
Kubernetes Network Policy with Calico
FreeSecure your Kubernetes cluster with precise network policies.
Free · Opens the source repo
What Kubernetes Network Policy with Calico does
Implementing Kubernetes Network Policy with Calico provides a robust framework for managing network traffic within Kubernetes clusters. Calico, as a Container Network Interface (CNI) plugin, enhances Kubernetes' native capabilities by supporting both Kubernetes NetworkPolicy and Calico-specific GlobalNetworkPolicy. This skill allows users to enforce fine-grained network segmentation and security policies, ensuring that only authorized pod-to-pod communications occur. With features like default-deny rules and service-account-based selectors, it aligns with zero-trust principles, making it an essential tool for securing cloud-native applications.
The skill is particularly useful for developers and security engineers tasked with deploying or auditing network policies in Kubernetes environments. By leveraging Calico's capabilities, users can create policies that restrict east-west traffic, thus minimizing the attack surface within their clusters. The provided templates and scripts simplify the process of implementing network policies, allowing users to focus on defining security requirements rather than getting bogged down in configuration details.
This skill is designed for those who have a foundational understanding of Kubernetes and wish to enhance their cluster security posture. It requires a Kubernetes cluster with Calico installed, along with the necessary CLI tools for configuration and management. The skill also includes verification steps to ensure that Calico is running correctly, which is crucial for maintaining operational integrity.
In summary, this skill is a valuable resource for anyone looking to implement network policies in Kubernetes using Calico, providing the necessary tools and templates to establish a secure and compliant environment.
When to use it
Use this skill when deploying Calico for network policy enforcement in Kubernetes or when conducting security assessments.
When not to use it
This skill may not be suitable for users without a Kubernetes environment or those looking for a general-purpose networking solution.
What you can build with it
Deploying Calico for Network Security
Use this skill to set up Calico as your CNI plugin to enforce network policies in a new Kubernetes cluster.
Auditing Existing Network Policies
Leverage the skill to review and enhance existing network policies in your Kubernetes environment for better security.
Implementing Zero-Trust Architecture
Utilize Calico's capabilities to create a zero-trust network model within your Kubernetes cluster, ensuring only authorized communications.
How to install Kubernetes Network Policy with Calico
View source1. Install with the skills CLI
npx skills add mukul975/anthropic-cybersecurity-skills/implementing-kubernetes-network-policy-with-calico --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by mukul975Implementing Kubernetes Network Policy with Calico
Overview
Calico is an open-source CNI plugin that provides fine-grained network policy enforcement for Kubernetes clusters. It implements the full Kubernetes NetworkPolicy API and extends it with Calico-specific GlobalNetworkPolicy, supporting policy ordering, deny rules, and service-account-based selectors.
When to Use
- When deploying or configuring implementing kubernetes network policy with calico capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Kubernetes cluster (v1.24+)
- Calico CNI installed (v3.26+)
kubectlandcalicoctlCLI tools- Cluster admin RBAC permissions
Installing Calico
Operator-based Installation (Recommended)
# Install the Tigera operator
kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.0/manifests/tigera-operator.yaml
# Install Calico custom resources
kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.0/manifests/custom-resources.yaml
# Verify installation
kubectl get pods -n calico-system
watch kubectl get pods -n calico-system
# Install calicoctl
kubectl apply -f https://raw.githubusercontent.com/projectcalico/calico/v3.27.0/manifests/calicoctl.yaml
Verify Calico is Running
# Check Calico pods
kubectl get pods -n calico-system
# Check Calico node status
kubectl exec -n calico-system calicoctl -- calicoctl node status
# Check IP pools
kubectl exec -n calico-system calicoctl -- calicoctl get ippool -o wide
Kubernetes NetworkPolicy
Default Deny All Traffic
# deny-all-ingress.yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-ingress
namespace: production
spec:
podSelector: {}
policyTypes:
- Ingress
---
# deny-all-egress.yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-egress
namespace: production
spec:
podSelector: {}
policyTypes:
- Egress
Allow Specific Pod-to-Pod Communication
# allow-frontend-to-backend.yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-frontend-to-backend
namespace: production
spec:
podSelector:
matchLabels:
app: backend
policyTypes:
- Ingress
ingress:
- from:
- podSelector:
matchLabels:
app: frontend
ports:
- protocol: TCP
port: 8080
Allow DNS Egress
# allow-dns-egress.yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-dns-egress
namespace: production
spec:
podSelector: {}
policyTypes:
- Egress
egress:
- to:
- namespaceSelector: {}
ports:
- protocol: UDP
port: 53
- protocol: TCP
port: 53
Namespace Isolation
# allow-same-namespace.yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-same-namespace
namespace: production
spec:
podSelector: {}
policyTypes:
- Ingress
ingress:
- from:
- podSelector: {}
Calico-Specific Policies
GlobalNetworkPolicy (Cluster-Wide)
# global-deny-external.yaml
apiVersion: projectcalico.org/v3
kind: GlobalNetworkPolicy
metadata:
name: deny-external-ingress
spec:
order: 100
selector: "projectcalico.org/namespace != 'ingress-nginx'"
types:
- Ingress
ingress:
- action: Deny
source:
nets:
- 0.0.0.0/0
destination: {}
Calico NetworkPolicy with Deny Rules
# calico-deny-policy.yaml
apiVersion: projectcalico.org/v3
kind: NetworkPolicy
metadata:
name: deny-database-from-frontend
namespace: production
spec:
order: 10
selector: app == 'database'
types:
- Ingress
ingress:
- action: Deny
source:
selector: app == 'frontend'
- action: Allow
source:
selector: app == 'backend'
destination:
ports:
- 5432
Service Account Based Policy
# sa-based-policy.yaml
apiVersion: projectcalico.org/v3
kind: NetworkPolicy
metadata:
name: allow-by-service-account
namespace: production
spec:
selector: app == 'api'
ingress:
- action: Allow
source:
serviceAccounts:
names:
- frontend-sa
- monitoring-sa
egress:
- action: Allow
destination:
serviceAccounts:
names:
- database-sa
Host Endpoint Protection
# host-endpoint-policy.yaml
apiVersion: projectcalico.org/v3
kind: GlobalNetworkPolicy
metadata:
name: restrict-host-ssh
spec:
order: 10
selector: "has(kubernetes.io/hostname)"
applyOnForward: false
types:
- Ingress
ingress:
- action: Allow
protocol: TCP
source:
nets:
- 10.0.0.0/8
destination:
ports:
- 22
- action: Deny
protocol: TCP
destination:
ports:
- 22
Calico Policy Tiers
# security-tier.yaml
apiVersion: projectcalico.org/v3
kind: Tier
metadata:
name: security
spec:
order: 100
---
# platform-tier.yaml
apiVersion: projectcalico.org/v3
kind: Tier
metadata:
name: platform
spec:
order: 200
Monitoring and Troubleshooting
# List all network policies
kubectl get networkpolicy --all-namespaces
# List Calico-specific policies
kubectl exec -n calico-system calicoctl -- calicoctl get networkpolicy --all-namespaces -o wide
kubectl exec -n calico-system calicoctl -- calicoctl get globalnetworkpolicy -o wide
# Check policy evaluation for a specific endpoint
kubectl exec -n calico-system calicoctl -- calicoctl get workloadendpoint -n production -o yaml
# View Calico logs
kubectl logs -n calico-system -l k8s-app=calico-node --tail=100
# Test connectivity
kubectl exec -n production frontend-pod -- wget -qO- --timeout=2 http://backend-svc:8080/health
Best Practices
- Start with default deny - Apply deny-all policies to every namespace, then allow specific traffic
- Use labels consistently - Define a labeling standard for app, tier, environment
- Order policies - Use Calico policy ordering (
orderfield) to control evaluation precedence - Allow DNS first - Always create DNS egress rules before applying egress deny policies
- Use GlobalNetworkPolicy for cluster-wide security baselines
- Test policies in staging - Validate network connectivity after applying policies
- Monitor denied traffic - Enable Calico flow logs for visibility into blocked connections
- Use tiers - Organize policies into security, platform, and application tiers
Frequently asked questions about Kubernetes Network Policy with Calico
Similar skills
Resemble Detect
Detect and analyze AI-generated media for authenticity.
Licenca para Auditar
Comprehensive security audits and threat modeling for projects.
Authenticated Vulnerability Scan
Run deep vulnerability scans with valid credentials.
Agentless Vulnerability Scanning
Assess systems for vulnerabilities without agents.
Implementing Rapid7 InsightVM for Scanning
Streamline vulnerability management with InsightVM setup.
Next-Generation Firewall Deployment
Streamline Palo Alto firewall configuration and management.
