NetworkPolicy needs an enforcement engine
Writing a NetworkPolicy does nothing unless something in the cluster enforces it.
The object is accepted, appears in the configuration and is silently ignored if the networking plugin does not implement it. This is a genuinely surprising failure mode: the policy exists, looks correct, and has no effect. Verifying enforcement is a separate check from verifying the policy.
More on Kubernetes
- A container is isolation, not a tiny virtual machinePartitions, not buildings
- Kubernetes RBAC controls API actions, not what a running container can then doChecked at the hatch, not inside the room
- A pod service account is an identityA badge on the same rail
- Admission control can stop risky objects before they runStopped on the chute
- Privileged containers weaken the host boundaryThe floor is the boundary
- Mutable image tags can move underneath youSame ticket, different coat
