Kubernetes NetworkPolicy: firewall for Pods
By default, all Pods can talk to all Pods (flat network)—NetworkPolicy opts in to deny-by-default once you add policies (behavior depends on CNI). Policies select Pods with labels and define allowed ingress and egress (IP blocks, ports, namespace selectors). Start with namespace isolation and egress allowlists for databases.