4.3.1 Use NetworkPolicy with built in GKE Dataplane V2 enforcement

Information

NetworkPolicy enforcement is built in for GKE Autopilot clusters through GKE Dataplane V2. Kubernetes NetworkPolicy objects can restrict Pod to Pod, Pod to Service, ingress, and egress traffic without enabling Calico or a separate NetworkPolicy add-on.

NetworkPolicies define pod level traffic rules, but enforcement depends on the networking implementation used by the cluster. In GKE Autopilot, GKE Dataplane V2 is enabled by default and provides built in Kubernetes NetworkPolicy enforcement. GKE Dataplane V2 uses Cilium and eBPF for routing, load balancing, and NetworkPolicy enforcement.

By default, pods in a cluster can communicate freely. Using NetworkPolicy in GKE Autopilot allows teams to implement defense in depth, namespace based segmentation, tenant isolation, and explicit ingress and egress controls for approved workload communication paths.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

For GKE Autopilot clusters, no remediation is required to enable NetworkPolicy enforcement because GKE Dataplane V2 is enabled by default and Kubernetes NetworkPolicy enforcement is built in. Remediation should focus on creating and maintaining NetworkPolicy resources that define the intended ingress and egress traffic rules for workloads.

-

Apply NetworkPolicy resources in the required namespaces to define explicit allowed traffic paths for approved workload communication.

-

Use default deny policies where appropriate, followed by explicit allow policies for required ingress and egress traffic.

-

Validate application connectivity after applying NetworkPolicy resources.

Impact:

Applying NetworkPolicy resources can change workload connectivity because traffic not explicitly allowed by policy might be denied. In GKE Autopilot, NetworkPolicy enforcement is built in through GKE Dataplane V2 and should not be separately enabled or disabled.

See Also

https://workbench.cisecurity.org/benchmarks/24958

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, CSCv7|14.1, CSCv7|14.2

Plugin: GCP

Control ID: ea2c9f3f2aa92ac0e42615457003099b608e3f059bd8e7ccb187fd5abef53517