AWS Network Firewall now supports container attribute-based rules, letting teams write firewall policy that targets Kubernetes pods by attributes instead of ephemeral IP addresses. The post explains why static IP-based rules break down as pods scale or restart, and how the new capability keeps policy stable across that churn.