KOP Network Policy Manager - Namespace Policies - Rafay Product Documentation

Namespace Network Policies

Overview

Important

For any pods/workloads that existed pre deployment of Cilium/Network Policy Manager onto the cluster, those pods/workloads must be RESTARTED in order for policies to take effect. New pods/workloads do NOT need to be restarted.

Important

Org Admin or Project Admin or Workspace Admin role is required to create and use namespace network policies.

A namespace network policy is a bundle of network security rules that can be applied to one or more namespaces. Namespace network policies are used to protect pods and applications residing in a namespace by enforcing a default set of rules for zero-trust while specifying how pods are allowed to communicate with other various entities whether that be other pods, other namespaces, system resources, or the internet.

Use Cases

Managing Namespace Policies

Creating a Namespace Policy

In order to create a namespace policy, you must add namespace-scoped network policy rules to it. Refer here for instructions to create Network Policy rules.

Rules can be added to or removed from a policy using the same workflow. A new version needs to be created every time a policy is updated.

Using Namespace Policies

Namespaces Policies are added to/removed namespaces by doing the following: