Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium

A cluster operator is observing unusual network traffic patterns within a Kubernetes cluster. They suspect a misconfigured Pod is attempting to communicate with unauthorized external services. Which Kubernetes resource, when applied, can restrict outbound network traffic from specific Pods?

  1. ANetworkPolicy
  2. BService
  3. CEndpointSlice
  4. DIngress
Show answer & explanation

Correct answer: A. NetworkPolicy

A NetworkPolicy object allows you to define rules for how Pods are allowed to communicate with each other and with external network endpoints. It can explicitly restrict both inbound (ingress) and outbound (egress) traffic for selected Pods.

Why the other options are wrong

  • B. A Service defines a logical set of Pods and a policy by which to access them, but does not control network traffic restrictions.
  • C. EndpointSlices are a more scalable alternative to Endpoints, listing network endpoints for a Service, but they do not control traffic flow.
  • D. Ingress manages external access to services within the cluster, primarily for HTTP/HTTPS traffic, not internal Pod egress restrictions.

Kubernetes NetworkPolicy

A Kubernetes resource that specifies how groups of Pods are allowed to communicate with each other and with other network endpoints, acting as a firewall for Pods.

  • Controls Pod ingress and egress traffic.
  • Applies to selected Pods.
  • Requires a CNI plugin that supports NetworkPolicy.

Memory trick: NetworkPolicy: Police the network traffic!

More Kubernetes Fundamentals questions