Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium
A cluster administrator needs to ensure that a specific set of Pods can only communicate with other Pods within the same namespace, and deny all traffic from Pods in different namespaces. Which Kubernetes resource should they use to enforce this network segmentation?
- AConfigMap
- BNetworkPolicy
- CIngress
- DService
Show answer & explanationAnswer & explanation
Correct answer: B. NetworkPolicy
NetworkPolicies are Kubernetes resources that allow you to specify how groups of Pods are allowed to communicate with each other and with other network endpoints. They are ideal for enforcing ingress and egress rules based on labels and namespaces.
Why the other options are wrong
- A. A ConfigMap stores non-confidential data in key-value pairs and is not used for network segmentation.
- C. Ingress manages external access to services within the cluster, typically HTTP/S, but not internal Pod-to-Pod segmentation.
- D. A Service provides stable network access to a set of Pods, but does not enforce network segmentation rules.
Kubernetes NetworkPolicy
A Kubernetes resource that controls the network traffic between Pods/namespaces and/or external network endpoints.
- Defines ingress and egress rules for Pods.
- Uses label selectors to identify Pods.
- Enforces network segmentation within the cluster.
Memory trick: NetworkPolicy is like a traffic cop for your Pods, directing who can talk to whom.