Professional Cloud Security EngineerConfiguring network securityMedium
A company is deploying a new web application on Google Kubernetes Engine (GKE) and requires strict ingress and egress control for its pods. Specifically, they need to restrict traffic based on IP ranges, ports, and protocols, both for communication between pods and between pods and external services. Which Google Cloud networking feature, when integrated with GKE, provides this granular control?
- AVPC Firewall Rules
- BCloud VPN
- CGKE Network Policies
- DCloud Armor
Show answer & explanationAnswer & explanation
Correct answer: C. GKE Network Policies
GKE Network Policies allow for granular, pod-level ingress and egress control within a GKE cluster, enabling specification of allowed traffic based on labels, IP ranges, ports, and protocols, directly addressing the requirement.
Why the other options are wrong
- A. VPC Firewall Rules operate at the VM instance level and do not provide the granular pod-level control required within GKE.
- B. Cloud VPN connects on-premises networks to GCP VPCs, not for granular pod-level traffic control within a GKE cluster.
- D. Cloud Armor provides WAF and DDoS protection for L7 services, not for internal pod-to-pod or pod-to-external granular network control.
GKE Network Policies
GKE Network Policies enable granular control over network communication between pods within a GKE cluster and between pods and external endpoints.
- Pod-level traffic control
- Uses Kubernetes NetworkPolicy API
- Configurable for ingress and egress
Memory trick: GKE pods need policies to guard their traffic flow.