Safety & Security · Data artifact
Pod Network Policy
Data artifactSafety & SecuritySafety, Security & Governancearc:PodNetworkPolicy
A declarative firewall rule set specifying allowed ingress and egress traffic between workloads by label and namespace.
Responsibility. Restricts which components may communicate with each other.
Also known as: Network policy, Network egress allow-list, Default-deny network policy
Relationships
constrains control
- Cluster Namespace Ch9.3
- Execution Sandbox abstract Ch9.3
- Gossip Membership Service Ch6.2B
- Vector Index Store abstract Ch4.3
- Worker Agent abstract Ch4.3
Design guidance
- SHOULD allow vector databases to accept connections only from authorised agent pods.
- SHOULD restrict cluster-gossip traffic to internal networks, separating it from data-replication and client ports.
- MUST start sandboxes with zero network connectivity and allow-list specific destinations (host, port) incrementally.
- MUST NOT isolate the filesystem while leaving network connectivity unrestricted.
Classification
- Patterns
- Default-deny segmentationDefault-deny egressDestination allow-listingCross-namespace isolation
- Technologies
- Kubernetes NetworkPolicy
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)
- Risks mitigated
- Unrestricted pod-to-pod lateral movementUnauthorized vector database accessWorker agents initiating external connectionsData exfiltrationMalware downloadCommand-and-control channelsNetwork reconnaissance
Sources
- Ch4.3: T. Nguyen, "Container Orchestration and Edge Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.3. ISBN: 9798244538229.
- Ch6.2B: T. Nguyen, "Production Vector Database Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 6.2B. ISBN: 9798244538229.
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.