GKE clusters where Kubernetes NetworkPolicy is not enforced
What does ZopNight detect here?
GKE Standard clusters without Dataplane V2 are flagged at high severity when the legacy `networkPolicy` enforcement setting is disabled or missing. Google notes that by default every Pod can talk to every other Pod, and a NetworkPolicy object has no effect without an enforcer, so one compromised container can reach any service in the cluster.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-125 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | networkPolicy disabled or unset, with no Dataplane V2 or Autopilot |
| Source | ZopNight |
| Permissions used | container.clusters.list · container.clusters.get |
Where it applies
Flat Pod networking and what it allows
Out of the box, Kubernetes networking is flat. Google’s network policy guide says it directly: by default, all Pods within a cluster can communicate with each other freely. NetworkPolicy objects are how you write Pod-level firewall rules, but they are only rules on paper unless the cluster runs an enforcer. On GKE that is either GKE Dataplane V2, which Google recommends for all clusters and makes the default on Autopilot, or the Calico add-on on Standard clusters.
Without enforcement, a compromised front-end Pod can open connections to the database, other teams’ services and anything else inside the cluster network. That lateral movement is what a default-deny policy is meant to stop.
Telling enforced clusters from unenforced ones
gcloud container clusters list \ --format="table(name,location,networkPolicy.enabled,networkConfig.datapathProvider)"ADVANCED_DATAPATH in the last column means Dataplane V2, which enforces policy regardless of
the first flag. A cluster with neither is unenforced.
The setting behind a finding
ZopNight records the cluster’s network policy enforcement setting during inventory and fires when it reads disabled or finds no value recorded. There is no workload scan: the rule does not check whether any NetworkPolicy objects exist.
When it has nothing to say
Clusters on GKE Dataplane V2 (ADVANCED_DATAPATH), including all Autopilot clusters, count as
enforced and are silent. On other Standard clusters the legacy networkPolicy.enabled flag
decides, and a missing value counts as disabled. NetworkPolicy objects that exist but carry no
rules are a separate check:
NetworkPolicy Has No Rules.
Lateral-movement risk, $0 saving
No saving is attached. The value is containment: a breach stays with the Pod it started in instead of spreading across the cluster.
Enforcing network policy on a Standard cluster
- Enable the add-on on the control plane:
gcloud container clusters update CLUSTER_NAME --update-addons=NetworkPolicy=ENABLED. - Enable enforcement on the nodes:
gcloud container clusters update CLUSTER_NAME --enable-network-policy. - Add a default-deny NetworkPolicy per namespace, then allow the paths each service needs.
- For new clusters, create them with Dataplane V2 and skip the add-on entirely.