---
title: Defining a default network policy for projects
---

# Defining a default network policy for projects {#default-network-policy}

To enforce consistent network isolation and security controls across projects, configure a default project template to automatically apply network policies to newly created projects.

As a cluster administrator, you can modify the new project template to automatically include network policies when you create a new project. If you do not yet have a customized template for new projects, you must first create one.

## Modifying the template for new projects {#modifying-template-for-new-projects_default-network-policy}

To modify the default project template to customize the resources and settings applied when users create new projects, you can create a custom project template.

As a cluster administrator, you can modify the default project template so that new projects are created using your custom requirements.

To create your own custom project template:

**Prerequisites**

- You have access to an OpenShift Container Platform cluster using an account with `cluster-admin` permissions.

**Procedure**

1. Log in as a user with `cluster-admin` privileges.
2. Generate the default project template:

   ```terminal
   $ oc adm create-bootstrap-project-template -o yaml > template.yaml
   ```
3. Use a text editor to modify the generated `template.yaml` file by adding objects or modifying existing objects.
4. The project template must be created in the `openshift-config` namespace. Load your modified template:

   ```terminal
   $ oc create -f template.yaml -n openshift-config
   ```
5. Edit the project configuration resource using the web console or CLI.

   - Using the web console, complete the following tasks:

     1. Navigate to the **Administration** → **Cluster Settings** page.
     2. Click **Configuration** to view all configuration resources.
     3. Find the entry for **Project** and click **Edit YAML**.
   - Using the CLI, complete the following tasks:

     1. Edit the `project.config.openshift.io/cluster` resource:

        ```terminal
        $ oc edit project.config.openshift.io/cluster
        ```
6. Update the `spec` section to include the `projectRequestTemplate` and `name` parameters. Ensure you set the name of your uploaded project template. The default name is `project-request`.

   ```yaml {title="Project configuration resource with custom project template"}
   apiVersion: config.openshift.io/v1
   kind: Project
   metadata:
   # ...
   spec:
     projectRequestTemplate:
       name: <template_name>
   # ...
   ```
7. After you save your changes, create a new project to verify that your changes were successfully applied.

## Adding network policies to the new project template {#nw-networkpolicy-project-defaults_default-network-policy}

You can add `NetworkPolicy` objects to the default project template so that new projects automatically include predefined network isolation rules. Applying network policies through templates helps enforce consistent network security controls across projects.

**Prerequisites**

- Your cluster uses a default container network interface (CNI) network plugin that supports `NetworkPolicy` objects, such as the OVN-Kubernetes.
- You installed the OpenShift CLI (`oc`).
- You must log in to the cluster with a user with `cluster-admin` privileges.
- You must have created a custom default project template for new projects.

**Procedure**

1. Edit the default template for a new project by running the following command:

   ```terminal
   $ oc edit template <project_template> -n openshift-config
   ```

   Replace `<project_template>` with the name of the default template that you configured for your cluster. The default template name is `project-request`.
2. In the template, add each `NetworkPolicy` object as an element to the `objects` parameter. The `objects` parameter accepts a collection of one or more objects.

   In the following example, the `objects` parameter collection includes several `NetworkPolicy` objects.

   ```yaml
   objects:
   - apiVersion: networking.k8s.io/v1
     kind: NetworkPolicy
     metadata:
       name: allow-from-same-namespace
     spec:
       podSelector: {}
       ingress:
       - from:
         - podSelector: {}
   - apiVersion: networking.k8s.io/v1
     kind: NetworkPolicy
     metadata:
       name: allow-from-openshift-ingress
     spec:
       ingress:
       - from:
         - namespaceSelector:
             matchLabels:
               policy-group.network.openshift.io/ingress:
       podSelector: {}
       policyTypes:
       - Ingress
   - apiVersion: networking.k8s.io/v1
     kind: NetworkPolicy
     metadata:
       name: allow-from-kube-apiserver-operator
     spec:
       ingress:
       - from:
         - namespaceSelector:
             matchLabels:
               kubernetes.io/metadata.name: openshift-kube-apiserver-operator
           podSelector:
             matchLabels:
               app: kube-apiserver-operator
       policyTypes:
       - Ingress
   ...
   ```
3. Optional: Create a new project and confirm the successful creation of your network policy objects.

   1. Create a new project:

      ```terminal
      $ oc new-project <project>
      ```

      Replace `<project>` with the name of the project you want to create.
   2. Confirm that the network policy objects in the new project template exist in the new project:

      ```terminal
      $ oc get networkpolicy
      ```

      Expected output:

      ```terminal
      NAME                           POD-SELECTOR   AGE
      allow-from-openshift-ingress   <none>         7s
      allow-from-same-namespace      <none>         7s
      ```
