Safety & Security · Data artifact

Pod Network Policy

Data artifactSafety & SecuritySafety, Security & Governancearc:PodNetworkPolicy

A declarative firewall rule set specifying allowed ingress and egress traffic between workloads by label and namespace.

Responsibility. Restricts which components may communicate with each other.

Also known as: Network policy, Network egress allow-list, Default-deny network policy

constrainsconstrainsconstrainsconstrainsconstrainsWorker Agent: constrainsWorker AgentVector Index Store: constrainsVector Index StoreExecution Sandbox: constrainsExecution SandboxGossip Membership Service: constrainsGossip Membership ServiceCluster Namespace: constrainsCluster Namespace
Direct neighbourhood (hover for relationship types)

Relationships

constrains control

Design guidance

Classification

Patterns
Default-deny segmentationDefault-deny egressDestination allow-listingCross-namespace isolation
Technologies
Kubernetes NetworkPolicy
Quality attributes
Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)
Risks mitigated
Unrestricted pod-to-pod lateral movementUnauthorized vector database accessWorker agents initiating external connectionsData exfiltrationMalware downloadCommand-and-control channelsNetwork reconnaissance

Sources

  1. Ch4.3: T. Nguyen, "Container Orchestration and Edge Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.3. ISBN: 9798244538229.
  2. Ch6.2B: T. Nguyen, "Production Vector Database Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 6.2B. ISBN: 9798244538229.
  3. Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.