---
title: "Policy for Kubernetes services"
description: "Apply Calico Enterprise policy to Kubernetes Services — node ports, ClusterIPs, and externally exposed services."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/network-policy/beginners/services/"
---

# Policy for Kubernetes services

## [📄️Apply Calico Enterprise policy to Kubernetes node ports](https://docs.tigera.io/calico-enterprise/latest/network-policy/beginners/services/kubernetes-node-ports.md)

[Restrict access to Kubernetes NodePort services using a Calico Enterprise GlobalNetworkPolicy at the host endpoint.](https://docs.tigera.io/calico-enterprise/latest/network-policy/beginners/services/kubernetes-node-ports.md)

## [📄️Apply Calico Enterprise policy to services exposed externally as cluster IPs](https://docs.tigera.io/calico-enterprise/latest/network-policy/beginners/services/services-cluster-ips.md)

[Expose Kubernetes Service ClusterIPs over BGP using Calico Enterprise and restrict who can reach them with network policy.](https://docs.tigera.io/calico-enterprise/latest/network-policy/beginners/services/services-cluster-ips.md)
