Tous les labs

Create default-deny and exact allows

Advanced ~28 mink8s

Isolate namespace backend. API Pods may receive TCP 8080 only from frontend Pods labeled role=client. They may reach kube-system DNS on UDP/TCP 53.

Objectifs
  • Default-deny ingress and egress for backend
  • Allow frontend role=client to backend app=api on TCP 8080
  • Allow backend Pods to DNS on TCP and UDP 53
Étapes suggérées
  1. Namespace selectors match labels, not names, unless you select the standard metadata label.
  2. DNS commonly needs both UDP and TCP.
  3. Policies are additive.
Indices
Voir la solution
# Apply one default-deny policy, one ingress allow policy and one DNS egress allow policy. Test positive and negative flows.