Default-Deny Policies

NetworkPolicies and Default-Deny Rules

By default every Pod can reach every other. Once a NetworkPolicy selects a Pod for a direction in its policyTypes, only traffic some policy allows passes that way; policies only add, with no deny rule. The usual start is a default deny that selects every Pod and allows nothing. Try it with a scratch server and client:

A server and a client, before and after a default-deny policyShell
kubectl create namespace netpol-demo >/dev/null
kubectl config set-context --current --namespace=netpol-demo >/dev/null
kubectl run server --image=localhost:33500/booknest-web:1.3 -l app=server --port=80 \
  --expose >/dev/null
kubectl run client --image=localhost:33500/booknest-web:1.3 -l role=client >/dev/null
kubectl wait --for=condition=Ready pod --all >/dev/null
probe() { kubectl exec ${1:-client} -- wget -qO- -T 3 http://server/healthz 2>&1 | head -1; }
probe
kubectl apply -f - <<'EOF'
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata: { name: default-deny }
spec:
  podSelector: {}
  policyTypes: [Ingress, Egress]
EOF
probe
Output
ok
networkpolicy.networking.k8s.io/default-deny created
wget: bad address 'server'

The client cannot even resolve server: denying egress also denied DNS, so every default deny needs a companion rule for DNS.