Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A development team is deploying a new microservices application using Azure Kubernetes Service (AKS). Each microservice runs in a separate container, and the team needs to ensure that network traffic between containers within the same cluster is securely segmented based on their roles. For instance, the frontend service should only communicate with the API gateway, and the API gateway should only communicate with specific backend services. Which Kubernetes networking construct should be implemented to enforce these communication policies?
- AService Endpoints
- BNetwork Policies
- CAzure Firewall
- DNetwork Security Groups (NSGs)
Show answer & explanationAnswer & explanation
Correct answer: B. Network Policies
Kubernetes Network Policies are the native way to specify how groups of pods are allowed to communicate with each other and with other network endpoints. They allow for fine-grained control over network traffic within an AKS cluster, directly addressing the requirement for secure segmentation between containers based on roles.
Why the other options are wrong
- A. Service Endpoints extend your virtual network private address space and identity to Azure services, securing direct connection to services like Storage or SQL Database, not for inter-pod communication control.
- C. Azure Firewall is a managed cloud-based network security service that protects Azure Virtual Network resources, primarily for north-south traffic, not east-west traffic between pods within a cluster.
- D. NSGs are used for filtering network traffic to and from Azure resources at the subnet or NIC level, not for fine-grained control between pods within a Kubernetes cluster.
Kubernetes Network Policies
A specification of how groups of pods are allowed to communicate with each other and with other network endpoints. Network Policies are implemented by a network plugin.
- Control ingress and egress traffic for pods.
- Based on labels and namespaces.
- Allows micro-segmentation within a Kubernetes cluster.
Memory trick: Network Policies are the traffic cops for your pods.