Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A DevOps team is deploying a new version of an application to an Azure Kubernetes Service (AKS) cluster. They want to expose the application externally via a public IP address and ensure that incoming traffic is securely routed to the correct service within the cluster. Additionally, they need to manage SSL/TLS termination and potentially implement advanced routing rules based on host or path. Which Kubernetes resource should they configure to achieve this?

  1. AConfigMap for network settings
  2. BIngress resource with an Ingress controller
  3. CService of type NodePort
  4. DService of type ClusterIP
Show answer & explanation

Correct answer: B. Ingress resource with an Ingress controller

An Ingress resource, combined with an Ingress controller (like NGINX Ingress Controller or Azure Application Gateway Ingress Controller), provides HTTP/HTTPS routing from outside the cluster to services within the cluster. It can handle SSL/TLS termination, host-based routing, and path-based routing, fulfilling all the specified requirements.

Why the other options are wrong

  • A. ConfigMaps are for non-sensitive configuration data, not for defining network routing or exposing services externally.
  • C. NodePort exposes a service on a port on each node, which is less managed and suitable for direct external access with advanced routing/TLS.
  • D. ClusterIP exposes a service only within the cluster, not externally.

Kubernetes Ingress

Kubernetes Ingress manages external access to services in a cluster, providing HTTP/HTTPS routing, SSL/TLS termination, and host/path-based routing rules.

  • Exposes services externally.
  • Requires an Ingress Controller (e.g., NGINX, AGIC).
  • Manages SSL/TLS termination.
  • Enables host-based and path-based routing.

Memory trick: Ingress: The Gatekeeper to Your K8s Services.

More Design and implement pipelines questions