Professional Cloud Security EngineerConfiguring network securityMedium
A development team is deploying a new containerized application to Google Kubernetes Engine (GKE). The application requires strict network isolation between different microservices within the same GKE cluster, ensuring that only authorized services can communicate with each other. They also need to apply granular ingress and egress policies based on pod labels and namespaces. Which GKE networking feature should they implement?
- ANetwork Policy
- BShared VPC
- CVPC Service Controls
- DGKE Private Clusters
Show answer & explanationAnswer & explanation
Correct answer: A. Network Policy
Kubernetes Network Policy allows you to define rules that specify how pods are allowed to communicate with each other and other network endpoints. It enables granular control over ingress and egress traffic based on labels and namespaces, which is exactly what's needed for strict microservice isolation in GKE.
Why the other options are wrong
- B. Shared VPC allows multiple projects to share a host VPC network, which is a broader networking construct and does not provide granular microservice isolation within a GKE cluster.
- C. VPC Service Controls protect against data exfiltration from Google Cloud services and are not for internal pod-to-pod communication control within GKE.
- D. GKE Private Clusters ensure that nodes have only internal IP addresses, improving security but not providing granular pod-level communication control within the cluster.
Kubernetes Network Policy (GKE)
A Kubernetes resource that defines how groups of pods are allowed to communicate with each other and network endpoints.
- Enforces traffic rules based on pod labels and namespaces
- Supports both ingress and egress policy definitions
- Requires a Network Policy-enabled CNI (e.g., Calico or GKE's default)
Memory trick: Keep your microservices talking only to friends.