eBPF with layer-7 rules. The NetworkPolicy objects in k8s/ stay the same on all of them.