Isolate namespace backend. API Pods may receive TCP 8080 only from frontend Pods labeled role=client. They may reach kube-system DNS on UDP/TCP 53.
Objectifs
- Default-deny ingress and egress for backend
- Allow frontend role=client to backend app=api on TCP 8080
- Allow backend Pods to DNS on TCP and UDP 53
Étapes suggérées
- Namespace selectors match labels, not names, unless you select the standard metadata label.
- DNS commonly needs both UDP and TCP.
- Policies are additive.
Indices
Voir la solution
# Apply one default-deny policy, one ingress allow policy and one DNS egress allow policy. Test positive and negative flows.