⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 32 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering Platform Governance & Policies Network Isolation
🎯 Target Role / Context: Senior Platform Engineer Interview · Platform Security & Networking

Q: Your cluster has 80 microservices running across 20 namespaces with an unsegmented flat network. A security audit mandates default-deny East-West network segmentation. How do you introduce strict Calico NetworkPolicies via Golden Path templates without breaking existing inter-service communications?

Automating zero-trust East-West network segmentation in multi-tenant Kubernetes clusters through Golden Path manifest generation.

#Platform Engineering #Calico #Kubernetes #NetworkPolicy #Security #Multi-Tenancy
🎙️ Candidate Opening & Architectural Context
"Applying immediate default-deny network policies across a brownfield cluster causes instant cross-namespace service outages. The platform team must first deploy audit-mode logging policies, analyze traffic flows via Hubble or Calico Enterprise, and inject standardized NetworkPolicy templates into Golden Path starter charts."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Audit Active East-West Traffic Flows via Cilium / Calico Logs

Deploy a Calico `GlobalNetworkPolicy` in `Log` or `Audit` mode before enforcing denial. Extract all active inter-namespace communication pairs.

apiVersion: projectcalico.org/v3
kind: GlobalNetworkPolicy
metadata:
  name: audit-east-west
spec:
  types: [Ingress, Egress]
  ingress:
    - action: Log
  egress:
    - action: Log
2

Standardize Namespace-Level Default-Deny with Ingress Allow-Lists

Incorporate automated NetworkPolicy generation into the base Helm chart. Every service declares its authorized upstream callers in values.yaml.

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: checkout-api-netpol
  namespace: team-checkout
spec:
  podSelector:
    matchLabels: { app: checkout-api }
  policyTypes: [Ingress]
  ingress:
    - from:
        - namespaceSelector:
            matchLabels: { kubernetes.io/metadata.name: team-frontend }
      ports:
        - protocol: TCP
          port: 8080
Advertisement
3

Automate Policy Ingestion in Golden Path Scaffolder

When developers scaffold a new service, Backstage prompts them: 'Which services need to call your API?' The scaffolder generates the corresponding NetworkPolicy automatically.

Pro Tip: Zero-Trust Reality: Default-deny with explicit allow-listing blocks lateral attack movement if a single public container is compromised.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Transition to zero-trust networking by auditing flows in log mode first, then generating declarative NetworkPolicies automatically through Golden Path Helm templates."
⚡ 60-Second Elevator Pitch Talking Points
  • Deploy Calico audit-mode policies to map active cross-namespace dependencies before enforcing denial.
  • Bake automated NetworkPolicy definitions directly into the platform's Golden Path base Helm chart.
  • Capture dependency allow-lists during Backstage scaffolding so security policies are created automatically.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →