Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A DevOps team is deploying a new version of an application to an Azure Kubernetes Service (AKS) cluster. The application consists of several microservices, and they need to expose some of these microservices to external users via HTTP/HTTPS. The team also requires features like SSL termination, load balancing, and URL-based routing to direct traffic to the correct microservice. Which Kubernetes resource should the team use to achieve this?

  1. AService of type `ClusterIP`.
  2. BService of type `NodePort`.
  3. CIngress.
  4. DConfigMap.
Show answer & explanation

Correct answer: C. Ingress.

A Kubernetes Ingress is an API object that manages external access to the services in a cluster, typically HTTP/HTTPS. It can provide load balancing, SSL termination, and name-based virtual hosting (URL-based routing), which perfectly matches the requirements for exposing microservices with advanced traffic management.

Why the other options are wrong

  • A. ClusterIP services are internal to the cluster and not directly accessible externally.
  • B. NodePort services expose a service on each node's IP at a static port, but lack advanced features like SSL termination or URL routing.
  • D. ConfigMaps are used for storing non-sensitive configuration data, not for exposing services.

Kubernetes Ingress

A Kubernetes API object that manages external access to services in a cluster, typically HTTP/HTTPS.

  • Provides HTTP/HTTPS routing, load balancing, SSL termination.
  • Requires an Ingress Controller (e.g., NGINX, Azure Application Gateway).
  • Enables URL-based and name-based virtual hosting.

Memory trick: Ingress is the gateway for web traffic.

More Design and implement pipelines questions