---
title: "Policy for Kubernetes services"
description: "Apply Calico Cloud policy to Kubernetes Services — node ports, ClusterIPs, and externally exposed services."
product: "Calico Cloud"
version: "v23.0.1"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-cloud/network-policy/beginners/services/"
---

# Policy for Kubernetes services

## [📄️Apply Calico Cloud policy to Kubernetes node ports](https://docs.tigera.io/calico-cloud/network-policy/beginners/services/kubernetes-node-ports.md)

[Restrict access to Kubernetes NodePort services using a Calico Cloud GlobalNetworkPolicy at the host endpoint.](https://docs.tigera.io/calico-cloud/network-policy/beginners/services/kubernetes-node-ports.md)

## [📄️Apply Calico Cloud policy to services exposed externally as cluster IPs](https://docs.tigera.io/calico-cloud/network-policy/beginners/services/services-cluster-ips.md)

[Expose Kubernetes Service ClusterIPs over BGP using Calico Cloud and restrict who can reach them with network policy.](https://docs.tigera.io/calico-cloud/network-policy/beginners/services/services-cluster-ips.md)
