Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A startup is deploying a multi-tier application to Azure Kubernetes Service (AKS). The application consists of a web frontend, an API backend, and a database service, all running as separate pods. The security team requires that the web frontend can only communicate with the API backend, and the API backend can only communicate with the database service. No direct communication should be allowed between the web frontend and the database service, or between pods within the same tier (e.g., frontend-to-frontend). Which AKS security feature should be configured to enforce these communication restrictions?
- AAzure Network Security Groups (NSGs).
- BKubernetes Network Policies.
- CAzure Firewall.
- DService mesh (e.g., Istio) with traffic rules.
Show answer & explanationAnswer & explanation
Correct answer: B. Kubernetes Network Policies.
Kubernetes Network Policies are specifically designed to control communication between pods within an AKS cluster. They allow you to define rules that specify which pods are allowed to communicate with each other, based on labels, namespaces, and IP ranges, directly addressing the requirement for granular inter-pod communication control.
Why the other options are wrong
- A. NSGs operate at the VNet/subnet level and cannot provide granular control over inter-pod communication within an AKS cluster.
- C. Azure Firewall filters traffic between VNets or to/from the internet, not between pods within a single AKS cluster.
- D. While a service mesh can provide advanced traffic management, Network Policies are the native and more fundamental Kubernetes mechanism for enforcing basic inter-pod communication restrictions.
Kubernetes Network Policies
Specifications that define how groups of pods are allowed to communicate with each other and other network endpoints. They enable granular control over network traffic within a Kubernetes cluster.
- Control pod-to-pod communication.
- Based on labels, namespaces, IP ranges.
- Enforce traffic segmentation within the cluster.
Memory trick: Network Policies are the 'traffic cops' of your AKS cluster, directing who can talk to whom.