KKP supports various CNIs and the standard NetworkPolicy resource. This allows for network isolation, which can serve as an equivalent security control, particularly in on-premise or air-gapped environments
Provide official documentation and best-practice guides on using network isolation as a primary security control for service access. This would include examples of using NetworkPolicy with a capable CNI to create a zero-trust network environment where only explicitly allowed pods can communicate with sensitive services.