Pods behind an Ingress are protected by a default-deny NetworkPolicy. External clients reach the Ingress controller, but app Pods never receive traffic. What additional NetworkPolicy consideration is required?
Select an answer to reveal the explanation.
Short Explanation
Ingress opens the city gate, but NetworkPolicy still guards each building. If default-deny is on, explicitly allow the controller’s Pods to talk to your app ports—or the gate leads nowhere.
Full Explanation
Ingress exposure and NetworkPolicies compose. With default-deny, traffic from the Ingress controller namespace/Pods to application Pods must be explicitly allowed on the relevant ports. Simply having an Ingress does not override NetworkPolicy. Deleting Services, misusing ingressClassName, or opening unrelated hostPorts does not correctly authorize controller-to-Pod paths.