DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium
A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. They need to ensure that all network traffic between namespaces and to external services is strictly controlled based on defined policies, such as allowing only specific ports or protocols between certain application tiers. Which Kubernetes resource should be used to implement these network segmentation and access control policies?
- ANetworkPolicy
- BConfigMap
- CService
- DIngress
Show answer & explanationAnswer & explanation
Correct answer: A. NetworkPolicy
Kubernetes NetworkPolicies allow you to define rules for how pods communicate with each other and with external network endpoints. They enable fine-grained control over network traffic, enforcing segmentation based on labels, namespaces, IP blocks, ports, and protocols, directly addressing the requirement for strict network control.
Why the other options are wrong
- B. A ConfigMap stores non-confidential configuration data as key-value pairs; it has no role in network policy enforcement.
- C. A Service defines a logical set of Pods and a policy by which to access them (e.g., load-balanced access), but it does not define network access control rules.
- D. Ingress manages external access to services within the cluster, typically for HTTP/HTTPS traffic, but it's not designed for fine-grained inter-namespace or egress network segmentation.
Kubernetes NetworkPolicy
Kubernetes NetworkPolicy is a resource that controls network traffic flow between pods, namespaces, and external network endpoints within a Kubernetes cluster.
- Enforces network segmentation.
- Based on labels, namespaces, IP blocks, ports, protocols.
- Applied to pods.
- Requires a network plugin that supports NetworkPolicy.
Memory trick: NetworkPolicy is the traffic cop for pods.