Policy theo traffic matrix
Ghi source → destination → direction → protocol/port → expected result. Default deny chỉ là containment; allow ingress cho app từ frontend/Ingress, allow egress tới dependency và DNS. podSelector/namespaceSelector có scope; namespace labels là một phần của security boundary.
Test dataplane, không chỉ API
Kubernetes chấp nhận policy không có nghĩa CNI enforce. Test từ debug Pod đúng namespace/labels bằng curl/nc/nslookup, kiểm tra Service/EndpointSlice/app trước rồi CNI status/logs. Nếu egress deny, DNS thường là dependency cần allow riêng.
Bài tập
Tạo frontend/backend/db, traffic matrix, default deny, allow rules, test allow/deny và mô phỏng selector/port/DNS lỗi. Restore policy/labels, cleanup lab và ghi CNI limitation.