𝔩𝔢𝔩𝕠𝔭𝔢𝔷
Theme

Homelab

Making NetworkPolicies Actually Enforce

Enforcing NetworkPolicy on a Talos Kubernetes Cluster with kube-router

Overview

Every NetworkPolicy in this cluster has been a no-op since it was written. Flannel, the CNI here, does not implement networking.k8s.io/v1 at all. The objects apply, kubectl get networkpolicy lists them, and nothing happens. The ten policies already in the repo, one per core component and per exposed workload, have been documenting intent without enforcing it. This article closes that gap without replacing Flannel: a small, policy-only DaemonSet chains onto the existing CNI and gives those objects a dataplane. Turning enforcement on also surfaces one design point that only a real dataplane can reveal, and the frpc policy is rewritten around it before anything ships.

Having trouble? See v2.7.1 for what your setup should look like after completing this article.

This article isn't ready yet

Check back soon for the full article.

Previous
Public Tier HTTPS