SlideShare a Scribd company logo
Anirban Sen Chowdhary
“Project Calico is the world's simplest, most scalable, open networking
solution for OpenStack”. 
Calico, a pure layer3 approach to Virtual Networking for highly scalable & 
flexible Data centers. It is a open-source technology, that  implements  
large, standards-based cloud data center infrastructures 
Calico supports rich and flexible network policy that enforces on every 
node in a cluster, to provide tenant isolation, security groups, and external 
reachability constraints.
There is security layer into Calico that enables developers and operations 
staff to easily define with fine granularity which connections are allowed, 
and which are not. These rules implement and extend the Kubernetes 
Network Policy API.
There are basically 3 policy demo we can configure:
* Simple Policy Demo 
* Stars Policy Demo 
* Advanced Policy Demo
We will discuss on the overview of Simple Policy Demo.
Lastime, we discussed Star Policy here:
https://www.slideshare.net/anir37/calico-and-stars-policy
Calico and simple policy
It includes demo try out Kubernetes NetworkPolicy with Calico, as well as a
client service for all running on Kubernetes.
It requires a Kubernetes cluster configured with Calico networking, and
expects that you have kubectl configured to interact with the cluster.
We need to install Kubernetes in the system which includes Network Policy
API.
We need to get the following thing:
Calico
and then need to get into star-policy directory of Calico
1) We need to create some nginx pods in the policy-demo Namespace, and
expose them through a Service.:
2) Also we need to ensure the nginx service is accessible:
Enable isolation:
Now this is the important part…. let’s turn on isolation in our policy-demo
Namespace which will then prevent connections to pods in this
Namespace.
We will now run the command that creates a NetworkPolicy which
implements a default deny behavior for all pods in the policy-demo
Namespace.
Allow Access using a NetworkPolicy :
Now, let’s enable access to the nginx Service using a NetworkPolicy. This
will allow incoming connections from our access Pod, but not from
anywhere else.
We need to now create a network policy access-nginx with the following
contents:
That’s it!
We should now be able to access the Service from the access Pod.
We can remove the policy using following:
As you can see, this is just a simple example of the Kubernetes
NetworkPolicy API and how Calico can secure your Kubernetes cluster.
In next slides, we will discuss the overview on other policy demo.
Lets share our knowledge and effort on community so that the Calico
community grows.
For more information visit
https://www.projectcalico.org/
https://docs.projectcalico.org/v2.6/introduction/
https://blog.tigera.io/tagged/calico
Calico and simple policy

More Related Content

PPT
Calico and ubuntu
PPT
Calico and juju
PPT
Calico and stars policy
PPT
Calico and open shift
PPT
Drive into calico architecture part 2
PPT
Drive into calico architecture
PPT
Calico and mesos
Calico and ubuntu
Calico and juju
Calico and stars policy
Calico and open shift
Drive into calico architecture part 2
Drive into calico architecture
Calico and mesos

What's hot (20)

PPT
Cloud technology and cloud native approach
PPTX
Hands-on Lab: Test Drive Your OpenStack Network
PDF
Tokyo meetup 20160224
PDF
Introduction to Istio on Kubernetes
PPT
Calico and how interprets neutron api
PPTX
Openstack and Reddwarf Overview
DOCX
cloudcomputing.docx
PPTX
Microservices With Istio Service Mesh
PPTX
Monitoring Security Policies for Container and OpenStack Clouds
PDF
OpenStack NFV Edge computing for IOT microservices
PDF
Cisco ACI Main Session EMC World 2015
PDF
Replacing vCloud with OpenNebula
PPTX
Cisco Application Centric Infrastructure
PPTX
Design and Deploy Secure Clouds for Financial Services Use Cases
PDF
Istio Service Mesh
PDF
Ignite 2015 NA Technology Breakout Session - "Security, Stability and Scalabi...
PDF
Ignite 2015 EU - Technology Breakout Session "Security, Stability and Scalab...
PPTX
Process for joining to the FIWARE Lab
PDF
Istio: Using nginMesh as the service proxy
PDF
Open source IoT gateway
Cloud technology and cloud native approach
Hands-on Lab: Test Drive Your OpenStack Network
Tokyo meetup 20160224
Introduction to Istio on Kubernetes
Calico and how interprets neutron api
Openstack and Reddwarf Overview
cloudcomputing.docx
Microservices With Istio Service Mesh
Monitoring Security Policies for Container and OpenStack Clouds
OpenStack NFV Edge computing for IOT microservices
Cisco ACI Main Session EMC World 2015
Replacing vCloud with OpenNebula
Cisco Application Centric Infrastructure
Design and Deploy Secure Clouds for Financial Services Use Cases
Istio Service Mesh
Ignite 2015 NA Technology Breakout Session - "Security, Stability and Scalabi...
Ignite 2015 EU - Technology Breakout Session "Security, Stability and Scalab...
Process for joining to the FIWARE Lab
Istio: Using nginMesh as the service proxy
Open source IoT gateway
Ad

Similar to Calico and simple policy (20)

PPT
Deploying calico on kubernetes
PDF
Simplifying and Securing your OpenShift Network with Project Calico
PPT
Calico with docker
PPT
Calico integration
PPT
Protecting host with calico
PPT
Calico in networking mode
PDF
Project calico - introduction
PDF
Network policies in Kubernetes using Calico
PPTX
Network policy @ k8s day
PPTX
Kubernetes Online Training
PPT
Calico using rkt
PPTX
Container Networking: the Gotchas (Mesos London Meetup 11 May 2016)
PPT
Getting started with project calico
PPTX
KubeCon EU 2016: Secure, Cloud-Native Networking with Project Calico
PDF
DCEU 18: Docker Container Networking
PPTX
Securing Kubernetes Clusters with NGINX Plus Ingress Controller & NAP
PDF
Introduction to the Container Networking and Security
PDF
Container Networking - State of the Ecosystem [ContainerConf, Mannheim, Nov 2...
PDF
Kubernetes Security with Calico and Open Policy Agent
PPTX
Container Networking Meetup March 31 2016
Deploying calico on kubernetes
Simplifying and Securing your OpenShift Network with Project Calico
Calico with docker
Calico integration
Protecting host with calico
Calico in networking mode
Project calico - introduction
Network policies in Kubernetes using Calico
Network policy @ k8s day
Kubernetes Online Training
Calico using rkt
Container Networking: the Gotchas (Mesos London Meetup 11 May 2016)
Getting started with project calico
KubeCon EU 2016: Secure, Cloud-Native Networking with Project Calico
DCEU 18: Docker Container Networking
Securing Kubernetes Clusters with NGINX Plus Ingress Controller & NAP
Introduction to the Container Networking and Security
Container Networking - State of the Ecosystem [ContainerConf, Mannheim, Nov 2...
Kubernetes Security with Calico and Open Policy Agent
Container Networking Meetup March 31 2016
Ad

More from Anirban Sen Chowdhary (20)

PPTX
Change the game with Game changer
PPTX
Ring central desktop app overview
PPTX
Overview in ringcentral digital line
PPTX
Some basics with ring central
PPTX
Ring central and python
PPTX
RingCentral application development overview
PPTX
Cloze connect ringcentral
PPTX
Overview on ring central errors part 4
PPTX
Setting up your ring central sandbox in steps
PPTX
Overview on ring central errors: part 2
PPTX
Overview on ring central errors
PPTX
Call recording overview ring central
PPTX
Ring central engaging with amazon alexa
PPTX
How ring central sdk changing the game
PPTX
When ring central connect salesforce
PPTX
Mule 4 connecting ring central
PPTX
Ring central sdk
PPTX
Ring central with okta
PPTX
Ring central connecting salesforce overview
PPTX
Ring central call logs overview (part 2)
Change the game with Game changer
Ring central desktop app overview
Overview in ringcentral digital line
Some basics with ring central
Ring central and python
RingCentral application development overview
Cloze connect ringcentral
Overview on ring central errors part 4
Setting up your ring central sandbox in steps
Overview on ring central errors: part 2
Overview on ring central errors
Call recording overview ring central
Ring central engaging with amazon alexa
How ring central sdk changing the game
When ring central connect salesforce
Mule 4 connecting ring central
Ring central sdk
Ring central with okta
Ring central connecting salesforce overview
Ring central call logs overview (part 2)

Recently uploaded (20)

PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
A Presentation on Touch Screen Technology
PPTX
OMC Textile Division Presentation 2021.pptx
PPTX
Chapter 5: Probability Theory and Statistics
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Getting Started with Data Integration: FME Form 101
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Hybrid model detection and classification of lung cancer
PPTX
1. Introduction to Computer Programming.pptx
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
A novel scalable deep ensemble learning framework for big data classification...
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Heart disease approach using modified random forest and particle swarm optimi...
A Presentation on Touch Screen Technology
OMC Textile Division Presentation 2021.pptx
Chapter 5: Probability Theory and Statistics
SOPHOS-XG Firewall Administrator PPT.pptx
Getting Started with Data Integration: FME Form 101
Programs and apps: productivity, graphics, security and other tools
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
1 - Historical Antecedents, Social Consideration.pdf
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Enhancing emotion recognition model for a student engagement use case through...
Hybrid model detection and classification of lung cancer
1. Introduction to Computer Programming.pptx
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Group 1 Presentation -Planning and Decision Making .pptx
Hindi spoken digit analysis for native and non-native speakers
A novel scalable deep ensemble learning framework for big data classification...
gpt5_lecture_notes_comprehensive_20250812015547.pdf

Calico and simple policy