lacework-global-773
Enable Network Policy and set as appropriate (Automated)
Description
Use Network Policy to restrict pod to pod traffic within a cluster and segregate workloads.
Remediation
Using Google Cloud Console:
- Go to Kubernetes Engine by visiting: https://console.cloud.google.com/kubernetes/list.
- Select the cluster with Network policy disabled.
- Under the
details
pane, within theNetworking
section, click the pencil icon namedEdit network policy
. - Set
Network policy for control plane
toEnabled
. - Click
Save Changes
. - Once the cluster has updated, repeat steps 1-3.
- Set
Network Policy for nodes
toEnabled
. - Click
Save Changes
.
Using Command Line:
To enable Network Policy for an existing cluster, firstly enable the Network Policy add-on:
gcloud container clusters update <cluster_name> --zone <compute_zone> --update-addons NetworkPolicy=ENABLED
Then, enable Network Policy:
gcloud container clusters update <cluster_name> --zone <compute_zone> --enable-network-policy
References
https://cloud.google.com/kubernetes-engine/docs/how-to/network-policy