Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A financial institution is deploying a sensitive application to a Kubernetes cluster. They need to ensure that all communication between the application's microservices is encrypted and mutually authenticated, even within the same cluster network. Which technology is best suited to achieve this without requiring application-level code changes for encryption?
- AIngress Controller
- BExternalDNS
- CService Mesh (e.g., Istio, Linkerd)
- DKubernetes NetworkPolicy
Show answer & explanationAnswer & explanation
Correct answer: C. Service Mesh (e.g., Istio, Linkerd)
A service mesh provides capabilities like mutual TLS (mTLS) for encrypting and authenticating traffic between services at the network layer, typically using sidecar proxies, without requiring application code modifications. NetworkPolicies only control traffic flow, not encryption or authentication.
Why the other options are wrong
- A. An Ingress Controller manages external access to services, not internal service-to-service communication encryption.
- B. ExternalDNS integrates Kubernetes services with external DNS providers, unrelated to inter-service encryption.
- D. NetworkPolicies control traffic flow but do not provide encryption or mutual authentication.
Service Mesh for Security
A configurable infrastructure layer for managing service-to-service communication, offering features like mutual TLS (mTLS) for encryption and authentication, traffic management, and observability.
- Provides mTLS for encrypted inter-service communication.
- Enables mutual authentication between services.
- Operates at the network level, often with sidecar proxies.
- Reduces security burden on application developers.
Memory trick: Mesh secures microservice communication.