---
title: "Policy for Kubernetes services"
description: "Apply Calico Open Source policy to Kubernetes Services — node ports, ClusterIPs, and externally exposed services."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico/latest/network-policy/services/"
---

# Policy for Kubernetes services

## [📄️Apply Calico policy to Kubernetes node ports](https://docs.tigera.io/calico/latest/network-policy/services/kubernetes-node-ports.md)

[Restrict access to Kubernetes NodePort services using Calico Open Source GlobalNetworkPolicy at the host endpoint.](https://docs.tigera.io/calico/latest/network-policy/services/kubernetes-node-ports.md)

## [📄️Apply Calico policy to services exposed externally as cluster IPs](https://docs.tigera.io/calico/latest/network-policy/services/services-cluster-ips.md)

[Expose Kubernetes Service ClusterIPs over BGP using Calico Open Source and restrict who can reach them with network policy.](https://docs.tigera.io/calico/latest/network-policy/services/services-cluster-ips.md)
