Describe the flow before fixing policy
Record source, namespace, labels, destination, protocol and port. If both ends are isolated in the relevant direction, source egress and destination ingress must permit the connection. Working DNS and a listening process help diagnosis but do not replace that authorization. In the exercise’s batch, egress already allows the destination and the issue lies in labels selected by ingress. Use that information to narrow hypotheses. Do not open every source merely because close is approaching; connect the fix to the approved boundary.
Treat labels as a release contract
A supplier changes role=settler to role=worker to standardize manifests. Policy still selects the prior value and a fresh connection fails. The technical manager should include selectors in label-change impact, just as API consumers are included. For a peer containing only podSelector, scope is the policy namespace; do not assume every namespace. Testing should compare an authorized client with one that must be denied. Retain labels actually deployed rather than only the template someone intended to use in the window.
Choose a control that understands the requirement
Allowing /status and blocking /admin on the same port is an application condition. Standard NetworkPolicy offers no HTTP-path field for that decision. Combine the network boundary with appropriate authorization in the service or proxy according to architecture. Likewise, runtimeClassName:sandbox does not itself establish the intended isolation. Confirm handler, configuration and limitations. Architecture review should connect each requirement to the mechanism enforcing it and to observable evidence, avoiding acceptance of an object name as proof of sufficient protection.
Assess exceptions by Pod-creating identity
A Pod Security Admission exemption does not automatically retain warn and audit while bypassing enforce: all three modes are skipped for covered requests. Also, exempting a Deployment author does not exempt the different identity creating Pods. Before proposing controller exemption, consider its reach across every workload that controller can create. Prefer correcting the template and validating functional requirements. Any exception needs explicit scope, owner, deadline and an observation method that continues supplying the evidence operations needs.
Control the baseline and containment meaning
Pinning a rehearsed PSA version makes the baseline explicit during an upgrade; it also requires later review planning. Using latest does not provide an immutable minor baseline. In incident response, distinguish another boundary: policy blocking fresh connections may not end existing sessions, depending on the plugin. In the exercise, the old flow keeps transferring bytes. That observation contradicts a complete-containment claim. Apply the authorized mechanism covering that flow while preserving evidence and healthy capacity according to the agreed response plan.
Build acceptance criteria per change
For a release, check deployed configuration, identity used, allowed paths and prohibited paths. For containment, add existing sessions and the executed action’s outcome. For an upgrade, record the rehearsed policy version and who assesses the next one. Organize handover around verifiable claims, such as client A can connect or client B is denied, with timing and evidence. These criteria help APS repeat diagnosis without depending on the manifest author. Practice here is synthetic; an authorized lab remains necessary to observe actual plugin and cluster behavior.
A fresh connection is denied after containment but the old session continues: incident response must also address that flow.
Common pitfalls
Assuming ingress suffices; confusing port names with HTTP paths; broadly exempting controllers; claiming containment from fresh connections alone.
Related topics: NetworkPolicy and selectors · PSA and incident response
A useful boundary retains the approved flow and demonstrates intended denial under the change’s actual conditions.
Reference: Network policies · Kubernetes v1.35; current six-domain CKS outline