Technical explanation
A cluster-wide requirement is best implemented with CiliumClusterwideNetworkPolicy , whose correct resource spelling is CiliumClusterwideNetworkPolicy . Unlike a namespaced CiliumNetworkPolicy , this Cilium CRD is non-namespaced and can select endpoints across the entire cluster.
To deny external ingress for every Cilium-managed pod, a cluster-wide policy can use an empty endpointSelector and an ingressDeny rule selecting the world entity. Cilium defines world as network endpoints outside the cluster. An alternative allow-list construction can permit only the cluster entity, thereby excluding external sources, but an explicit deny rule usually communicates the requirement more directly.
A standard Kubernetes NetworkPolicy and a CiliumNetworkPolicy are namespaced, requiring repeated resources in every applicable namespace. CiliumGlobalPolicy is not a valid Cilium resource type. Although the option capitalizes “Wide” differently from the actual kind, D unmistakably identifies the intended cluster-scoped policy.
Official references
Cilium Deny Policies , Cilium Network Policy Types
Study Guide topic: Cluster-scoped policies, external traffic, and reserved entities.
Submit