Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security auditor is reviewing a Kubernetes cluster's network policies. They observe that a critical microservice, running in the 'backend' namespace, needs to accept incoming connections only from pods in the 'frontend' namespace and from a specific external IP range (192.0.2.0/24). All other ingress traffic should be denied. Which NetworkPolicy configuration snippet correctly enforces this requirement?

  1. AapiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: backend-policy spec: podSelector: matchLabels: app: backend-service policyTypes: - Ingress ingress: - from: - namespaceSelector: matchLabels: name: frontend - from: - ipBlock: cidr: 192.0.2.0/24
  2. BapiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: backend-policy spec: podSelector: matchLabels: app: backend-service policyTypes: - Egress egress: - to: - namespaceSelector: matchLabels: name: frontend - ipBlock: cidr: 192.0.2.0/24
  3. CapiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: backend-policy spec: podSelector: matchLabels: app: backend-service policyTypes: - Ingress ingress: - from: - namespaceSelector: matchLabels: name: frontend - ipBlock: cidr: 192.0.2.0/24
  4. DapiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: backend-policy spec: podSelector: matchLabels: app: backend-service policyTypes: - Ingress ingress: - from: - podSelector: matchLabels: namespace: frontend - ipBlock: cidr: 192.0.2.0/24
Show answer & explanation

Correct answer: C. apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: backend-policy spec: podSelector: matchLabels: app: backend-service policyTypes: - Ingress ingress: - from: - namespaceSelector: matchLabels: name: frontend - ipBlock: cidr: 192.0.2.0/24

Option A correctly uses `namespaceSelector` to target pods in the 'frontend' namespace and `ipBlock` for the external IP range within a single `from` clause. This allows traffic from either source. Placing both selectors under the same `from` entry means 'OR' logic, allowing traffic if it matches *either* the namespace *or* the IP block. The `policyTypes: Ingress` ensures only ingress rules are applied.

Why the other options are wrong

  • A. This configuration would create two separate `from` entries, which means 'AND' logic if used in the same `ingress` rule and would be interpreted differently than intended; however, in this specific structure (multiple `from` entries within the same `ingress` rule), it acts as an OR. The key difference from A is that A groups them under a single `from` item, making the OR explicit for the sources. Both A and D achieve the logical OR, but A is generally the more conventional and clearer way to express 'source A OR source B' within a single rule.
  • B. Incorrectly uses `policyTypes: Egress` and `egress` rules, which control outgoing traffic, not incoming.
  • D. Incorrectly uses `podSelector` with `namespace: frontend` label; `namespaceSelector` is needed to select namespaces, and it's applied at the namespace level, not pod level within 'from'.

Kubernetes NetworkPolicy

A Kubernetes resource that controls traffic flow between pods and/or external networks based on labels, namespaces, and IP blocks.

  • Applied to pods via `podSelector`.
  • Default deny if no policies match for a pod.
  • Supports `Ingress` (incoming) and `Egress` (outgoing) rules.
  • Rules are additive; if any rule allows traffic, it's permitted.

Memory trick: Policies control traffic, Ingress, Egress, from and to.

More Cloud Native Security questions