Network policies
Without network policy, pods in a cluster can generally talk to each other freely.
That default is convenient and means one compromised workload can reach everything else. Policies restore the constraint, service by service, and they are a great deal easier to write while the estate is small than to retrofit once hundreds of services depend on the openness.
Checked against the primary source.
