Lesson 2: Zero-Trust & K8s Network Policies
🧠 The Concept (Explain Like I'm 5)
By default, Kubernetes is a giant open party. Anyone in the building can talk to anyone else (Pod A can freely ping Pod B). Network Policies are security guards at every door. They enforce a "Zero-Trust" rule: Unless you are explicitly on the VIP list, you cannot talk to the database.
🏢 The Enterprise Context
- Blast Radius: If an attacker breaches your public-facing frontend Pod, a flat network allows them to easily scan and hack the backend database Pod.
- Cilium Network Policies: Standard K8s network policies only filter by IP or Port (Layer 4). Cilium (eBPF) allows Layer 7 filtering (e.g., "Frontend can only send HTTP GET requests to Backend, but cannot send HTTP DELETE").
🗺️ Visual Architecture: Zero-Trust Network Policy
flowchart TD
Hacker["Hacked Frontend Pod"]
Auth["Auth Service Pod"]
DB[("Database Pod")]
Auth -->|Allowed: Port 5432| DB
Hacker -->|Blocked ❌| DB
classDef block stroke:#ef4444,stroke-width:4px;
class Hacker block;