Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A client is deploying a new web application on Google Kubernetes Engine (GKE) and requires strict network isolation between different microservices within the same cluster. Specifically, the 'frontend' service should only be able to communicate with the 'backend-api' service, and the 'backend-api' service should only be able to communicate with the 'database' service. All other internal communications should be blocked by default. Which Google Cloud feature should the client implement to achieve this granular network segmentation?

  1. AVPC Service Controls
  2. BKubernetes Network Policies
  3. CCloud Firewall Rules
  4. DShared VPC
Show answer & explanation

Correct answer: B. Kubernetes Network Policies

Kubernetes Network Policies are specifically designed to control communication between pods within a Kubernetes cluster. They allow for granular, namespace-based or label-based network segmentation, directly addressing the requirement for strict isolation between microservices.

Why the other options are wrong

  • A. VPC Service Controls establish security perimeters around Google Cloud resources to prevent data exfiltration, not for internal pod-to-pod communication within a GKE cluster.
  • C. Cloud Firewall Rules operate at the Virtual Private Cloud (VPC) network level and apply to VM instances, not granular pod-to-pod communication within a GKE cluster.
  • D. Shared VPC allows multiple projects to use a common VPC network, which aids in network organization but does not provide granular pod-level isolation.

Kubernetes Network Policies

Specifications that define how groups of pods are allowed to communicate with each other and with other network endpoints.

  • Operate at Layer 3 (IP) and Layer 4 (TCP/UDP).
  • Apply to pods based on labels.
  • Are enforced by the network plugin running in the cluster.

Memory trick: Policies Police Pod Pathways.

More Security and operations with Google Cloud questions