---
title: "Calico Network Policy Comes to Kubernetes"
source: "https://www.tigera.io/blog/calico-network-policy-comes-to-kubernetes/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Calico Network Policy Comes to Kubernetes

By [Casey Davenport](https://www.tigera.io/blog/author/caseydavenport/) on Aug 13, 2015 • 3 min read

## Calico Network Policy on Kubernetes

As you may know, Calico was designed from the ground up to support rich, flexible, and secure [network policy](http://docs.projectcalico.org/en/latest/security-model.html). We’ve been working to bring that policy to Kubernetes deployments, and the [latest Calico Kubernetes plugin](http://github.com/projectcalico/calico-kubernetes/releases) does just that, allowing namespace isolation at the network layer, and fine-grained security between your Kubernetes pods.

In tandem with this, we’d like to announce that Calico now supports acting in “policy-only” mode. This means you don’t need to use Calico networking to take advantage of Calico’s rich security policy enforcement.

Take a look at the demonstration video below to see Calico network policy in Kubernetes in action. The demo uses Calico’s policy-only mode to enforce network policy on a Kubernetes cluster running on the standard GCE cloud provider. Networking is still performed using GCE’s native routing, while Calico is simply enforcing security policy.

### How Does it Work?

#### Declaring Policy

We make use of the [annotation](http://github.com/GoogleCloudPlatform/kubernetes/blob/release-1.0/docs/user-guide/annotations.md) field on the [v1.podTemplate](http://htmlpreview.github.io/?http://github.com/GoogleCloudPlatform/kubernetes/HEAD/docs/api-reference/definitions.html#_v1_podtemplate) API object to declare network policy. This allows us to declare policy in a concise, easily readable format, matching on arbitrary labels. For example, securing traffic to your backend pods is as easy as adding the following two lines to your backend pod manifest and adding the label “access=backend” to each pod that should be allowed access:

```
`annotations: policy: "allow tcp from label access=backend to port 4001"`
```

Remember you can use arbitrary labels in Calico policy – “access” is just what we chose for this example. Take a look at our GitHub page on [declaring Kubernetes policy](http://github.com/projectcalico/calico-docker/blob/master/docs/kubernetes/KubernetesPolicy.md) for a full set of supported policy statements.

#### Behind the Scenes

The Calico plugin reads the declared policy combined with the pod’s `namespace` and converts it to Calico policy primitives – profiles, tags, and rules. The policy is realized as iptables rules in the kernel of the Kubernetes node which hosts your pods. Programming ACLs to the kernel means we can take advantage of Linux’s battle-hardened iptables kernel support and eliminate the need for a user-space datapath, improving the security and performance of our network policy.

Note the use of `namespace` in the policy mapping. By including the Kubernetes namespace, Calico can enforce Kubernetes namespace isolation. This means pods in your development namespace won’t accidentally interfere with your production pods. Pretty cool!

#### What’s Next?

This is just the first step – we have a lot of exciting work ahead of us continuing to develop network policy in Kubernetes and ensuring that Calico’s policy implementation can easily be combined with any Kubernetes networking plug-in / cloud provider. We plan on adding richer tag semantics to Calico policy to better support label-selectors, augmenting the Kubernetes API for better policy declaration, and improving policy performance in high-scale Kubernetes clusters.

[Open Source](https://www.tigera.io/tags/open-source/)[Partner/Integration](https://www.tigera.io/tags/partner-integration/)[Project Calico](https://www.tigera.io/tags/project-calico/)

## Related posts

[![What’s new in Calico: Spring 2026 Release](https://www.tigera.io/app/uploads/2026/06/Whats-New-in-Calico-NEW-TEMPLATE-2026.png)](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[Company Blog](https://www.tigera.io/category/company-blog/)

#### [What’s new in Calico: Spring 2026 Release](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on Jun 2, 2026

Kubernetes has come a long way since its debut in 2014. It’s gone from running a couple of containerized microservices to orchestrating fleets of production workloads spanning everything from AI agents to full scale VMs...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[![Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/app/uploads/2026/05/Kubernetes-Operational-Maturity-Secure-and-Resilient-Cluster-Federation-with-Cluster-Mesh.png)](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

#### [Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on May 25, 2026

Practically no one runs a single Kubernetes cluster in production these days. Maybe that’s how it started but data sovereignty requirements, acquisitions, AI initiatives and the need for edge servers, among other considerations, have pulled...

[Read more](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

[![What’s New in Calico v3.32](https://www.tigera.io/app/uploads/2026/05/Green-Please-use-a-different-background-color-alternately-1.png)](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

#### [What’s New in Calico v3.32](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

By [Reza Ramezanpour](https://www.tigera.io/blog/author/rezar/)
on May 13, 2026

We’re excited to announce the release of Calico Open Source v3.32! 🎉 This release corresponds with Kubernetes v1.36 (Codename Haru) and it goes beyond just sharing a cat as the mascot of the release, it...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6284 metric#misses=17 metric#hit-ratio=99.7 metric#bytes=2230334 metric#prefetches=0 metric#store-reads=420 metric#store-writes=15 metric#store-hits=433 metric#store-misses=6 metric#sql-queries=32 metric#ms-total=1163.81 metric#ms-cache=76.37 metric#ms-cache-avg=0.1760 metric#ms-cache-ratio=6.6 -->
