1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["1823"],{26427:function(e,i,n){n.r(i),n.d(i,{frontMatter:()=>r,toc:()=>c,default:()=>p,metadata:()=>o,assets:()=>l,contentTitle:()=>s});var o=JSON.parse('{"id":"microsegmentation","title":"Implement microsegmentation with calico for enhanced Kubernetes Security","description":"Calico enables robust microsegmentation in Kubernetes environments, offering granular isolation and enhanced security for containerized applications.","source":"@site/use-cases/microsegmentation.mdx","sourceDirName":".","slug":"/microsegmentation","permalink":"/use-cases/microsegmentation","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/use-cases/microsegmentation.mdx","tags":[],"version":"current","frontMatter":{"description":"Calico enables robust microsegmentation in Kubernetes environments, offering granular isolation and enhanced security for containerized applications.","title":"Implement microsegmentation with calico for enhanced Kubernetes Security","keywords":["microsegmentation"],"sidebar_label":"Microsegmentation"},"sidebar":"useCaseSidebar","next":{"title":"Observability","permalink":"/use-cases/observability"}}'),t=n(37937),a=n(17869);let r={description:"Calico enables robust microsegmentation in Kubernetes environments, offering granular isolation and enhanced security for containerized applications.",title:"Implement microsegmentation with calico for enhanced Kubernetes Security",keywords:["microsegmentation"],sidebar_label:"Microsegmentation"},s="Microsegmentation",l={},c=[{value:"Overview",id:"overview",level:2},{value:"What is microsegmentation?",id:"what-is-microsegmentation",level:3},{value:"Why use Calico for microsegmentation?",id:"why-use-calico-for-microsegmentation",level:3},{value:"Microsegmentation at different levels",id:"microsegmentation-at-different-levels",level:3},{value:"Workload isolation",id:"workload-isolation",level:4},{value:"Namespace isolation",id:"namespace-isolation",level:4},{value:"Tenant isolation",id:"tenant-isolation",level:4},{value:"Foundational concepts for microsegmentation",id:"foundational-concepts-for-microsegmentation",level:2},{value:"Security domains",id:"security-domains",level:3},{value:"Calico's enhanced network policy capabilities",id:"calicos-enhanced-network-policy-capabilities",level:3},{value:"Default deny",id:"default-deny",level:3},{value:"Additional functionality with Calico Enterprise and Calico Cloud",id:"additional-functionality-with-calico-enterprise-and-calico-cloud",level:3},{value:"Global network policies",id:"global-network-policies",level:4},{value:"Network policy management",id:"network-policy-management",level:4},{value:"Policy ordering",id:"policy-ordering",level:5},{value:"Policy tiers",id:"policy-tiers",level:5},{value:"Staged policies",id:"staged-policies",level:5},{value:"Implementing microsegmentation with network policies",id:"implementing-microsegmentation-with-network-policies",level:2},{value:"Identify your security domains",id:"identify-your-security-domains",level:3},{value:"Develop a policy framework",id:"develop-a-policy-framework",level:3},{value:"Analyze cluster traffic",id:"analyze-cluster-traffic",level:4},{value:"Label your assets",id:"label-your-assets",level:4},{value:"Write your policies",id:"write-your-policies",level:4},{value:"Deploy network policies",id:"deploy-network-policies",level:3},{value:"Enforce a default deny policy",id:"enforce-a-default-deny-policy",level:3},{value:"Monitor and fine-tune your policies",id:"monitor-and-fine-tune-your-policies",level:3},{value:"Review the policies board",id:"review-the-policies-board",level:4},{value:"Use observability tools",id:"use-observability-tools",level:4},{value:"Test connectivity with test pods",id:"test-connectivity-with-test-pods",level:4},{value:"Read the logs",id:"read-the-logs",level:4},{value:"Simulate your application or service",id:"simulate-your-application-or-service",level:4}];function d(e){let i={a:"a",admonition:"admonition",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",h4:"h4",h
15:"h5",header:"header",img:"img",li:"li",ol:"ol",p:"p",pre:"pre",ul:"ul",...(0,a.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(i.header,{children:(0,t.jsx)(i.h1,{id:"microsegmentation",children:"Microsegmentation"})}),"\n",(0,t.jsx)(i.p,{children:"This guide explains the concept of microsegmentation and shows you how to use Calico network policy to isolate and protect containerized applications."}),"\n",(0,t.jsx)(i.admonition,{title:"Calico quickstart",type:"tip",children:(0,t.jsxs)(i.p,{children:["You can get started with Calico by following our ",(0,t.jsx)(i.a,{href:"/calico/latest/getting-started/kubernetes/quickstart",children:"quickstart guide"}),".\nYou'll learn how to install Calico, secure a cluster with network policy, and monitor network traffic with Calico Whisker."]})}),"\n",(0,t.jsx)(i.h2,{id:"overview",children:"Overview"}),"\n",(0,t.jsx)(i.h3,{id:"what-is-microsegmentation",children:"What is microsegmentation?"}),"\n",(0,t.jsx)(i.p,{children:"Microsegmentation extends traditional segmentation to containerized environments, providing granular isolation for enhanced security in Kubernetes.\nUnlike legacy methods that focus on perimeter security, microsegmentation leverages network policies to secure assets at a finer level, from workloads to namespaces, based on label selectors.\nBy limiting communication between segments, it isolates critical security domains, stops lateral movement, and ensures compliance."}),"\n",(0,t.jsx)(i.h3,{id:"why-use-calico-for-microsegmentation",children:"Why use Calico for microsegmentation?"}),"\n",(0,t.jsxs)(i.p,{children:["Anyone who has a need to segment containerized systems in their organization can use ",(0,t.jsx)(i.a,{href:"/calico/latest/network-policy/get-started/calico-policy/calico-network-policy",children:"Calico's network policies"})," to isolate, protect, and secure multiple security domains, such as Kubernetes workloads, namespaces, tenants, and hosts.\nTraditional firewalls are not designed with dynamic, containerized environments in mind.\nInstead, microsegmentation is implemented using purpose-built network policies that allow for different levels of granularity to secure workloads, applications, namespaces, or clusters."]}),"\n",(0,t.jsx)(i.p,{children:"Calico has a range of functionality that makes implementing microsegmentation in Kubernetes easier and faster."}),"\n",(0,t.jsx)(i.p,{children:"In open-source Calico (Project Calico) and commercial Calico products, you take advantage of Calico network policy, which extends functionality of Kubernetes network policy. Some of these key features include using Calico network policies to protect more endpoints, write global policies that apply cluster-wide, and additional policy actions such as deny and log."}),"\n",(0,t.jsx)(i.p,{children:"Commercial Calico products (Calico Enterprise and Calico Cloud) compliment the additional network policy capabilities with an easy-to-use browser-based UI that includes observability, enhanced policy management, policy recommendations, and more."}),"\n",(0,t.jsx)(i.p,{children:"More detailed descriptions of functionality and how to implement microsegmentation with Calico can be found further on in this document."}),"\n",(0,t.jsx)(i.h3,{id:"microsegmentation-at-different-levels",children:"Microsegmentation at different levels"}),"\n",(0,t.jsxs)(i.p,{children:["When organizations need to segment and isolate their Kubernetes environments, this is typically done at three different levels: ",(0,t.jsx)(i.a,{href:"https://www.tigera.io/blog/enabling-microsegmentation-with-calico-enterprise-2/",children:"Workload Isolation"}),", ",(0,t.jsx)(i.a,{href:"https://www.tigera.io/blog/automated-namespace-isolation-with-calico/",children:"Namespace Isolation"})," and ",(0,t.jsx)(i.a,{href:"https://www.tigera.io/blog/deep-dive/implementing-tenant-isolation-in-multi-tenant-kubernetes-clusters/",children:"Tenant Isolation"}),"."]}),"\n",(0,t.jsx)(i.h4,{id:"workload-isolation",children:"Workload isolation"}),"\n",(0,t.jsx)(i.p,{children:"Kubernetes network policy is defined to secure specific microservices within a tenant or namespace.\nIsolating individual workloads helps further reduce the attack surface and prevents lateral movement between workloads or potential performance issues.\nA network policy designed for workload isolation contains more restrictive ingress and egress rules, only allowing essential communication between microservices.\nFor example, an application may contain frontend and backend workloads within the same namespace.\nIf the frontend is public, and more likely to be breached, apply a microsegmentation strategy where communication between the frontend and backend is restricted.\nIf the frontend is compromised, the likelihood of the malicious actor obtaining sensitive information from the backend is significantly reduced.\nPerimeter (namespace) security approaches are inadequate in this situation."}),"\n",(0,t.jsx)(i.h4,{id:"namespace-isolation",children:"Namespace isolation"}),"\n",(0,t.jsx)(i.p,{children:"In Kubernetes, namespaces are used to separate different software applications or processes from each other by assigning them unique namespaces.\nThis helps to prevent conflicts or interference between different applications that may be running on the same system, and owned by different users.\nIsolating and securing applications in their namespaces means developers can ensure that their software operates independently and securely without the ability to impact other namespaces in the cluster.\nIf one application in a namespace is compromised, having secured and isolated namespaces reduces and contains the \u201Cblast radius\u201D of that threat."}),"\n",(0,t.jsx)(i.h4,{id:"tenant-isolation",children:"Tenant isolation"}
1),"\n",(0,t.jsx)(i.p,{children:"When cluster infrastructure is shared between tenants, there may be an organizational or compliance requirement for isolation.\nA tenant may contain several resources, including workloads or namespaces (secured or unsecured), and still require that perimeter security apply to the context of the tenant.\nThis protects each tenant from lateral movement at an infrastructure level where a malicious or opportunistic actor may seek to obtain or steal high value assets, damage or misuse applications.\nIf one tenant is compromised, the risk to other tenants on the same infrastructure is significantly reduced."}),"\n",(0,t.jsx)(i.h2,{id:"foundational-concepts-for-microsegmentation",children:"Foundational concepts for microsegmentation"}),"\n",(0,t.jsx)(i.p,{children:"Before implementing a segmentation strategy in a cluster there are a few key high-level concepts that must be understood.\nThese are:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:"Security domains"}),"\n",(0,t.jsx)(i.li,{children:"Network security"}),"\n",(0,t.jsx)(i.li,{children:"Default deny"}),"\n"]}),"\n",(0,t.jsx)(i.p,{children:"If you are a Calico Enterprise or Calico Cloud user there are more features available that enable a faster and easier microsegmentation experience."}),"\n",(0,t.jsx)(i.h3,{id:"security-domains",children:"Security domains"}),"\n",(0,t.jsx)(i.p,{children:"Anyone implementing microsegmentation and zero-trust should first identify all the security domains that need to be secured, which is what you need to secure.\nA security domain could be any of the following:"}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.em,{children:"Clusters"}),": The cluster can be considered a security domain."]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.em,{children:"Tenants"}),": Each tenant can be considered a separate security domain.\nA tenant may be comprised of a team or individuals that share the same Kubernetes infrastructure.\nIt is a collection of applications or namespaces for which a specific security declaration is enforced."]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.em,{children:"Namespaces"}),": Microservices that make up an application are typically organized into a single namespace and can be treated as separate security domains.\nFor example, you can consider protecting an application from other applications in the cluster or the same tenant."]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.em,{children:"Endpoints"})," A microservice comprises endpoint groups such as Deployment, StatefulSet, and DaemonSet resources.\nMicroservices, even in the same namespace, must be protected from each other to limit exposure if one is compromised.\nFor example, consider a frontend and a backend microservice in the same namespace.\nThey are in separate security domains and must be protected by network policies."]}),"\n",(0,t.jsx)(i.p,{children:(0,t.jsx)(i.img,{alt:"Security domains",src:n(1790).A+"",width:"3612",height:"2292"})}),"\n",(0,t.jsx)(i.h3,{id:"calicos-enhanced-network-policy-capabilities",children:"Calico's enhanced network policy capabilities"}),"\n",(0,t.jsx)(i.p,{children:"Successful segmentation is achieved by implementing network policies that secure security domains at the correct granularity depending on an organization's security posture or compliance requirements."}),"\n",(0,t.jsx)(i.p,{children:"Calico\u2019s network policies provide a richer set of policy capabilities than standard Kubernetes network policies.\nCalico's network policies include:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:"policy ordering/priority"}),"\n",(0,t.jsx)(i.li,{children:"deny rules"}),"\n",(0,t.jsx)(i.li,{children:"more flexible match rules"}),"\n",(0,t.jsx)(i.li,{children:"applicable to multiple endpoints (pods, VMs, and host interfaces)."}),"\n"]}),"\n",(0,t.jsxs)(i.p,{children:["There is a more detailed list of Calico network policy features available ",(0,t.jsx)(i.a,{href:"/calico/latest/network-policy/get-started/calico-policy/calico-network-policy#features",children:"here"}),".\nThe Kubernetes documentation outlines what network policies ",(0,t.jsx)(i.a,{href:"https://kubernetes.io/docs/concepts/services-networking/network-policies/",children:"do"})," and ",(0,t.jsx)(i.a,{href:"https://kubernetes.io/docs/concepts/services-networking/network-policies/#what-you-can-t-do-with-network-policies-at-least-not-yet",children:"do not"})," support."]}
1),"\n",(0,t.jsxs)(i.p,{children:["Project Calico integration with Istio providers application security, and service mesh.\nThis integration enables layers 5\u20137 network policy match criteria, end-to-end mTLS encryption, and cryptographic identity.\nFor more information, read ",(0,t.jsx)(i.a,{href:"https://www.tigera.io/blog/how-to-build-a-service-mesh-with-istio-and-calico/",children:"this blog"})," to learn how to integrate Kubernetes RBAC and Calico to achieve shift-left security."]}),"\n",(0,t.jsx)(i.p,{children:"Calico network policies are:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.em,{children:"Declarative"})," - define security intentions in YAML files (or by creating a policy from the Calico Cloud or the web console)"]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.em,{children:"Label-based"})," - network policies apply to endpoints based on workload identity using label selectors.\nThese can be combined into larger expressions using multiple operators and parentheses."]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.em,{children:"Dynamic"})," - network policies are tightly coupled with workloads based on their identity, not ever-changing IP addresses"]}),"\n"]}),"\n",(0,t.jsx)(i.p,{children:(0,t.jsx)(i.img,{alt:"Network policy anatomy",src:n(60652).A+"",width:"4484",height:"2204"})}),"\n",(0,t.jsx)(i.p,{children:"All Calico products support label-based policies that can be applied to either a namespace or cluster-wide (global) scope."}),"\n",(0,t.jsx)(i.p,{children:"By default, if no policies exist, then all ingress and egress traffic is allowed to and from pods in that namespace."}),"\n",(0,t.jsx)(i.h3,{id:"default-deny",children:"Default deny"}),"\n",(0,t.jsxs)(i.p,{children:["In Kubernetes, the default allows all traffic, unless policies apply to it.\nTherefore, we recommend creating a ",(0,t.jsx)(i.a,{href:"/calico/latest/network-policy/get-started/kubernetes-default-deny",children:"default deny"})," policy for your Kubernetes pods.\nThis guarantees that if no other policy is defined that explicitly allows traffic to/from a pod, then the traffic will be denied."]}),"\n",(0,t.jsx)(i.p,{children:"Note that an implicit default deny policy always occurs last.\nIf any other policy allows the traffic, then the deny does not come into effect.\nThe deny is executed only after all other policies are evaluated."}),"\n",(0,t.jsx)(i.p,{children:"A global default deny policy avoids needing to define a policy every time a namespace is created.\nIt also forces tenants of the cluster to define a network policy for every new pod.\nHowever, ensure you have the correct allow policies in place to ensure control plane traffic does not get blocked."}),"\n",(0,t.jsx)(i.h3,{id:"additional-functionality-with-calico-enterprise-and-calico-cloud",children:"Additional functionality with Calico Enterprise and Calico Cloud"}),"\n",(0,t.jsx)(i.p,{children:"Calico Enterprise and Calico Cloud extend network policy capabilities and usability to support hierarchical tiered network policy, automatic network policy recommendations (including automatic namespace isolation) based on existing flows, and integrations with third party firewalls.\nNetwork policies can be viewed and managed through a user interface, with the ability to stage and preview policy impact before enforcement."}),"\n",(0,t.jsxs)(i.p,{children:["To achieve something similar to tiers, Project Calico users may want to read this ",(0,t.jsx)(i.a,{href:"https://www.tigera.io/blog/how-to-integrate-kubernetes-rbac-and-calico-to-achieve-shift-left-security/",children:"blog"}),"."]}),"\n",(0,t.jsx)(i.p,{children:"This enables users to manage policies at scale, leading to more efficient management and implementation of a microsegmentation strategy."}),"\n",(0,t.jsx)(i.p,{children:"The diagram below shows an example of how policies for different security domains are grouped and organized into tiers with Calico Cloud or Enterprise."}),"\n",(0,t.jsx)(i.p,{children:(0,t.jsx)(i.img,{alt:"Tiers",src:n(46140).A+"",width:"6248",height:"3808"})}),"\n",(0,t.jsx)(i.h4,{id:"global-network-policies",children:"Global network policies"}),"\n",(0,t.jsxs)(i.p,{children:["Calico supports global network policy ",(0,t.jsx)(i.co
1de,{children:"kind: GlobalNetworkPolicy"}),"; a non-namespaced resource containing rules which are applied to any endpoints (pods, VMs, host interfaces) that match a selector.\nNetwork policy is a namespaced resource that only applies to workload endpoint resources (pods, containers, VMs) within that namespace.\nGlobal policies are beneficial in reducing the number of policies that need to be written and managed by targeting assets that span across a cluster or multiple namespaces. An example of this might be creating one default deny policy instead or one policy that allows communication to system services, like kube-dns. The alternative would be using Kubernetes network policies and duplicating policies for each namespace within the cluster."]}),"\n",(0,t.jsx)(i.h4,{id:"network-policy-management",children:"Network policy management"}),"\n",(0,t.jsx)(i.p,{children:"Network policy can quickly become complex and hard to manage.\nThere are a number of tools that make it easier to understand what your policies are doing and help you make adjustments."}),"\n",(0,t.jsx)(i.h5,{id:"policy-ordering",children:"Policy ordering"}),"\n",(0,t.jsxs)(i.p,{children:["In Calico, you can use the order field (with precedence from the lowest value to highest) to control how policies are applied and evaluated.\nDefining policy order is important when you include both ",(0,t.jsx)(i.code,{children:"action: allow"})," and ",(0,t.jsx)(i.code,{children:"action: deny"})," rules that may apply to the same endpoint."]}),"\n",(0,t.jsxs)(i.p,{children:["In Calico, you can use the order field (with precedence from the lowest value to highest) to control how policies are applied and evaluated.\nDefining policy order is important when you include both ",(0,t.jsx)(i.code,{children:"action: allow"})," and ",(0,t.jsx)(i.code,{children:"action: deny"})," rules that apply to the same endpoint."]}),"\n",(0,t.jsx)(i.p,{children:"If no network policies apply to a pod, then all traffic to that pod is allowed."}),"\n",(0,t.jsx)(i.p,{children:"If one or more network policies apply to a pod containing ingress rules, then only the ingress traffic specifically allowed by those policies is allowed."}),"\n",(0,t.jsx)(i.p,{children:"If one or more network policies apply to a pod containing egress rules, then only the egress traffic specifically allowed by those policies is allowed."}),"\n",(0,t.jsx)(i.h5,{id:"policy-tiers",children:"Policy tiers"}),"\n",(0,t.jsx)(i.p,{children:"Calico Cloud and Calico Enterprise allow hierarchical grouping of policies into tiers.\nPolicy tiers allow enforcement of higher-precedence policies that cannot be circumvented by other teams.\nPolicy tiers are evaluated based on order, as are policies within each tier.\nGraphically, policies are evaluated from left to right, top to bottom.\nRBAC for each tier can be defined to restrict who can interact with each tier."}),"\n",(0,t.jsx)(i.p,{children:"While Calico Open Source does not support policy tiers, you can use RBAC to control how different users can shape cluster security."}),"\n",(0,t.jsx)(i.h5,{id:"staged-policies",children:"Staged policies"}),"\n",(0,t.jsx)(i.p,{children:"These rules are used to preview network behavior and do not enforce network traffic, and can be applied to both network or global policies."}),"\n",(0,t.jsx)(i.p,{children:"Staged policies let you test the traffic impact of the policy as if it were enforced, but without changing traffic flow.\nYou can also preview the impacts of a staged policy on existing traffic.\nBy verifying that correct flows are allowed and denied before enforcement, you can minimize misconfiguration and potential network disruption."}),"\n",(0,t.jsx)(i.h2,{id:"implementing-microsegmentation-with-network-policies",children:"Implementing microsegmentation with network policies"}),"\n",(0,t.jsx)(i.p,{children:"To implement microsegmentation, you should follow a structured and repeatable approach to increase the likelihood of success.\nThese can be summarized as four broad steps:"}),"\n",(0,t.jsxs)(i.ol,{children:["\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.a,{href:"./microsegmentation#identify-your-security-domains",children:"Identify the security domains"})," for which microsegmentation will be enforced, who will be responsible for them, and who or which services need access to those security domains."]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.a,{href:"./microsegmentation#develop-a-policy-framework",children:"Define a policy"})," model using documented microservice communication for your applications or by analyzing traffic flows.\nWhen defining policies you should also consider the scope of the policies (global or namespace), who will be writing and applying the policies, and policy order (or tiers)."]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.a,{href:"./microsegmentation#deploy-network-policies",children:"Author and deploy network policies"}),".\nOnce all the correct allow policies are in place, stage a ",(0,t.jsx)(i.a,{href:"./microsegmentation#enforce-a-default-deny-policy",children:"default deny policy"}),".\nYou may want to identify a low-impact application or security domain first to understand and evaluate the process before prioritizing segmentation of critical security domains."]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.a,{href:"./microsegmentation#monitor-and-fine-tune-your-policies",children:"Re-assess any flows"})," or new applications that may require policy remediation before enforcing a default-deny.\nIn Calico Open Source, where staged policies are not supported, enforce a default deny in a staging environment to correct any policies prior to enforcing in production."]}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(i.h3,{id:"identify-your-security-domains",children:"Identify your security domains"}),"\n",(0,t.jsxs)(i.p,{children:["When identifying security domains or applications to secure, you may also want to consider compliance requirements and how critical your applications are.\nFor more information on meeting compliance requirements beyond microsegmentation, review one of our ",(0,t.jsx)(i.a,{href:"https://www.tigera.io/resources/?_sft_types=white-paper&_sft_Resource_Topics=compliance",children:"white papers"}),".\nThis will be unique to your organizational requirements, security posture, and risk tolerance."]}),"\n",(0,t.jsx)(i.p,{children:"An organization should know if they have critical applications that require a strong security posture, where the effort to protect outweighs the risk of having an application compromised.\nThis will require a more fine-grained security approach and might need policies in place for multiple security domains: cluster, tenants, namespaces, and workloads.\nIn a low-risk environment that doesn't contain critical or sensitive data, you may determine that namespace or tenant security domain isolation is sufficient."}),"\n",(0,t.jsx)(i.p,{children:"Starting with a low-risk implementation in a staging environment allows you to de-risk the process before applying it to business-critical security domains."}),"\n",(0,t.jsx)(i.p,{children:"Things you should consider:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:"Compliance requirements"}),"\n",(0,t.jsx)(i.li,{children:"Vulnerability or susceptibility to attack"}),"\n",(0,t.jsx)(i.li,{children:"Organizational security posture (zero-trust will require more stringent segmentation)"}),"\n",(0,t.jsx)(i.li,{children:"Importance of applications or security domains"}),"\n"]}),"\n",(0,t.jsx)(i.h3,{id:"develop-a-policy-framework",children:"Develop a policy framework"}),"\n",(0,t.jsx)(i.p,{children:"Once the security domains are identified, you should start designing and developing your network policies.\nWork from the highest-level policies (broadest scope) to the lowest level, more fine-grained policies.\nIn Calico Enterprise or Calico Cloud, it will be easier to think in tiers, and design policies tier-by-tier, from left to right across the policy board.\nThe left-hand side of the board contains tiers and policies with higher precedence that apply to the cluster or platform, or a broad subset of assets within them.\nAs you move right across the policy board, tiers should focus on specific namespaces or applications and the network policies will reflect that."}),"\n",(0,t.jsx)(i.p,{children:"Refer to this diagram as a skeleton framework for developing a policy framework:"}),"\n",(0,t.jsx)(i.p,{children:(0,t.jsx)(i.img,{alt:"Tiers",src:n(46140).A+"",width:"6248",height:"3808"})}),"\n",(0,t.jsx)(i.p,{children:"Before you can write the network policies, you will need to know how to target specific assets (labels, service accounts or namespaces) and what rules to write (based on cluster traffic):"}),"\n",(0,t.jsx)(i.h4,{id:"analyze-cluster-traffic",children:"Analyze cluster traffic"}),"\n",(0,t.jsx)(i.p,{children:"To define a network policy model, you need to know what the expected communication is within a security domain and design policies to protect those domains.\nYou may need to consider:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-best-practices#use-global-network-policy-only-when-all-rules-apply-globally",children:"Will you use global or namespaced policies?"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/hosts/",children:"Do you need to protect hosts (and configure that)?"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-best-practices#determine-who-can-write-policy",children:"Who is responsible for defining policies for different security domains?"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-tiers/policy-tutorial-ui#policy-ordering",children:"What order should policies be applied in?"})}),"\n",(0,t.jsxs)(i.li,{children:["Policy ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-tiers/policy-tutorial-ui#tiers",children:"tiers"}),", for Calico Cloud or Calico Enterprise users."]}),"\n"]}),"\n",(0,t.jsx)(i.p,{children:"Policy models may be easier to produce if an application has documentation stating how microservices communicate over which protocols and ports.\nA \u2018shift left\u2019 approach also puts the onus on individuals or developers who are more familiar with communication dependencies and can define accurate policy."}),"\n",(0,t.jsx)(i.p,{children:"If you\u2019re using Calico Open Source and struggling to analyze traffic flows, you may find it easier to install a text scraping tool (such as Fluent Bit) and pass log information to a text processing application (such as Elastic).\nThis lets you see layer 2-3 logs and build policies based on that information."}),"\n",(0,t.jsxs)(i.p,{children:["Calico Cloud and Enterprise users have multiple tools available to analyze flows:\n",(0,t.jsx)(i.a,{href:"/calico-cloud/tutorials/calico-cloud-features/tour#service-graph",children:"Dynamic Service and Threat Graph"})," is a topographical visualization of workload communication.\nThrough this feature, you can access flow logs that show metadata for source and destination endpoints, as well as any policies that apply to the flow and the outcome.\n",(0,t.jsx)(i.a,{href:"/calico-cloud/tutorials/calico-cloud-features/tour#service-graph",children:"Flow Visualization"})," shows volumetric flow data within the cluster in a 360\u2019 view.\nFlowViz, in addition to Service Graph, allows users to see what flows exist within a cluster or namespace, metadata and selectors associated with endpoints and any applied policies.\n",(0,t.jsx)(i.a,{href:"/calico-cloud/tutorials/calico-cloud-features/tour#logs",children:"Elasticsearch and Kibana"})," are included with ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/observability/kibana",children:"Calico Cloud"})," and ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/observability/kibana",children:"Calico Enterprise"})," that enables users to explore Elasticsearch logs and gain insights into workload communication traffic volume, performance, and other key aspects of cluster operations.\nLog data is also summarized in custom dashboards."]}),"\n",(0,t.jsx)(i.h4,{id:"label-your-assets",children:"Label your assets"}),"\n",(0,t.jsx)(i.p,{children:"As network policies are identity-aware, it is likely assets within a cluster will be targeted using labels.\nAdditionally, Calico global network policies can target service accounts or namespaces.\nAs such, before authoring any policies, ensure all assets are appropriately labeled so that policy selectors can target the correct assets at the right level of segmentation."}),"\n",(0,t.jsx)(i.p,{children:"In an example applying microsegmentation to a demo storefront, every pod within a hipstershop namespace is labeled with a compliance label in addition to an 'app' label denoting what service the pod is.\nThis allows for multiple policies. One network policy could be designed, allowing communication between all pods with a generalized label. Other network policies could be created for each workload, using the 'app' label to target specific workloads and create fine-grained ingress and egress rules.\nThis allows flexibility in the approach to microsegmentation depending on which security domains need protecting."}),"\n",(0,t.jsx)(i.p,{children:"When designing and applying labels, you should:"}),"\n",(0,t.jsxs)(i.ol,{children:["\n",(0,t.jsx)(i.li,{children:"Integrate label design into the identification step, creating a hierarchical design that aligns with security domains."}),"\n",(0,t.jsx)(i.li,{children:"Use label prefixes for classification to create a standardized approach depen
1ding on the security domain.\nConsider prefixing labels with the intended security domain, and designing appropriate key/value pairs that accurately represent the tenant, application, namespace, or endpoint."}),"\n",(0,t.jsxs)(i.li,{children:["Don't use reserved label keys, such as ",(0,t.jsx)(i.code,{children:"kubernetes"}),", ",(0,t.jsx)(i.code,{children:"tigera"})," or ",(0,t.jsx)(i.code,{children:"calico"}),"."]}),"\n",(0,t.jsx)(i.li,{children:"If using a CI/CD pipeline, ensure the right labels are being applied and set up label governance checks.\nThis will ensure new deployments are appropriately secured from the beginning."}),"\n"]}),"\n",(0,t.jsx)(i.p,{children:(0,t.jsx)(i.a,{href:"https://www.helpnetsecurity.com/2021/05/26/kubernetes-security/",children:"More information is available on labeling best practices."})}),"\n",(0,t.jsx)(i.h4,{id:"write-your-policies",children:"Write your policies"}),"\n",(0,t.jsx)(i.p,{children:"The previous steps should set you up for success when creating policies because you will know exactly what policies need to be created, with what order and tier, and what labels to use as selectors."}),"\n",(0,t.jsxs)(i.p,{children:["Before you write any policies, you may want to review the best practices for network policies in: ",(0,t.jsx)(i.a,{href:"/calico/latest/about/kubernetes-training/about-network-policy#best-practices-for-network-policies",children:"Calico Open Source"}),", ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-best-practices#policy-best-practices-for-day-one-zero-trust",children:"Calico Enterprise"}),", ",(0,t.jsx)(i.a,{href:"/calico-cloud/tutorials/training/about-network-policy#best-practices-for-network-policies",children:"Calico Cloud"}),"."]}),"\n",(0,t.jsxs)(i.p,{children:["To make policy writing easier and faster, Calico Enterprise and Calico Cloud have several features you may want to consider:\nGraphical Policy Editor: ",(0,t.jsx)(i.a,{href:"/calico-cloud/network-policy/policy-tiers/policy-tutorial-ui#create-a-network-policy",children:"Calico Cloud"})," and ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-tiers/policy-tutorial-ui#create-a-network-policy",children:"Calico Enterprise"})," have a \u2018Create Policy\u2019 GUI to create, edit, and delete policies.\nPolicies that have been created in the GUI can be downloaded as YAML."]}),"\n",(0,t.jsxs)(i.p,{children:["DNS Policies: ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/beginners/policy-rules/external-ips-policy",children:"If you need to limit traffic to/from external non-Calico workloads or networks, you can use external IPs or network rules."})]}),"\n",(0,t.jsxs)(i.p,{children:["Automatic policy recommendations: Calico Cloud and Calico Enterprise also support ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/recommendations/policy-recommendations",children:"automatic policy recommendations"})," that automatically generate network policy to isolate namespaces.\nPolicy recommendations can also be generated for specific namespaces or workloads for a more granular segmentation strategy.\nPolicy Recommendations makes it easier and faster for platform operators to implement namespace isolation at scale or without experience in authoring network policies or detailed knowledge of how application workloads are communicating.\nCalico analyzes the flow logs that are generated from workloads, and automatically recommends and stages policies for each namespace that can be used for isolation.\nAll recommended polices are staged by default.\nThis allows you to preview the impact of a policy without impacting traffic flow, to assess the effectiveness of a policy, or to evaluate any unintended side-effects.\n",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/recommendations/policy-recommendations#activate-and-review-policy-recommendations",children:"Policy recommendations need to be enabled"})," per cluster and may take time to learn and analyze flows before providing recommendations."]}),"\n",(0,t.jsx)(i.p,{children:"All versions of Calico support both Kubernetes network policy and Calico network policy."}),"\n",(0,t.jsx)(i.h3,{id:"deploy-network-policies",children:"Deploy network policies"}),"\n",(0,t.jsx)(i.p,{children:"In all products, policies can be applied using the CLI.\nPolicies created in the web console for Calico Enterprise or Calico can be staged or enforced through the UI.\nYou can check whether policies have been applied by running the following commands:"}
1),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-bash",children:"kubectl get networkpolicy\nkubectl describe networkpolicy <networkpolicy-name>\n"})}),"\n",(0,t.jsx)(i.p,{children:"or"}),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-bash",children:"kubectl get globalnetworkpolicy\nkubectl describe globalnetworkpolicy <globalnetworkpolicy-name>\n"})}),"\n",(0,t.jsx)(i.p,{children:"When applying network policies, you will need to apply policies in such an order that it does not impact applications.\nCalico network policy supports policy ordering when traffic is being evaluated.\nCalico Enterprise and Calico Cloud also support hierarchical policy tiers."}),"\n",(0,t.jsxs)(i.p,{children:["With ",(0,t.jsx)(i.a,{href:"/calico/latest/network-policy/get-started/calico-policy/calico-network-policy#apply-network-policies-in-specific-order",children:"Calico Open Source"})," you may want to define the policy order in the policy spec in addition to applying policies in the correct order."]}),"\n",(0,t.jsx)(i.p,{children:"Calico Enterprise and Calico Cloud feature hierarchical tiers that are visible on the policies board.\nAny applied policies, both staged and enforced, are visible on the policies board in the correct order."}),"\n",(0,t.jsxs)(i.p,{children:["It is important to understand how ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/network-policy/policy-tiers/tiered-policy#policy-endpoint-matching-across-tiers",children:"policy endpoints match across tiers"}),"."]}),"\n",(0,t.jsxs)(i.ol,{children:["\n",(0,t.jsx)(i.li,{children:"Apply policies by any method.\nStart with general policies that target broad security domains."}),"\n",(0,t.jsx)(i.li,{children:"Verify policies are working as intended before you apply narrower policies, such as those at the application or workload level."}),"\n",(0,t.jsx)(i.li,{children:"Ensure policies allow communication to critical services and control plane services (such as kube-dns)."}),"\n",(0,t.jsx)(i.li,{children:"Confirm that policies exist in the correct order by using CLI tools or the web console's policy board."}),"\n",(0,t.jsx)(i.li,{children:"Enforce any staged policies."}),"\n"]}),"\n",(0,t.jsx)(i.h3,{id:"enforce-a-default-deny-policy",children:"Enforce a default deny policy"}),"\n",(0,t.jsx)(i.p,{children:"The default behavior in Kubernetes is to allow all communication that isn't restricted by a network policy.\nA default deny policy ensures that unwanted traffic (ingress and egress) is denied by default.\nYou must create policies to allow traffic to your pods and services.\nPods without a policy (or that have an incorrect policy) are blocked from all network traffic until an appropriate network policy is defined."}),"\n",(0,t.jsx)(i.p,{children:"Note that Calico global network policies are not namespaced.\nThey affect all pods that match the policy selector.\nIn contrast, Kubernetes network policies are namespaced\nTo achieve the same effect, you would need to create a default deny policy for every namespace in your cluster."}),"\n",(0,t.jsx)(i.p,{children:"This also comes with the warning that you need to ensure the default deny does not target system pods that are critical to cluster integrity.\nThe following policy correctly excludes system pods from the global deny rule:"}),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-yaml",children:'apiVersion: projectcalico.org/v3\nkind: GlobalNetworkPolicy\nmetadata:\n name: deny-app-policy\nspec:\n namespaceSelector: has(projectcalico.org/name) && projectcalico.org/name not in {"kube-system", "calico-system", "tigera-system"}\n types:\n - Ingress\n - Egress\n egress:\n # allow all namespaces to communicate to DNS pods\n - action: Allow\n protocol: UDP\n destination:\n selector: \'k8s-app == "kube-dns"\'\n ports:\n - 53\n - action: Allow\n protocol: TCP\n destination:\n selector: \'k8s-app == "kube-dns"\'\n ports:\n - 53\n'})}),"\n",(0,t.jsx)(i.p,{children:"Calico Enterprise and Calico Cloud have a 'hidden' tier that contains policies to secure Calico components that have precedence over any user-created policies or tiers.\nTo ensure your cluster continues to work correctly, don't modify or circumvent these policies."}),"\n",(0,t.jsx)(i.p,{children:(0,t.jsx)(i.a,{href:"/calico/latest/network-policy/get-started/kubernetes-default-deny",children:"Calico Open Source: Enable default deny for Kubernetes pods"})}),"\n",(0,t.jsxs)(i.p,{children:["In Calico Cloud and Calico Enterprise the ",(0,t.jsx)(i.a,{href:"/calico-enterprise/latest/reference/resources/stagednetworkpolicy",children:"staging policy"})," tool will help you find incorrect and missing policies\nA global deny rule helps mitigate other lateral malicious attacks."]}),"\n",(0,t.jsx)(i.p,{children:"We recommend that you create a global default deny policy after you complete writing policy for the traffic that you want to allow.\nUse the staged policy feature to get your allowed traffic working as expected, and then lock down the cluster to block unwanted traffic.\nThe following steps summarize best practice:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:"Create a staged global default deny policy.\nIt will show all the traffic that would be blocked if it were converted into an enforced deny policy."}),"\n",(0,t.jsx)(i.li,{children:"Create other network policies to individually allow the traffic shown as blocked, until no connections are denied."}),"\n",(0,t.jsx)(i.li,{children:"Convert the staged global network policy to an enforced policy."}),"\n"]}),"\n",(0,t.jsx)(i.p,{children:"Steps to an enforced default-deny posture:"}),"\n",(0,t.jsxs)(i.ol,{children:["\n",(0,t.jsx)(i.li,{children:"Create your allow policies.\nYou can't predict everything, but try to get as much of this in place as you can."}),"\n",(0,t.jsxs)(i.li,{children:["Create a default deny policy.\nIf globally scoped, create one policy.\nFor namespace-scoped default deny policies, create one policy per namespace.","\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["In Calico Enterprise or Calico Cloud, stage the default deny policy either through the UI or by setting ",(0,t.jsx)(i.co
1de,{children:"kind: StagedGlobalNetworkPolicy"})," or ",(0,t.jsx)(i.code,{children:"kind: StagedNetworkPolicy"}),"."]}),"\n",(0,t.jsxs)(i.li,{children:["In Calico Open Source, you should apply the default deny policy in a non-production environment first.\nYou may optionally include a ",(0,t.jsx)(i.a,{href:"/calico/latest/reference/resources/networkpolicy#rule",children:"'log' action"})," and have flows that are evaluated by the default deny recorded in the syslog."]}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(i.li,{children:"Simulate your application or services.\nValidate all policies are working as intended, and there are no issues with the application or service."}),"\n",(0,t.jsx)(i.li,{children:"Once everything is validated, the default deny policy can be enforced or applied in a production environment."}),"\n"]}),"\n",(0,t.jsx)(i.h3,{id:"monitor-and-fine-tune-your-policies",children:"Monitor and fine-tune your policies"}),"\n",(0,t.jsx)(i.p,{children:"After you have policies in place, you can actively monitor traffic and performance to make sure your policies are behaving as you expect."}),"\n",(0,t.jsx)(i.p,{children:"There are a few ways to monitor and review whether your policies are effective."}),"\n",(0,t.jsx)(i.h4,{id:"review-the-policies-board",children:"Review the policies board"}),"\n",(0,t.jsx)(i.p,{children:"In Calico Cloud and Calico Enterprise, the policies board is the first place to look for misconfigurations.\nFrom here, you can spot policies that are denying traffic or that have no endpoints assigned to them."}),"\n",(0,t.jsx)(i.h4,{id:"use-observability-tools",children:"Use observability tools"}),"\n",(0,t.jsxs)(i.p,{children:["Calico Enterprise and Calico Cloud have tools that help you visually identify misconfigured policies\nThese include Service Graph, FlowViz, and the policy board.\nCommercial Calico products also include Kibana as a frontend for ElasticSearch.\nThis provides richer functionality for dashboards and logs.\nFor an in-depth demonstration, see ",(0,t.jsx)(i.a,{href:"https://fast.wistia.com/embed/channel/lhjf79y3oy?wchannelid=lhjf79y3oy",children:"this video series"}),"."]}),"\n",(0,t.jsx)(i.h4,{id:"test-connectivity-with-test-pods",children:"Test connectivity with test pods"}),"\n",(0,t.jsx)(i.p,{children:"One way to test connectivity is to deploy test pods in different security domains and see whether they can connect to one another.\nYou can label these pods to mimic other services and trigger specific policies.\nWhen the pods are deployed, you can use tools such as curl or netcat to check that connectivity is working as expected."}),"\n",(0,t.jsx)(i.p,{children:"The response can be used to determine if a network policy is correctly denying or allowing traffic to pass through, and this can be used in conjunction with flow logs or observability."}),"\n",(0,t.jsx)(i.h4,{id:"read-the-logs",children:"Read the logs"}),"\n",(0,t.jsx)(i.p,{children:"Calico supports a log action for its network policies.\nCalico Enterprise and Calico Cloud can collect a wide range of logs that can be used to investigate flows and validate policies."}),"\n",(0,t.jsx)(i.h4,{id:"simulate-your-application-or-service",children:"Simulate your application or service"}),"\n",(0,t.jsx)(i.p,{children:"Using and testing the deployed application and a wide range of its functionality should show whether there are any issues after deploying and enforcing network policies."}),"\n",(0,t.jsx)(i.p,{children:"If you need to create new policies or edit existing policies, refer to the sections above."})]})}function p(e={}){let{wrapper:i}={...(0,a.R)(),...e.components};return i?(0,t.jsx)(i,{...e,children:(0,t.jsx)(d,{...e})}):d(e)}},60652:function(e,i,n){n.d(i,{A:()=>o});let o=n.p+"assets/images/anatomy-of-policy-82b38fe7e1e404d54458315214ef8182.png"},1790:function(e,i,n){n.d(i,{A:()=>o});let o=n.p+"assets/images/security-domains-cf88b974bcea28c57bd45a8a2fb8650d.png"},46140:function(e,i,n){n.d(i,{A:()=>o});let o=n.p+"assets/images/security-policy-framework-02239e8357a746558fb2d107e080778c.png"},17869:function(e,i,n){n.d(i,{R:()=>r,x:()=>s});var o=n(82645);let t={},a=o.createContext(t);function r(e){let i=o.useContext(a);return o.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function s(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:r(e.components),o.createElement(a.Provider,{value:i},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.