Skip to main content

implementing-kubernetes-network-policy-with-calico

Installs Calico as the cluster CNI and writes standard Kubernetes NetworkPolicy under it, covering default-deny baselines, policy ordering and precedence, service-account-based selectors, and verifying that policy is genuinely being enforced. Use when adopting Calico as the enforcement CNI, establishing a default-deny baseline, or debugging why a NetworkPolicy is not taking effect under Calico. Keywords: Calico CNI, NetworkPolicy, default deny, policy order, Felix, service account selector. Do not use for Calico-only CRDs such as GlobalNetworkPolicy or DNS egress - use implementing-container-network-policies-with-calico; for CNI-agnostic policy use implementing-network-policies-for-kubernetes.

설치로 이동

소스 정보

저장소
mukul975/Anthropic-Cybersecurity-Skills
최근 소스 활동
2026년 8월 23일 15:15
감지된 SKILL.md 언어
영어
스타
33,129
포크
4,016

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
8 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
implementing-kubernetes-network-policy-with-calico
description
Installs Calico as the cluster CNI and writes standard Kubernetes NetworkPolicy under it, covering default-deny baselines, policy ordering and precedence, service-account-based selectors, and verifying that policy is genuinely being enforced. Use when adopting Calico as the enforcement CNI, establishing a default-deny baseline, or debugging why a NetworkPolicy is not taking effect under Calico. Keywords: Calico CNI, NetworkPolicy, default deny, policy order, Felix, service account selector. Do not use for Calico-only CRDs such as GlobalNetworkPolicy or DNS egress - use implementing-container-network-policies-with-calico; for CNI-agnostic policy use implementing-network-policies-for-kubernetes.
domain
cybersecurity
subdomain
container-security
tags
["calico","kubernetes","network-policy","network-segmentation","zero-trust","cni"]
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
["PR.PS-01","PR.IR-01","ID.AM-08","DE.CM-01"]
mitre_attack
["T1610","T1611","T1609","T1525"]
# Implementing Kubernetes Network Policy with Calico ## Overview Calico is an open-source CNI plugin that provides fine-grained network policy enforcement for Kubernetes clusters. It implements the full Kubernetes NetworkPolicy API and extends it with Calico-specific GlobalNetworkPolicy, supporting policy ordering, deny rules, and service-account-based selectors. ## When to Use - When deploying or configuring implementing kubernetes network policy with calico capabilities in your environment - When establishing security controls aligned to compliance requirements - When building or improving security architecture for this domain - When conducting security assessments that require this implementation ## Prerequisites - Kubernetes cluster (v1.24+) - Calico CNI installed (v3.26+) - `kubectl` and `calicoctl` CLI tools - Cluster admin RBAC permissions ## Installing Calico ### Operator-based Installation (Recommended) ```bash # Install the Tigera operator kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.0/manifests/tigera-operator.yaml # Install Calico custom resources kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.0/manifests/custom-resources.yaml # Verify installation kubectl get pods -n calico-system watch kubectl get pods -n calico-system # Install calicoctl kubectl apply -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.0/manifests/calicoctl.yaml ``` ### Verify Calico is Running ```bash # Check Calico pods kubectl get pods -n calico-system # Check Calico node status kubectl exec -n calico-system calicoctl -- calicoctl node status # Check IP pools kubectl exec -n calico-system calicoctl -- calicoctl get ippool -o wide ``` ## Kubernetes NetworkPolicy ### Default Deny All Traffic ```yaml # deny-all-ingress.yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: default-deny-ingress namespace: production spec: podSelector: {} policyTypes: - Ingress --- # deny-all-egress.yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: default-deny-egress namespace: production spec: podSelector: {} policyTypes: - Egress ``` ### Allow Specific Pod-to-Pod Communication ```yaml # allow-frontend-to-backend.yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-frontend-to-backend namespace: production spec: podSelector: matchLabels: app: backend policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: app: frontend ports: - protocol: TCP port: 8080 ``` ### Allow DNS Egress ```yaml # allow-dns-egress.yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-dns-egress namespace: production spec: podSelector: {} policyTypes: - Egress egress: - to: - namespaceSelector: {} ports: - protocol: UDP port: 53 - protocol: TCP port: 53 ``` ### Namespace Isolation ```yaml # allow-same-namespace.yaml apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: allow-same-namespace namespace: production spec: podSelector: {} policyTypes: - Ingress ingress: - from: - podSelector: {} ``` ## Calico-Specific Policies ### GlobalNetworkPolicy (Cluster-Wide) ```yaml # global-deny-external.yaml apiVersion: projectcalico.org/v3 kind: GlobalNetworkPolicy metadata: name: deny-external-ingress spec: order: 100 selector: "projectcalico.org/namespace != 'ingress-nginx'" types: - Ingress ingress: - action: Deny source: nets: - 0.0.0.0/0 destination: {} ``` ### Calico NetworkPolicy with Deny Rules ```yaml # calico-deny-policy.yaml apiVersion: projectcalico.org/v3 kind: NetworkPolicy metadata: name: deny-database-from-frontend namespace: production spec: order: 10 selector: app == 'database' types: - Ingress ingress: - action: Deny source: selector: app == 'frontend' - action: Allow source: selector: app == 'backend' destination: ports: - 5432 ``` ### Service Account Based Policy ```yaml # sa-based-policy.yaml apiVersion: projectcalico.org/v3 kind: NetworkPolicy metadata: name: allow-by-service-account namespace: production spec: selector: app == 'api' ingress: - action: Allow source: serviceAccounts: names: - frontend-sa - monitoring-sa egress: - action: Allow destination: serviceAccounts: names: - database-sa ``` ### Host Endpoint Protection ```yaml # host-endpoint-policy.yaml apiVersion: projectcalico.org/v3 kind: GlobalNetworkPolicy metadata: name: restrict-host-ssh spec: order: 10 selector: "has(kubernetes.io/hostname)" applyOnForward: false types: - Ingress ingress: - action: Allow protocol: TCP source: nets: - 10.0.0.0/8 destination: ports: - 22 - action: Deny protocol: TCP destination: ports: - 22 ``` ## Calico Policy Tiers ```yaml # security-tier.yaml apiVersion: projectcalico.org/v3 kind: Tier metadata: name: security spec: order: 100 --- # platform-tier.yaml apiVersion: projectcalico.org/v3 kind: Tier metadata: name: platform spec: order: 200 ``` ## Monitoring and Troubleshooting ```bash # List all network policies kubectl get networkpolicy --all-namespaces # List Calico-specific policies kubectl exec -n calico-system calicoctl -- calicoctl get networkpolicy --all-namespaces -o wide kubectl exec -n calico-system calicoctl -- calicoctl get globalnetworkpolicy -o wide # Check policy evaluation for a specific endpoint kubectl exec -n calico-system calicoctl -- calicoctl get workloadendpoint -n production -o yaml # View Calico logs kubectl logs -n calico-system -l k8s-app=calico-node --tail=100 # Test connectivity kubectl exec -n production frontend-pod -- wget -qO- --timeout=2 http://backend-svc:8080/health ``` ## Best Practices 1. **Start with default deny** - Apply deny-all policies to every namespace, then allow specific traffic 2. **Use labels consistently** - Define a labeling standard for app, tier, environment 3. **Order policies** - Use Calico policy ordering (`order` field) to control evaluation precedence 4. **Allow DNS first** - Always create DNS egress rules before applying egress deny policies 5. **Use GlobalNetworkPolicy** for cluster-wide security baselines 6. **Test policies in staging** - Validate network connectivity after applying policies 7. **Monitor denied traffic** - Enable Calico flow logs for visibility into blocked connections 8. **Use tiers** - Organize policies into security, platform, and application tiers
GitHub에서 보기