Homelab
Making NetworkPolicies Actually Enforce
Enforcing NetworkPolicy on a Talos Kubernetes Cluster with kube-router
Overview
Every NetworkPolicy in this cluster has been a no-op since it was written. Flannel, the CNI here, does not implement networking.k8s.io/v1 at all. The objects apply, kubectl get networkpolicy lists them, and nothing happens. The ten policies already in the repo, one per core component and per exposed workload, have been documenting intent without enforcing it. This article closes that gap without replacing Flannel: a small, policy-only DaemonSet chains onto the existing CNI and gives those objects a dataplane. Turning enforcement on also surfaces one design point that only a real dataplane can reveal, and the frpc policy is rewritten around it before anything ships.
Having trouble? See v2.7.1 for what your setup should look like after completing this article.
This article isn't ready yet
Check back soon for the full article.