Microsoft Certified: Azure Developer Associate (AZ-204)Develop Azure compute solutionsHard

A company is developing a new application with several microservices deployed to Azure Kubernetes Service (AKS). One of the microservices is a critical payment processing service that requires enhanced network isolation and dedicated compute resources to meet strict compliance requirements. The company wants to ensure that this specific microservice runs on dedicated nodes within the AKS cluster, separate from other less sensitive workloads. Which AKS feature should be used to achieve this isolation?

  1. ANode Pools
  2. BIngress Controller
  3. CNetwork Security Groups
  4. DPod Security Policies
Show answer & explanation

Correct answer: A. Node Pools

AKS Node Pools allow you to group nodes with different configurations (e.g., VM sizes, operating systems, taints/labels) within the same cluster. By creating a dedicated node pool for the payment processing service and using node taints and tolerations, you can ensure that only specific pods (like the payment service) are scheduled onto these isolated, dedicated nodes, providing enhanced network isolation and dedicated compute resources.

Why the other options are wrong

  • B. An Ingress Controller manages external access to services in a cluster, typically HTTP/S, and does not provide compute isolation for specific workloads.
  • C. Network Security Groups (NSGs) control network traffic at the IP address and port level, but they do not provide logical isolation of compute resources within an AKS cluster itself.
  • D. Pod Security Policies (PSPs) enforce security standards for pods, such as preventing privileged containers, but they do not provide dedicated compute isolation for pods on specific nodes.

AKS Node Pools

Groups of nodes within an AKS cluster that share the same configuration, allowing for dedicated compute resources for specific workloads.

  • Supports different VM sizes, OS types, and configurations
  • Enables workload isolation (e.g., using taints and tolerations)
  • Allows for separate scaling and upgrades for different workloads

Memory trick: Node Pools are for Niche workloads on specific Nodes.

More Develop Azure compute solutions questions