Skip to content

Lesson 2: Zero-Trust & K8s Network Policies

🧠 The Concept (Explain Like I'm 5)

By default, Kubernetes is a giant open party. Anyone in the building can talk to anyone else (Pod A can freely ping Pod B). Network Policies are security guards at every door. They enforce a "Zero-Trust" rule: Unless you are explicitly on the VIP list, you cannot talk to the database.


🏢 The Enterprise Context

  • Blast Radius: If an attacker breaches your public-facing frontend Pod, a flat network allows them to easily scan and hack the backend database Pod.
  • Cilium Network Policies: Standard K8s network policies only filter by IP or Port (Layer 4). Cilium (eBPF) allows Layer 7 filtering (e.g., "Frontend can only send HTTP GET requests to Backend, but cannot send HTTP DELETE").

🗺️ Visual Architecture: Zero-Trust Network Policy

flowchart TD
    Hacker["Hacked Frontend Pod"]
    Auth["Auth Service Pod"]
    DB[("Database Pod")]

    Auth -->|Allowed: Port 5432| DB
    Hacker -->|Blocked ❌| DB

    classDef block stroke:#ef4444,stroke-width:4px;
    class Hacker block;