Ch. 14 · Kubernetes

Kubernetes Network Policies and Traffic Direction

Kubernetes Network Policies and Traffic Direction. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Network policies constrain selected traffic when the network implementation enforces them. Ingress and egress policies require explicit thought.

Before you start

You should understand Pods, Deployments and Services. Read desired configuration separately from observed cluster state. Use a development cluster when trying changes, and inspect events and status rather than assuming that an accepted manifest means the workload is ready to serve traffic.

The practical goal is to reason through this situation: Allow application Pods to reach the database while denying unrelated egress. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Verify implementation support

A declared policy needs a network implementation that enforces it.

Step 2: Model ingress and egress

Select source and destination requirements for the complete request path.

Step 3: Preserve necessary DNS

Restricted egress can break service-name resolution before database traffic starts.

Worked scenario

Allow application Pods to reach the database while denying unrelated egress.

A workload is permitted to contact the database but cannot resolve its hostname because resolver traffic was omitted. The resulting connection error can look like database failure. Test resolver access, target traffic and unwanted destinations; policy selectors and namespaces must match the actual deployment.

Common mistake

Creating a policy without compatible enforcement does not provide the intended protection.

Verify the behavior

Verify DNS, permitted application flows and denied flows on the real enforcement layer.

Interview exercise

Preserve DNS under egress restrictions.

Answer and reasoning

Allow the required resolver traffic and test the complete request path, not only database connections.

Continue learning

Compare the scenario with the Kubernetes interview questions and test your understanding with the Kubernetes MCQs. For terminology and implementation details, consult the reference material.

More in Kubernetes

read ✓Kubernetes · mid

Kubernetes ConfigMap Update Behavior

Understand why ConfigMap changes reach volumes but not environment variables, and how to roll a Deployment deliberately.

~2 min readread →
read ✓Kubernetes · mid

Kubernetes emptyDir Volumes

Share scratch space between containers in a pod with emptyDir, choose the backing medium, and bound its size.

~2 min readread →
read ✓Kubernetes · hard

Kubernetes Gateway API for Ingress

Route traffic with GatewayClass, Gateway and HTTPRoute, and understand how the Gateway API improves on Ingress.

~2 min readread →
esc