Deny-Defaults
Deny All Ingress
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: deny-all-ingress
namespace: <ns>
spec:
podSelector: {}
policyTypes:
- Ingress → Blockiert allen eingehenden Traffic. Basis für Zero-Trust.
Deny All Egress
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: deny-all-egress
namespace: <ns>
spec:
podSelector: {}
policyTypes:
- Egress → Blockiert allen ausgehenden Traffic. Immer mit DNS-Egress (Pattern 10) kombinieren.
Deny All (beides)
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: deny-all
namespace: <ns>
spec:
podSelector: {}
policyTypes:
- Ingress
- Egress → Komplette Namespace-Isolation. Von hier aus Pattern für Pattern öffnen.