You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure ACS集群中Azure NetworkPolicy未生效,如何实现Pod访问控制?

Hey there, let's figure out why your NetworkPolicy isn't working as expected with the Azure network policy plugin in your ACS Kubernetes cluster.

First, does the Azure Network Policy plugin support default-deny ingress rules?

Absolutely. The Azure network policy plugin (configured via networkPolicy: azure in your acs-engine template) fully supports the Kubernetes NetworkPolicy API, including default-deny rules for ingress traffic. So the functionality you're aiming for is definitely possible—we just need to iron out a few potential issues.

Common reasons your policy isn't working, and fixes:

1. Incorrect API version for your Kubernetes 1.9 cluster

Kubernetes 1.9 doesn't support the networking.k8s.io/v1 API version for NetworkPolicies—that version was only stabilized in Kubernetes 1.19. For 1.9, you need to use networking.k8s.io/v1beta1 instead. Using the wrong API version means your cluster won't recognize the policy at all.

Here's the corrected version of your default-deny ingress policy:

apiVersion: networking.k8s.io/v1beta1
kind: NetworkPolicy
metadata:
  name: default-deny-ingress
spec:
  podSelector: {}
  policyTypes:
  - Ingress

Apply this with kubectl apply -f your-policy.yaml -n your-namespace (replace your-namespace with the target namespace).

2. Verify the Azure Network Policy plugin is running

If the plugin isn't deployed or healthy, no NetworkPolicies will be enforced. Check the kube-system namespace for the policy manager pods:

kubectl get pods -n kube-system | grep azure-network-policy

You should see pods named azure-network-policy-manager-<node-name> in a Running state. If they're missing or in a failed state, your acs-engine deployment might have had an issue—double-check your cluster creation JSON and ensure the networkPolicy: azure setting was correctly applied during provisioning.

3. Validate the policy is working

After applying the corrected policy, test it with two pods in your target namespace:

  • Deploy an nginx pod: kubectl run nginx --image=nginx -n your-namespace
  • Spin up a temporary busybox pod to test access:
kubectl run busybox --rm -it --image=busybox -n your-namespace -- /bin/sh
# Inside the busybox shell, try to curl the nginx pod
curl nginx

If the curl times out or fails, your default-deny policy is working as expected. To allow specific traffic later, you can add additional NetworkPolicies that explicitly permit ingress to targeted pods.

Final Notes

The Azure network policy plugin supports all core NetworkPolicy features, including pod label selectors, namespace label selectors, port filtering, and both ingress/egress rules. As long as the plugin is healthy and your policy uses the correct API version for your cluster, you'll be able to control pod traffic as intended.

内容的提问来源于stack exchange,提问作者Sachin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:51:03