Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A startup is deploying a multi-tier application to Azure Kubernetes Service (AKS). The application consists of a front-end web service and a back-end API service, each running in separate namespaces. The security team requires that the front-end service can only communicate with the back-end service, and the back-end service cannot initiate outbound connections to the internet. Which Kubernetes security construct should be used to enforce these communication restrictions?
- AService Mesh (e.g., Istio)
- BAzure Firewall
- CNetwork Policies
- DIngress Controller
Show answer & explanationAnswer & explanation
Correct answer: C. Network Policies
Kubernetes Network Policies are the native Kubernetes resource designed to control network traffic flow between pods/namespaces within an AKS cluster. They can enforce both ingress (front-end to back-end) and egress (back-end to no internet) restrictions.
Why the other options are wrong
- A. A Service Mesh provides advanced traffic management, observability, and security features, but Network Policies are the fundamental construct for enforcing communication restrictions at the network layer.
- B. Azure Firewall is a cloud-native network security service that protects Azure Virtual Network resources, typically used for VNet-level or external network traffic filtering, not granular pod-to-pod within a cluster.
- D. An Ingress Controller manages external access to services within the cluster, typically for HTTP/S routing, and does not control internal pod-to-pod or pod-to-external communication restrictions.
Kubernetes Network Policies
A Kubernetes resource that defines how pods are allowed to communicate with each other and with other network endpoints.
- Operate at Layer 3/4 of the OSI model.
- Enforce both ingress (inbound) and egress (outbound) rules.
- Applied to pods based on labels and namespaces.
Memory trick: Network Policies: Your cluster's traffic cop for pods.