1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["5194"],{65198:function(e,n,o){o.r(n),o.d(n,{frontMatter:()=>r,toc:()=>i,default:()=>d,metadata:()=>s,assets:()=>t,contentTitle:()=>l});var s=JSON.parse('{"id":"network-policy/policy-rules/namespace-policy","title":"Use namespace rules in policy","description":"Use namespaces and namespace selectors in Calico network policy to group or separate resources. Use network policies to allow or deny traffic to/from pods that belong to specific namespaces.","source":"@site/calico_versioned_docs/version-3.28/network-policy/policy-rules/namespace-policy.mdx","sourceDirName":"network-policy/policy-rules","slug":"/network-policy/policy-rules/namespace-policy","permalink":"/calico/3.28/network-policy/policy-rules/namespace-policy","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.28/network-policy/policy-rules/namespace-policy.mdx","tags":[],"version":"3.28","frontMatter":{"description":"Use namespaces and namespace selectors in Calico network policy to group or separate resources. Use network policies to allow or deny traffic to/from pods that belong to specific namespaces."},"sidebar":"calicoSidebar","previous":{"title":"Basic rules","permalink":"/calico/3.28/network-policy/policy-rules/policy-rules-overview"},"next":{"title":"Use service rules in policy","permalink":"/calico/3.28/network-policy/policy-rules/service-policy"}}'),a=o(37937),c=o(17869);let r={description:"Use namespaces and namespace selectors in Calico network policy to group or separate resources. Use network policies to allow or deny traffic to/from pods that belong to specific namespaces."},l="Use namespace rules in policy",t={},i=[{value:"Big picture",id:"big-picture",level:2},{value:"Value",id:"value",level:2},{value:"How to",id:"how-to",level:2},{value:"Control traffic to/from endpoints in a namespace",id:"control-traffic-tofrom-endpoints-in-a-namespace",level:3},{value:"Use Kubernetes RBAC to control namespace label assignment",id:"use-kubernetes-rbac-to-control-namespace-label-assignment",level:3},{value:"Additional resources",id:"additional-resources",level:2}];function p(e){let n={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,c.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(n.header,{children:(0,a.jsx)(n.h1,{id:"use-namespace-rules-in-policy",children:"Use namespace rules in policy"})}),"\n",(0,a.jsx)(n.h2,{id:"big-picture",children:"Big picture"}),"\n",(0,a.jsx)(n.p,{children:"Use Calico network policies to reference pods in other namespaces."}),"\n",(0,a.jsx)(n.h2,{id:"value",children:"Value"}),"\n",(0,a.jsx)(n.p,{children:"Kubernetes namespaces let you group/separate resources to meet a variety of use cases. For example, you can use namespaces to separate development, production, and QA environments, or allow different teams to use the same cluster. You can use namespace selectors in Calico network policies to allow or deny traffic to/from pods in specific namespaces."}),"\n",(0,a.jsx)(n.h2,{id:"how-to",children:"How to"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#control-traffic-tofrom-endpoints-in-a-namespace",children:"Control traffic to/from endpoints in a namespace"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#use-kubernetes-rbac-to-control-namespace-label-assignment",children:"Use Kubernetes RBAC to control namespace label assignment"})}),"\n"]}),"\n",(0,a.jsx)(n.h3,{id:"control-traffic-tofrom-endpoints-in-a-namespace",children:"Control traffic to/from endpoints in a namespace"}),"\n",(0,a.jsxs)(n.p,{children:["In the following example, ingress traffic is allowed to endpoints in the ",(0,a.jsx)(n.strong,{children:"namespace: production"})," with label ",(0,a.jsx)(n.strong,{children:"color: red"}),", and only from a pod in the same namespace with ",(0,a.jsx)(n.strong,{children:"color: blue"}),", on ",(0,a.jsx)(n.strong,{children:"port 6379"}),"."]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: NetworkPolicy\nmetadata:\n name: allow-tcp-6379\n namespace: production\nspec:\n selector: color == 'red'\n ingress:\n - action: Allow\n protocol: TCP\n source:\n selector: color == 'blue'\n destination:\n ports:\n - 6379\n"})}),"\n",(0,a.jsxs)(n.p,{children:["To allow ingress traffic from endpoints in other namespaces, use a ",(0,a.jsx)(n.strong,{children:"namespaceSelector"})," in the policy rule. A namespaceSelector matches one or more namespaces based on the labels that are applied on the namespace. In the following example, ingress traffic is also allowed from endpoints with ",(0,a.jsx)(n.strong,{children:"color: blue"})," in namespaces with ",(0,a.jsx)(n.strong,{children:"shape: circle"}),"."]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: NetworkPolicy\nmetadata:\n name: allow-tcp-6379\n namespace: production\nspec:\n selector: color == 'red'\n ingress:\n - action: Allow\n protocol: TCP\n source:\n selector: color == 'blue'\n namespaceSelector: shape == 'circle'\n destination:\n ports:\n - 6379\n"})}),"\n",(0,a.jsx)(n.h3,{id:"use-kubernetes-rbac-to-control-namespace-label-assignment",children:"Use Kubernetes RBAC to control namespace label assignment"}),"\n",(0,a.jsx)(n.p,{children:"Network policies can be applied to endpoints using selectors that match labels on the endpoint, the endpoint's namespace, or the endpoint's service account. By applying selectors based on the endpoint's namespace, you can use Kubernetes RBAC to control which users can assign labels to namespaces. This allows you to separate groups who can deploy pods from those who can assign labels to namespaces."}),"\n",(0,a.jsxs)(n.p,{children:["In the following example, users in the development environment can communicate only with pods that have a namespace labeled, ",(0,a.jsx)(n.code,{children:'environment == "development"'}),"."]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: GlobalNetworkPolicy\nmetadata:\n name: restrict-development-access\nspec:\n namespaceSelector: 'environment == \"development\"'\n ingress:\n - action: Allow\n source:\n namespaceSelector: 'environment == \"development\"'\n egress:\n - action: Allow\n destination:\n namespaceSelector: 'environment == \"development\"'\n"})}),"\n",(0,a.jsx)(n.h2,{id:"additional-resources",children:"Additional resources"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsxs)(n.li,{children:["For more network policies, see ",(0,a.jsx)(n.a,{href:"/calico/3.28/reference/resources/networkpolicy",children:"Network policy"})]}),"\n",(0,a.jsxs)(n.li,{children:["To apply policy to all namespaces, see ",(0,a.jsx)(n.a,{href:"/calico/3.28/reference/resources/globalnetworkpolicy",children:"Global network policy"})]}),"\n"]})]})}function d(e={}){let{wrapper:n}={...(0,c.R)(),...e.components};return n?(0,a.jsx)(n,{...e,children:(0,a.jsx)(p,{...e})}):p(e)}},17869:function(e,n,o){o.d(n,{R:()=>r,x:()=>l});var s=o(82645);let a={},c=s.createContext(a);function r(e){let n=s.useContext(c);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function l(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:r(e.components),s.createElement(c.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.