Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard
A cluster operator is investigating network connectivity issues within a Kubernetes cluster. They notice that Pods within a specific Deployment can communicate with each other, but they cannot reach Pods in a different Namespace, even though both Deployments are exposed via ClusterIP Services. What is the most likely reason for this isolation?
- AThe ClusterIP Services are only accessible within their own Namespace.
- BThe Pods in different Namespaces have conflicting IP addresses.
- CThe `kube-proxy` component is misconfigured on the worker nodes.
- DNetworkPolicy objects are configured to restrict cross-Namespace communication.
Show answer & explanationAnswer & explanation
Correct answer: D. NetworkPolicy objects are configured to restrict cross-Namespace communication.
Kubernetes Namespaces provide logical isolation, but by default, Pods across Namespaces can communicate. NetworkPolicies are the mechanism used to enforce network isolation rules, including restricting traffic between Namespaces.
Why the other options are wrong
- A. ClusterIP Services are accessible cluster-wide by default, not just within their own Namespace, using their fully qualified domain name (e.g., `service-name.namespace-name.svc.cluster.local`).
- B. Kubernetes' CNI plugin ensures unique IP addresses for Pods across the cluster, regardless of Namespace.
- C. Misconfigured `kube-proxy` would likely cause broader network issues, potentially affecting communication even within the same Namespace or preventing Service IP resolution entirely, rather than selective cross-Namespace blocking.
Kubernetes NetworkPolicy
A NetworkPolicy specifies how groups of Pods are allowed to communicate with each other and other network endpoints. It provides network segmentation at the Pod level.
- Namespace-scoped resource.
- Defines ingress and egress rules.
- Applies to Pods selected by labels.
- Must be enforced by a CNI plugin that supports NetworkPolicy (e.g., Calico, Cilium).
Memory trick: Network Policies Protect Pods' Paths