Skip to content

NetworkPolicy egress

Tested with: Cilium 1.16 · Calico 3.28 · Kubernetes 1.31 NetworkPolicy

A default-deny egress policy plus an explicit allow for the Databasezy endpoint keeps a compromised pod from reaching anything else. The Databasezy gateway IPs for your region are listed under Instance → Network → Gateway addresses and change only with 30 days’ notice; FQDN policies avoid tracking them.

default-deny-egress.yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-egress
namespace: app
spec:
podSelector: {}
policyTypes: [Egress]
egress:
- to:
- namespaceSelector:
matchLabels: { kubernetes.io/metadata.name: kube-system }
podSelector:
matchLabels: { k8s-app: kube-dns }
ports:
- { protocol: UDP, port: 53 }
- { protocol: TCP, port: 53 }
allow-databasezy.yaml
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-databasezy-postgres
namespace: app
spec:
endpointSelector:
matchLabels: { app: api }
egress:
- toEndpoints:
- matchLabels:
io.kubernetes.pod.namespace: kube-system
k8s-app: kube-dns
toPorts:
- ports: [{ port: "53", protocol: ANY }]
rules:
dns:
- matchPattern: "*.databasezy.com"
- toFQDNs:
- matchPattern: "*.us-east.databasezy.com"
toPorts:
- ports: [{ port: "5432", protocol: TCP }]

Change the port for other engines: 3306 (MySQL), 6379 (Valkey), 27017 (FerretDB), 443 (every HTTP and gRPC engine, such as libSQL, Qdrant or TypeDB), and 8443 plus 9440 for ClickHouse.

The allow-list on the Databasezy side is the other half. Give the instance your cluster’s egress CIDR (Network → Allow-list in the portal, or PUT /v1/orgs/{org}/instances/{id}/network); with a NAT gateway or a Cilium Egress Gateway that is a small, stable range.