Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium
A DevOps team is deploying a new version of an application to an Azure Kubernetes Service (AKS) cluster. They want to expose the application externally via a public IP address and ensure that incoming traffic is securely routed to the correct service within the cluster. Additionally, they need to manage SSL/TLS termination and potentially implement advanced routing rules based on host or path. Which Kubernetes resource should they configure to achieve this?
- AConfigMap for network settings
- BIngress resource with an Ingress controller
- CService of type NodePort
- DService of type ClusterIP
Show answer & explanationAnswer & explanation
Correct answer: B. Ingress resource with an Ingress controller
An Ingress resource, combined with an Ingress controller (like NGINX Ingress Controller or Azure Application Gateway Ingress Controller), provides HTTP/HTTPS routing from outside the cluster to services within the cluster. It can handle SSL/TLS termination, host-based routing, and path-based routing, fulfilling all the specified requirements.
Why the other options are wrong
- A. ConfigMaps are for non-sensitive configuration data, not for defining network routing or exposing services externally.
- C. NodePort exposes a service on a port on each node, which is less managed and suitable for direct external access with advanced routing/TLS.
- D. ClusterIP exposes a service only within the cluster, not externally.
Kubernetes Ingress
Kubernetes Ingress manages external access to services in a cluster, providing HTTP/HTTPS routing, SSL/TLS termination, and host/path-based routing rules.
- Exposes services externally.
- Requires an Ingress Controller (e.g., NGINX, AGIC).
- Manages SSL/TLS termination.
- Enables host-based and path-based routing.
Memory trick: Ingress: The Gatekeeper to Your K8s Services.