NetworkPolicy: Ingress from Internet only
ResourceQuota: 20 CPU / 40Gi Memory
RBAC: frontend-team (limited access)
Secrets: Only frontend secrets visible
↓ NetworkPolicy (port 8080 only)
NetworkPolicy: Only from dmz-frontend
ResourceQuota: 100 CPU / 200Gi Memory
RBAC: backend-team only
PodSecurity: restricted
↓ NetworkPolicy (port 5432 only)
postgres-primary
postgres-replica
NetworkPolicy: DENY ALL + backend only
ResourceQuota: 50 CPU / 500Gi Mem / 1Ti PVC
RBAC: dba-team only (no dev access)
Encryption: at-rest + in-transit