← CKS: Kubernetes security in production
10 / 11 · 60 MIN

Network and admission boundaries during changes

Connect selectors, identities and policy versions to release and containment testing.

Describe the flow before fixing policy

Record source, namespace, labels, destination, protocol and port. If both ends are isolated in the relevant direction, source egress and destination ingress must permit the connection. Working DNS and a listening process help diagnosis but do not replace that authorization. In the exercise’s batch, egress already allows the destination and the issue lies in labels selected by ingress. Use that information to narrow hypotheses. Do not open every source merely because close is approaching; connect the fix to the approved boundary.

Treat labels as a release contract

A supplier changes role=settler to role=worker to standardize manifests. Policy still selects the prior value and a fresh connection fails. The technical manager should include selectors in label-change impact, just as API consumers are included. For a peer containing only podSelector, scope is the policy namespace; do not assume every namespace. Testing should compare an authorized client with one that must be denied. Retain labels actually deployed rather than only the template someone intended to use in the window.

Choose a control that understands the requirement

Allowing /status and blocking /admin on the same port is an application condition. Standard NetworkPolicy offers no HTTP-path field for that decision. Combine the network boundary with appropriate authorization in the service or proxy according to architecture. Likewise, runtimeClassName:sandbox does not itself establish the intended isolation. Confirm handler, configuration and limitations. Architecture review should connect each requirement to the mechanism enforcing it and to observable evidence, avoiding acceptance of an object name as proof of sufficient protection.

Assess exceptions by Pod-creating identity

A Pod Security Admission exemption does not automatically retain warn and audit while bypassing enforce: all three modes are skipped for covered requests. Also, exempting a Deployment author does not exempt the different identity creating Pods. Before proposing controller exemption, consider its reach across every workload that controller can create. Prefer correcting the template and validating functional requirements. Any exception needs explicit scope, owner, deadline and an observation method that continues supplying the evidence operations needs.

Control the baseline and containment meaning

Pinning a rehearsed PSA version makes the baseline explicit during an upgrade; it also requires later review planning. Using latest does not provide an immutable minor baseline. In incident response, distinguish another boundary: policy blocking fresh connections may not end existing sessions, depending on the plugin. In the exercise, the old flow keeps transferring bytes. That observation contradicts a complete-containment claim. Apply the authorized mechanism covering that flow while preserving evidence and healthy capacity according to the agreed response plan.

Build acceptance criteria per change

For a release, check deployed configuration, identity used, allowed paths and prohibited paths. For containment, add existing sessions and the executed action’s outcome. For an upgrade, record the rehearsed policy version and who assesses the next one. Organize handover around verifiable claims, such as client A can connect or client B is denied, with timing and evidence. These criteria help APS repeat diagnosis without depending on the manifest author. Practice here is synthetic; an authorized lab remains necessary to observe actual plugin and cluster behavior.

IN PRACTICE

A fresh connection is denied after containment but the old session continues: incident response must also address that flow.

Common pitfalls

Assuming ingress suffices; confusing port names with HTTP paths; broadly exempting controllers; claiming containment from fresh connections alone.

Related topics: NetworkPolicy and selectors · PSA and incident response

Take this idea with you

A useful boundary retains the approved flow and demonstrates intended denial under the change’s actual conditions.

Create account

Reference: Network policies · Kubernetes v1.35; current six-domain CKS outline

Kubernetes® and CKS are trademarks or registered trademarks of The Linux Foundation. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by The Linux Foundation. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.