By default every Pod can reach every other. Once a NetworkPolicy selects a Pod for a direction in its policyTypes, only traffic some policy allows passes that way; policies only add, with no deny rule. The usual start is a default deny that selects every Pod and allows nothing. Try it with a scratch server and client:
kubectl create namespace netpol-demo >/dev/null
kubectl config set-context --current --namespace=netpol-demo >/dev/null
kubectl run server --image=localhost:33500/booknest-web:1.3 -l app=server --port=80 \
--expose >/dev/null
kubectl run client --image=localhost:33500/booknest-web:1.3 -l role=client >/dev/null
kubectl wait --for=condition=Ready pod --all >/dev/null
probe() { kubectl exec ${1:-client} -- wget -qO- -T 3 http://server/healthz 2>&1 | head -1; }
probe
kubectl apply -f - <<'EOF'
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata: { name: default-deny }
spec:
podSelector: {}
policyTypes: [Ingress, Egress]
EOF
probeOutput
ok networkpolicy.networking.k8s.io/default-deny created wget: bad address 'server'
The client cannot even resolve server: denying egress also denied DNS, so every default deny needs a companion rule for DNS.