Q: Your cluster has 80 microservices running across 20 namespaces with an unsegmented flat network. A security audit mandates default-deny East-West network segmentation. How do you introduce strict Calico NetworkPolicies via Golden Path templates without breaking existing inter-service communications?
Automating zero-trust East-West network segmentation in multi-tenant Kubernetes clusters through Golden Path manifest generation.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Audit Active East-West Traffic Flows via Cilium / Calico Logs
Deploy a Calico `GlobalNetworkPolicy` in `Log` or `Audit` mode before enforcing denial. Extract all active inter-namespace communication pairs.
apiVersion: projectcalico.org/v3
kind: GlobalNetworkPolicy
metadata:
name: audit-east-west
spec:
types: [Ingress, Egress]
ingress:
- action: Log
egress:
- action: Log
Standardize Namespace-Level Default-Deny with Ingress Allow-Lists
Incorporate automated NetworkPolicy generation into the base Helm chart. Every service declares its authorized upstream callers in values.yaml.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: checkout-api-netpol
namespace: team-checkout
spec:
podSelector:
matchLabels: { app: checkout-api }
policyTypes: [Ingress]
ingress:
- from:
- namespaceSelector:
matchLabels: { kubernetes.io/metadata.name: team-frontend }
ports:
- protocol: TCP
port: 8080
Automate Policy Ingestion in Golden Path Scaffolder
When developers scaffold a new service, Backstage prompts them: 'Which services need to call your API?' The scaffolder generates the corresponding NetworkPolicy automatically.
- Deploy Calico audit-mode policies to map active cross-namespace dependencies before enforcing denial.
- Bake automated NetworkPolicy definitions directly into the platform's Golden Path base Helm chart.
- Capture dependency allow-lists during Backstage scaffolding so security policies are created automatically.