Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A financial institution is deploying a highly sensitive application to Kubernetes. They require a robust identity and access management (IAM) solution that integrates with their existing enterprise directory and provides fine-grained authorization for Kubernetes resources based on user roles and attributes. Which component within Kubernetes is primarily responsible for enforcing these authorization rules?

  1. AKubelet
  2. BController Manager
  3. CScheduler
  4. DAPI Server
Show answer & explanation

Correct answer: D. API Server

The Kubernetes API Server is the central management entity and the only component that interacts directly with etcd. All requests to modify or read cluster state, including authorization checks, must go through the API Server. It integrates with various authorization modules (e.g., RBAC, ABAC) to enforce access control.

Why the other options are wrong

  • A. Kubelet is the agent that runs on each node and manages Pods and containers, it does not handle cluster-wide authorization.
  • B. The Controller Manager runs various controllers that regulate the state of the cluster, but it relies on the API Server for authorization when making changes.
  • C. The Scheduler is responsible for assigning Pods to nodes based on resource requirements and policies, not authorization.

Kubernetes API Server

The central component of the Kubernetes control plane that exposes the Kubernetes API. It is responsible for serving the API, authenticating requests, authorizing access, and validating data.

  • Entry point for all cluster communication.
  • Handles authentication and authorization.
  • Validates and processes API requests.

Memory trick: The API Server is the brain and gatekeeper of the Kubernetes cluster.

More Cloud Native Security questions