A global network set resource (GlobalNetworkSet) represents an arbitrary set of IP subnetworks/CIDRs, allowing it to be matched by Calico policy. Network sets are useful for applying policy to traffic coming from (or going to) external, non-Calico, networks.
The metadata for each network set includes a set of labels. When Calico is calculating the set of IPs that should match a source/destination selector within a global network policy rule, it includes the CIDRs from any network sets that match the selector.
A global network policy resource (
GlobalNetworkPolicy ) represents an ordered set of rules which are applied to a collection of endpoints that match a label selector.
GlobalNetworkPolicy is not a namespaced resource.
GlobalNetworkPolicy applies to workload endpoint resources in all namespaces, and to host endpoint resources. Select a namespace in a
GlobalNetworkPolicy in the standard selector by using
projectcalico.org/namespace as the label name and a
namespace name as the value to compare against, e.g.,
projectcalico.org/namespace == "default" . See network policy resource for namespaced network policy.
GlobalNetworkPolicy resources can be used to define network connectivity rules between groups of Calico endpoints and host endpoints, and take precedence over Profile resources if any are defined.