Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard
A cluster operator is investigating network connectivity issues within a Kubernetes cluster. They suspect that Pods in a specific namespace are unable to communicate with Pods in another namespace due to security enforcement. Which Kubernetes resource is primarily used to control traffic flow between Pods based on labels and namespaces?
- ANetworkPolicy
- BService
- CIngress
- DRoute
Show answer & explanationAnswer & explanation
Correct answer: A. NetworkPolicy
NetworkPolicies are Kubernetes resources that define how groups of Pods are allowed to communicate with each other and with external network endpoints. They are crucial for enforcing network segmentation and security policies within a cluster.
Why the other options are wrong
- B. Services provide stable network endpoints for Pods but don't enforce traffic rules.
- C. Ingress manages external access to services within the cluster, not internal Pod-to-Pod communication policy.
- D. Route is a general networking concept, not a specific Kubernetes resource for internal Pod traffic control.
Kubernetes NetworkPolicy
A NetworkPolicy is a Kubernetes resource that specifies how groups of Pods are allowed to communicate with each other and with other network endpoints. It enables network segmentation and security within a cluster.
- Controls inbound (ingress) and outbound (egress) traffic.
- Applies to Pods based on labels.
- Scoped to a specific namespace.
- Requires a network plugin that supports NetworkPolicy.
Memory trick: NetworkPolicy sets the 'No-Go' zones for Pod 'P'aths.