---
title: "NetworkPolicy"
description: "one allowed flow between two parties on the private network; everything not declared is denied"
section: concepts
address: /concepts/networkpolicy
contract: 0476e35e6e275db5
---

# NetworkPolicy

one allowed flow between two parties on the private network; everything not declared is denied

[figure: NetworkPolicy is a definition at platform scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | platform |
| key | the source and the destination |
| store | postgres |
| family | network |



## Fields


| field | type | required | note |
|---|---|---|---|
| `from_role` | `text` | yes | a role, the ingress, the load balancer, or the internet |
| `to_role` | `text` | yes | a role, a store, the collector, or the internet |
| `port` | `count` | yes |  |
| `protocol` | `one of tcp \| udp` | yes |  |
| `reason` | `text` | yes | why the flow exists, in one sentence |



## Routes that use it
No route takes or returns NetworkPolicy directly. The record holds it, and the objects that point at it reach it.
