Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard
A cluster operator is configuring a new Kubernetes cluster and wants to ensure that all internal communication between Pods is encrypted by default. Which networking component or feature would be primarily responsible for enforcing such a policy?
- AService Mesh
- BCoreDNS
- Ckube-proxy
- DIngress Controller
Show answer & explanationAnswer & explanation
Correct answer: A. Service Mesh
A Service Mesh, such as Istio or Linkerd, provides advanced networking capabilities including traffic encryption (mTLS), observability, and traffic management for inter-service communication within the cluster. This is the primary tool for enforcing encryption between Pods by default.
Why the other options are wrong
- B. CoreDNS provides DNS resolution for services within the cluster, not encryption.
- C. kube-proxy handles network proxying for Services and load balancing, but does not enforce encryption.
- D. An Ingress Controller manages external access to services within the cluster, typically handling TLS termination for incoming traffic, not internal Pod-to-Pod encryption.
Service Mesh
An infrastructure layer for handling service-to-service communication, providing features like traffic management, security (e.g., mTLS), and observability.
- Manages inter-service communication.
- Offers traffic encryption (mTLS).
- Adds observability and policy enforcement.
Memory trick: Mesh your services for security!