---
title: "Policy for Kubernetes services"
description: "Apply Calico policy to Kubernetes node ports, and to services that are exposed externally as cluster IPs."
product: "Calico Enterprise"
version: "3.21"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/services/"
---

# Policy for Kubernetes services

## [📄️Apply Calico Enterprise policy to Kubernetes node ports](https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/services/kubernetes-node-ports.md)

[Restrict access to Kubernetes node ports using Calico Enterprise global network policy. Follow the steps to secure the host, the node ports, and the cluster.](https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/services/kubernetes-node-ports.md)

## [📄️Apply Calico Enterprise policy to services exposed externally as cluster IPs](https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/services/services-cluster-ips.md)

[Expose Kubernetes service cluster IPs over BGP using Calico Enterprise, and restrict who can access them using Calico Enterprise network policy.](https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/services/services-cluster-ips.md)
