NetworkPolicy egress
Tested with: Cilium 1.16 · Calico 3.28 · Kubernetes 1.31 NetworkPolicy
A default-deny egress policy plus an explicit allow for the Databasezy endpoint keeps a compromised pod from reaching anything else. The Databasezy gateway IPs for your region are listed under Instance → Network → Gateway addresses and change only with 30 days’ notice; FQDN policies avoid tracking them.
Default deny
Section titled “Default deny”apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata: name: default-deny-egress namespace: appspec: podSelector: {} policyTypes: [Egress] egress: - to: - namespaceSelector: matchLabels: { kubernetes.io/metadata.name: kube-system } podSelector: matchLabels: { k8s-app: kube-dns } ports: - { protocol: UDP, port: 53 } - { protocol: TCP, port: 53 }Allow the database
Section titled “Allow the database”apiVersion: cilium.io/v2kind: CiliumNetworkPolicymetadata: name: allow-databasezy-postgres namespace: appspec: endpointSelector: matchLabels: { app: api } egress: - toEndpoints: - matchLabels: io.kubernetes.pod.namespace: kube-system k8s-app: kube-dns toPorts: - ports: [{ port: "53", protocol: ANY }] rules: dns: - matchPattern: "*.databasezy.com" - toFQDNs: - matchPattern: "*.us-east.databasezy.com" toPorts: - ports: [{ port: "5432", protocol: TCP }]apiVersion: projectcalico.org/v3kind: NetworkPolicymetadata: name: allow-databasezy-postgres namespace: appspec: selector: app == 'api' types: [Egress] egress: - action: Allow protocol: TCP destination: domains: ["*.us-east.databasezy.com"] ports: [5432]Domain-based egress requires Calico Enterprise or Calico Cloud; on open-source Calico use the CIDR variant.
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata: name: allow-databasezy-postgres namespace: appspec: podSelector: matchLabels: { app: api } policyTypes: [Egress] egress: - to: # Databasezy gateway addresses for us-east (Instance → Network → Gateway addresses) - ipBlock: { cidr: 203.0.113.0/26 } - ipBlock: { cidr: 203.0.113.64/26 } ports: - { protocol: TCP, port: 5432 }Change the port for other engines: 3306 (MySQL), 6379 (Valkey), 27017 (FerretDB), 443 (every HTTP and gRPC
engine, such as libSQL, Qdrant or TypeDB), and 8443 plus 9440 for ClickHouse.
Both directions
Section titled “Both directions”The allow-list on the Databasezy side is the other half. Give the instance your cluster’s egress CIDR
(Network → Allow-list in the portal, or PUT /v1/orgs/{org}/instances/{id}/network); with a NAT gateway or a Cilium Egress Gateway that is a small, stable range.