---
title: "The New NetworkPolicy API in Kubernetes 1.7"
source: "https://www.tigera.io/blog/the-new-networkpolicy-api-in-kubernetes-1-7/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# The New NetworkPolicy API in Kubernetes 1.7

By [Mike Stowe](https://www.tigera.io/blog/author/mikestowe/) on Jul 10, 2017 • 3 min read

## Kubernetes 1.7

After focusing on stability in [Kubernetes 1.6](http://kubernetes.io/), version 1.7 *(set to be released June 28th)* looks to bring as many as 50 new features to Kubernetes, including focuses on federation, networking, and security.

According to Ihor Dvoretskyi, as shared with [SDX Central](http://www.sdxcentral.com/articles/news/kubernetes-1-7-to-focus-on-features-instead-of-initial-stability/2017/05/), most of these new capabilities will be initially launched as alpha features. However, in moving to bring these much needed features and advancements to Kubernetes, there will be some significant changes in terms of API capabilities- and possibly stability (in the short term).

One such exciting change includes the release of the new [v1 NetworkPolicy API](http://github.com/kubernetes/kubernetes/pull/39164#issue-197243974), which replaces the previous v1beta1 NetworkPolicy API. It’s important to note, that while the syntax of the NetworkPolicy remains the same, the behavior will differ slightly.

Two of the changes you need to be aware of are:

### **The v1beta1 NetworkPolicy API Has Been Deprecated**

The v1beta1 version of the NetworkPolicy API has been deprecated in favor of moving forward with the new behaviors and updating the behavior of the *extensions* API to allow for future expansion and development.Keep in mind that while the v1 NetworkPolicy API eclipses the existing beta, the new API endpoint will only be available on Kubernetes 1.7+ (as older versions do not include the v1 API code). As such, as you work towards upgrading, you’ll want to ensure that you are using the correct version of Project Calico for the NetworkPolicy behavior you want.

### **The DefaultDeny Annotation Has Been Removed**

One of the bigger changes in Kubernetes 1.7 is the removal of the DefaultDeny annotation. This means that when upgrading, you should **first delete any existing NetworkPolicy** objects in namespaces that previously **did not have** the “DefaultDeny” annotation (as this may cause Kubernetes to unintentionally block traffic now).

For those objects with the “DefaultDeny” annotation, you can replicate it’s past behavior by creating a NetworkPolicy that selects all pods but does not allow any traffic, like so:

```
`kind: NetworkPolicy apiVersion: networking.k8s.io/v1 metadata: name: default-deny spec: podSelector:`
```

 

## Using Project Calico with Kubernetes 1.7

If you want to try out the new NetworkPolicy behavior you can do it today by installing Calico v2.3.0 and Kubernetes v1.7.0-beta.3.

Note that while currently only the Kubernetes datastore driver implements the new behavior, we’re hard at work updating Project Calico to be able to utilize both APIs when using etcd as well, so stay tuned!

But again, you may need to update your policies as described above, as well as in the Project Calico [release notes](http://docs.projectcalico.org/latest/releases/).

[Open Source](https://www.tigera.io/tags/open-source/)[Project Calico](https://www.tigera.io/tags/project-calico/)

## Related posts

[![What’s new in Calico: Spring 2026 Release](https://www.tigera.io/app/uploads/2026/06/Whats-New-in-Calico-NEW-TEMPLATE-2026.png)](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[Company Blog](https://www.tigera.io/category/company-blog/)

#### [What’s new in Calico: Spring 2026 Release](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on Jun 2, 2026

Kubernetes has come a long way since its debut in 2014. It’s gone from running a couple of containerized microservices to orchestrating fleets of production workloads spanning everything from AI agents to full scale VMs...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[![Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/app/uploads/2026/05/Kubernetes-Operational-Maturity-Secure-and-Resilient-Cluster-Federation-with-Cluster-Mesh.png)](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

#### [Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on May 25, 2026

Practically no one runs a single Kubernetes cluster in production these days. Maybe that’s how it started but data sovereignty requirements, acquisitions, AI initiatives and the need for edge servers, among other considerations, have pulled...

[Read more](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

[![What’s New in Calico v3.32](https://www.tigera.io/app/uploads/2026/05/Green-Please-use-a-different-background-color-alternately-1.png)](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

#### [What’s New in Calico v3.32](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

By [Reza Ramezanpour](https://www.tigera.io/blog/author/rezar/)
on May 13, 2026

We’re excited to announce the release of Calico Open Source v3.32! 🎉 This release corresponds with Kubernetes v1.36 (Codename Haru) and it goes beyond just sharing a cat as the mascot of the release, it...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6183 metric#misses=37 metric#hit-ratio=99.4 metric#bytes=2204518 metric#prefetches=0 metric#store-reads=420 metric#store-writes=37 metric#store-hits=412 metric#store-misses=26 metric#sql-queries=50 metric#ms-total=1370.17 metric#ms-cache=72.17 metric#ms-cache-avg=0.1583 metric#ms-cache-ratio=5.3 -->
