[{"data":1,"prerenderedAt":1402},["ShallowReactive",2],{"sidebar-course-\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking":3,"i-lucide:chevron-down":51,"i-lucide:search":55,"i-lucide:sun":57,"i-lucide:moon":59,"i-lucide:arrow-right":61,"i-lucide:menu":63,"i-lucide:panel-left":65,"i-lucide:mail":67,"i-simple-icons:x":69,"i-simple-icons:linkedin":71,"i-simple-icons:dribbble":73,"i-simple-icons:github":75,"lessons-\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking":77,"sidebar-quiz-\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking":1234,"i-lucide:network":1235,"i-lucide:circle-check-big":1237,"i-lucide:printer":1239,"i-lucide:graduation-cap":1241,"i-lucide:book-marked":1243,"i-lucide:notebook-pen":1245,"quiz-\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking":1247,"quiz-topic-\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking":1385,"i-lucide:chevron-right":1398,"i-lucide:percent":1400},{"id":4,"title":5,"access":6,"body":7,"description":14,"draft":15,"estimatedMinutes":16,"extension":17,"featured":18,"icon":19,"lang":20,"level":21,"meta":22,"navigation":18,"order":23,"path":24,"prerequisites":25,"resources":27,"seo":38,"sku":39,"stem":40,"subjects":41,"summary":43,"tags":44,"updated":49,"__hash__":50},"courses\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002Findex.md","Kubernetes Networking","free",{"type":8,"value":9,"toc":10},"minimark",[],{"title":11,"searchDepth":12,"depth":12,"links":13},"",3,[],"Services, Ingress and network policy — how a packet actually reaches a pod.",false,45,"md",true,"lucide:network","en","intermediate",{},2,"\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking",[26],"\u002Flearn\u002Fen\u002Fkubernetes\u002Fpods",[28,32],{"label":29,"file":30,"access":6,"size":31},"Service types cheat sheet","k8s-service-types.pdf","180 KB",{"label":33,"file":34,"access":35,"sku":36,"size":37},"NetworkPolicy recipe pack","k8s-network-policies.pdf","premium","res-k8s-netpol","640 KB",{"title":5,"description":14},null,"learn\u002Fen\u002Fcourses\u002Fnetworking\u002Findex",[42],"kubernetes","Kubernetes networking rests on one rule: every pod gets its own IP and can\nreach every other pod without NAT. Everything above that — Services, Ingress,\nNetworkPolicy — exists because pod IPs are not stable and not exposed.\nServices give you a stable virtual IP and load balancing. Ingress puts an\nHTTP router in front of Services so many hostnames share one entry point.\nNetworkPolicy takes the default-allow flat network and narrows it down. Get\nthose three roles clear and the failure modes stop being mysterious.\n",[45,46,47,48],"networking","services","ingress","cni","2026-08-06","GumIppvDWYP1scgT_rOvScFGIQ-Wqs-Uax-NJtxnUbU",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":54},0,24,"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m6 9l6 6l6-6\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":56},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"m21 21l-4.34-4.34\"\u002F>\u003Ccircle cx=\"11\" cy=\"11\" r=\"8\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":58},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"4\"\u002F>\u003Cpath d=\"M12 2v2m0 16v2M4.93 4.93l1.41 1.41m11.32 11.32l1.41 1.41M2 12h2m16 0h2M6.34 17.66l-1.41 1.41M19.07 4.93l-1.41 1.41\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":60},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M20.985 12.486a9 9 0 1 1-9.473-9.472c.405-.022.617.46.402.803a6 6 0 0 0 8.268 8.268c.344-.215.825-.004.803.401\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":62},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 12h14m-7-7l7 7l-7 7\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":64},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":66},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Crect width=\"18\" height=\"18\" x=\"3\" y=\"3\" rx=\"2\"\u002F>\u003Cpath d=\"M9 3v18\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":68},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"m22 7l-8.991 5.727a2 2 0 0 1-2.009 0L2 7\"\u002F>\u003Crect width=\"20\" height=\"16\" x=\"2\" y=\"4\" rx=\"2\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":70},"\u003Cpath fill=\"currentColor\" d=\"M14.234 10.162L22.977 0h-2.072l-7.591 8.824L7.251 0H.258l9.168 13.343L.258 24H2.33l8.016-9.318L16.749 24h6.993zm-2.837 3.299l-.929-1.329L3.076 1.56h3.182l5.965 8.532l.929 1.329l7.754 11.09h-3.182z\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":72,"hidden":18},"\u003Cpath fill=\"currentColor\" d=\"M20.447 20.452h-3.554v-5.569c0-1.328-.027-3.037-1.852-3.037c-1.853 0-2.136 1.445-2.136 2.939v5.667H9.351V9h3.414v1.561h.046c.477-.9 1.637-1.85 3.37-1.85c3.601 0 4.267 2.37 4.267 5.455v6.286zM5.337 7.433a2.06 2.06 0 0 1-2.063-2.065a2.064 2.064 0 1 1 2.063 2.065m1.782 13.019H3.555V9h3.564zM22.225 0H1.771C.792 0 0 .774 0 1.729v20.542C0 23.227.792 24 1.771 24h20.451C23.2 24 24 23.227 24 22.271V1.729C24 .774 23.2 0 22.222 0z\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":74},"\u003Cpath fill=\"currentColor\" d=\"M12 24C5.385 24 0 18.615 0 12S5.385 0 12 0s12 5.385 12 12s-5.385 12-12 12m10.12-10.358c-.35-.11-3.17-.953-6.384-.438c1.34 3.684 1.887 6.684 1.992 7.308a10.28 10.28 0 0 0 4.395-6.87zm-6.115 7.808c-.153-.9-.75-4.032-2.19-7.77l-.066.02c-5.79 2.015-7.86 6.025-8.04 6.4a10.16 10.16 0 0 0 6.29 2.166c1.42 0 2.77-.29 4-.814zm-11.62-2.58c.232-.4 3.045-5.055 8.332-6.765q.202-.067.405-.12q-.392-.879-.832-1.74C7.17 11.775 2.206 11.71 1.756 11.7l-.004.312c0 2.633.998 5.037 2.634 6.855zm-2.42-8.955c.46.008 4.683.026 9.477-1.248a66 66 0 0 0-3.8-5.928a10.28 10.28 0 0 0-5.676 7.17zM9.6 2.052c.282.38 2.145 2.914 3.822 6c3.645-1.365 5.19-3.44 5.373-3.702A10.2 10.2 0 0 0 12 1.764c-.825 0-1.63.1-2.4.285zm10.335 3.483c-.218.29-1.935 2.493-5.724 4.04c.24.49.47.985.68 1.486c.08.18.15.36.22.53c3.41-.43 6.8.26 7.14.33c-.02-2.42-.88-4.64-2.31-6.38z\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":76},"\u003Cpath fill=\"currentColor\" d=\"M12 .297c-6.63 0-12 5.373-12 12c0 5.303 3.438 9.8 8.205 11.385c.6.113.82-.258.82-.577c0-.285-.01-1.04-.015-2.04c-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729c1.205.084 1.838 1.236 1.838 1.236c1.07 1.835 2.809 1.305 3.495.998c.108-.776.417-1.305.76-1.605c-2.665-.3-5.466-1.332-5.466-5.93c0-1.31.465-2.38 1.235-3.22c-.135-.303-.54-1.523.105-3.176c0 0 1.005-.322 3.3 1.23c.96-.267 1.98-.399 3-.405c1.02.006 2.04.138 3 .405c2.28-1.552 3.285-1.23 3.285-1.23c.645 1.653.24 2.873.12 3.176c.765.84 1.23 1.91 1.23 3.22c0 4.61-2.805 5.625-5.475 5.92c.42.36.81 1.096.81 2.22c0 1.606-.015 2.896-.015 3.286c0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12\"\u002F>",[78,428,859],{"id":79,"title":80,"access":6,"body":81,"description":422,"extension":17,"lang":20,"meta":423,"navigation":18,"order":123,"partial":15,"path":424,"seo":425,"stem":426,"__hash__":427},"lessons\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002F01.services.md","Services",{"type":8,"value":82,"toc":415},[83,86,90,98,103,111,225,232,238,242,311,317,321,328,331,345,349,358,361,365,372,408,411],[84,85,80],"h1",{"id":46},[87,88,89],"p",{},"A pod IP is an unstable identifier. Pods are rescheduled, replaced on deploy, and\nscaled in and out. Anything that hard-codes a pod IP breaks on the first restart.",[87,91,92,93,97],{},"A ",[94,95,96],"strong",{},"Service"," is a stable name and virtual IP in front of a changing set of pods.",[99,100,102],"h2",{"id":101},"how-the-selector-works","How the selector works",[87,104,105,106,110],{},"A Service does not reference pods directly. It declares a label selector, and a\ncontroller keeps a matching ",[107,108,109],"code",{},"EndpointSlice"," up to date:",[112,113,117],"pre",{"className":114,"code":115,"language":116,"meta":11,"style":11},"language-yaml shiki shiki-themes github-dark-dimmed github-dark-dimmed","apiVersion: v1\nkind: Service\nmetadata:\n  name: payments\nspec:\n  selector:\n    app: payments\n  ports:\n    - port: 80\n      targetPort: 8080\n","yaml",[107,118,119,136,146,154,165,173,181,191,199,214],{"__ignoreMap":11},[120,121,124,128,132],"span",{"class":122,"line":123},"line",1,[120,125,127],{"class":126},"sza-u","apiVersion",[120,129,131],{"class":130},"sM9_K",": ",[120,133,135],{"class":134},"szYpP","v1\n",[120,137,138,141,143],{"class":122,"line":23},[120,139,140],{"class":126},"kind",[120,142,131],{"class":130},[120,144,145],{"class":134},"Service\n",[120,147,148,151],{"class":122,"line":12},[120,149,150],{"class":126},"metadata",[120,152,153],{"class":130},":\n",[120,155,157,160,162],{"class":122,"line":156},4,[120,158,159],{"class":126},"  name",[120,161,131],{"class":130},[120,163,164],{"class":134},"payments\n",[120,166,168,171],{"class":122,"line":167},5,[120,169,170],{"class":126},"spec",[120,172,153],{"class":130},[120,174,176,179],{"class":122,"line":175},6,[120,177,178],{"class":126},"  selector",[120,180,153],{"class":130},[120,182,184,187,189],{"class":122,"line":183},7,[120,185,186],{"class":126},"    app",[120,188,131],{"class":130},[120,190,164],{"class":134},[120,192,194,197],{"class":122,"line":193},8,[120,195,196],{"class":126},"  ports",[120,198,153],{"class":130},[120,200,202,205,208,210],{"class":122,"line":201},9,[120,203,204],{"class":130},"    - ",[120,206,207],{"class":126},"port",[120,209,131],{"class":130},[120,211,213],{"class":212},"sQdni","80\n",[120,215,217,220,222],{"class":122,"line":216},10,[120,218,219],{"class":126},"      targetPort",[120,221,131],{"class":130},[120,223,224],{"class":212},"8080\n",[87,226,227,228,231],{},"Any pod carrying ",[107,229,230],{},"app: payments"," and passing its readiness probe is added to the\nendpoint list. Any pod that fails readiness is removed. This is the reconciliation\nmodel again: the Service is a declaration, the endpoint list is reality, and a\ncontroller closes the gap.",[233,234,235],"note",{},[87,236,237],{},"A Service with a selector that matches nothing is not an error. It is an empty\nendpoint list, and connections to it fail with connection refused rather than a\nclear message. This is the single most common \"my Service is broken\" cause.",[99,239,241],{"id":240},"the-three-types","The three types",[243,244,245,261],"table",{},[246,247,248],"thead",{},[249,250,251,255,258],"tr",{},[252,253,254],"th",{},"Type",[252,256,257],{},"Allocates",[252,259,260],{},"Reachable from",[262,263,264,278,295],"tbody",{},[249,265,266,272,275],{},[267,268,269],"td",{},[107,270,271],{},"ClusterIP",[267,273,274],{},"A virtual IP inside the cluster",[267,276,277],{},"Inside the cluster only",[249,279,280,285,292],{},[267,281,282],{},[107,283,284],{},"NodePort",[267,286,287,288,291],{},"A ClusterIP ",[94,289,290],{},"plus"," the same port on every node",[267,293,294],{},"Anything that can reach a node",[249,296,297,302,308],{},[267,298,299],{},[107,300,301],{},"LoadBalancer",[267,303,304,305,307],{},"A NodePort ",[94,306,290],{}," an external load balancer",[267,309,310],{},"The internet, via the cloud provider",[87,312,313,314,316],{},"The types are cumulative, not alternatives. A ",[107,315,301],{}," Service still has a\nClusterIP and still has a node port — the cloud controller simply provisions an\nexternal balancer that points at those node ports.",[99,318,320],{"id":319},"what-clusterip-really-is","What ClusterIP really is",[87,322,323,324,327],{},"The ClusterIP is not assigned to any interface. Nothing answers ARP for it. It\nexists only as a set of rules in each node's kernel — iptables or IPVS entries\ninstalled by ",[107,325,326],{},"kube-proxy"," — that rewrite the destination address to a real pod IP\nas the packet leaves.",[87,329,330],{},"That has a practical consequence worth internalising:",[332,333,334],"warning",{},[87,335,336,337,340,341,344],{},"You cannot ",[107,338,339],{},"ping"," a ClusterIP. There is no host to answer ICMP — only DNAT rules\nfor the ports the Service declares. A failed ping proves nothing about whether\nthe Service works. Test with ",[107,342,343],{},"curl"," against a declared port instead.",[99,346,348],{"id":347},"load-balancing-granularity","Load balancing granularity",[87,350,351,353,354,357],{},[107,352,326],{}," picks an endpoint per ",[94,355,356],{},"connection",", not per request. For HTTP\u002F1.1\nwith connection reuse, and especially for HTTP\u002F2 and gRPC where a single long-lived\nconnection carries every request, this means traffic pins to one pod.",[87,359,360],{},"This is why gRPC services behind a plain ClusterIP often show badly skewed load.\nThe fix is client-side load balancing, a proxy that understands HTTP\u002F2, or a\nservice mesh — not a different Service type.",[99,362,364],{"id":363},"headless-services","Headless Services",[87,366,367,368,371],{},"Setting ",[107,369,370],{},"clusterIP: None"," disables the virtual IP entirely. DNS then returns the\npod IPs directly, one A record per ready endpoint:",[112,373,375],{"className":114,"code":374,"language":116,"meta":11,"style":11},"spec:\n  clusterIP: None\n  selector:\n    app: cassandra\n",[107,376,377,383,393,399],{"__ignoreMap":11},[120,378,379,381],{"class":122,"line":123},[120,380,170],{"class":126},[120,382,153],{"class":130},[120,384,385,388,390],{"class":122,"line":23},[120,386,387],{"class":126},"  clusterIP",[120,389,131],{"class":130},[120,391,392],{"class":134},"None\n",[120,394,395,397],{"class":122,"line":12},[120,396,178],{"class":126},[120,398,153],{"class":130},[120,400,401,403,405],{"class":122,"line":156},[120,402,186],{"class":126},[120,404,131],{"class":130},[120,406,407],{"class":134},"cassandra\n",[87,409,410],{},"This is what StatefulSets use. When each replica is individually addressable and\nidentity matters — database members, brokers, anything with a quorum — you want\nthe caller to see the real topology rather than a single virtual IP hiding it.",[412,413,414],"style",{},"html pre.shiki code .sza-u, html code.shiki .sza-u{--shiki-default:#8DDB8C;--shiki-dark:#8DDB8C}html pre.shiki code .sM9_K, html code.shiki .sM9_K{--shiki-default:#ADBAC7;--shiki-dark:#ADBAC7}html pre.shiki code .szYpP, html code.shiki .szYpP{--shiki-default:#96D0FF;--shiki-dark:#96D0FF}html pre.shiki code .sQdni, html code.shiki .sQdni{--shiki-default:#6CB6FF;--shiki-dark:#6CB6FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":11,"searchDepth":12,"depth":12,"links":416},[417,418,419,420,421],{"id":101,"depth":23,"text":102},{"id":240,"depth":23,"text":241},{"id":319,"depth":23,"text":320},{"id":347,"depth":23,"text":348},{"id":363,"depth":23,"text":364},"ClusterIP, NodePort and LoadBalancer, and what each one actually allocates.",{},"\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002Fservices",{"title":80,"description":422},"learn\u002Fen\u002Fcourses\u002Fnetworking\u002F01.services","6w0dHzL6jKSzV2gpGWIKGGQgiq8FUOgmMB__4BLHel8",{"id":429,"title":430,"access":6,"body":431,"description":853,"extension":17,"lang":20,"meta":854,"navigation":18,"order":23,"partial":15,"path":855,"seo":856,"stem":857,"__hash__":858},"lessons\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002F02.ingress.md","Ingress",{"type":8,"value":432,"toc":846},[433,435,440,444,451,464,468,685,691,695,743,768,773,777,821,828,834,838,841,844],[84,434,430],{"id":47},[87,436,92,437,439],{},[107,438,301],{}," Service gives you one external IP per Service. Thirty services\nmeans thirty load balancers and thirty bills. Ingress exists to collapse that into\none entry point that routes by hostname and path.",[99,441,443],{"id":442},"the-resource-is-only-a-declaration","The resource is only a declaration",[87,445,446,447,450],{},"This is the part that catches people out. An Ingress object is inert. It describes\nrouting rules; it does not implement them. Without an ",[94,448,449],{},"ingress controller"," running\nin the cluster — ingress-nginx, Traefik, HAProxy, a cloud-native one — creating an\nIngress does exactly nothing.",[332,452,453],{},[87,454,455,456,459,460,463],{},"An Ingress with no controller stays in a permanent pending state with no address,\nand produces no events explaining why. If ",[107,457,458],{},"kubectl get ingress"," shows an empty\n",[107,461,462],{},"ADDRESS"," column and nothing is logged, check whether a controller is installed\nbefore debugging the rules.",[99,465,467],{"id":466},"a-minimal-rule-set","A minimal rule set",[112,469,471],{"className":114,"code":470,"language":116,"meta":11,"style":11},"apiVersion: networking.k8s.io\u002Fv1\nkind: Ingress\nmetadata:\n  name: storefront\nspec:\n  ingressClassName: nginx\n  rules:\n    - host: shop.example.com\n      http:\n        paths:\n          - path: \u002Fapi\n            pathType: Prefix\n            backend:\n              service:\n                name: api\n                port:\n                  number: 80\n          - path: \u002F\n            pathType: Prefix\n            backend:\n              service:\n                name: web\n                port:\n                  number: 80\n",[107,472,473,482,491,497,506,512,522,529,541,548,555,569,580,588,596,607,615,625,637,646,653,660,670,677],{"__ignoreMap":11},[120,474,475,477,479],{"class":122,"line":123},[120,476,127],{"class":126},[120,478,131],{"class":130},[120,480,481],{"class":134},"networking.k8s.io\u002Fv1\n",[120,483,484,486,488],{"class":122,"line":23},[120,485,140],{"class":126},[120,487,131],{"class":130},[120,489,490],{"class":134},"Ingress\n",[120,492,493,495],{"class":122,"line":12},[120,494,150],{"class":126},[120,496,153],{"class":130},[120,498,499,501,503],{"class":122,"line":156},[120,500,159],{"class":126},[120,502,131],{"class":130},[120,504,505],{"class":134},"storefront\n",[120,507,508,510],{"class":122,"line":167},[120,509,170],{"class":126},[120,511,153],{"class":130},[120,513,514,517,519],{"class":122,"line":175},[120,515,516],{"class":126},"  ingressClassName",[120,518,131],{"class":130},[120,520,521],{"class":134},"nginx\n",[120,523,524,527],{"class":122,"line":183},[120,525,526],{"class":126},"  rules",[120,528,153],{"class":130},[120,530,531,533,536,538],{"class":122,"line":193},[120,532,204],{"class":130},[120,534,535],{"class":126},"host",[120,537,131],{"class":130},[120,539,540],{"class":134},"shop.example.com\n",[120,542,543,546],{"class":122,"line":201},[120,544,545],{"class":126},"      http",[120,547,153],{"class":130},[120,549,550,553],{"class":122,"line":216},[120,551,552],{"class":126},"        paths",[120,554,153],{"class":130},[120,556,558,561,564,566],{"class":122,"line":557},11,[120,559,560],{"class":130},"          - ",[120,562,563],{"class":126},"path",[120,565,131],{"class":130},[120,567,568],{"class":134},"\u002Fapi\n",[120,570,572,575,577],{"class":122,"line":571},12,[120,573,574],{"class":126},"            pathType",[120,576,131],{"class":130},[120,578,579],{"class":134},"Prefix\n",[120,581,583,586],{"class":122,"line":582},13,[120,584,585],{"class":126},"            backend",[120,587,153],{"class":130},[120,589,591,594],{"class":122,"line":590},14,[120,592,593],{"class":126},"              service",[120,595,153],{"class":130},[120,597,599,602,604],{"class":122,"line":598},15,[120,600,601],{"class":126},"                name",[120,603,131],{"class":130},[120,605,606],{"class":134},"api\n",[120,608,610,613],{"class":122,"line":609},16,[120,611,612],{"class":126},"                port",[120,614,153],{"class":130},[120,616,618,621,623],{"class":122,"line":617},17,[120,619,620],{"class":126},"                  number",[120,622,131],{"class":130},[120,624,213],{"class":212},[120,626,628,630,632,634],{"class":122,"line":627},18,[120,629,560],{"class":130},[120,631,563],{"class":126},[120,633,131],{"class":130},[120,635,636],{"class":134},"\u002F\n",[120,638,640,642,644],{"class":122,"line":639},19,[120,641,574],{"class":126},[120,643,131],{"class":130},[120,645,579],{"class":134},[120,647,649,651],{"class":122,"line":648},20,[120,650,585],{"class":126},[120,652,153],{"class":130},[120,654,656,658],{"class":122,"line":655},21,[120,657,593],{"class":126},[120,659,153],{"class":130},[120,661,663,665,667],{"class":122,"line":662},22,[120,664,601],{"class":126},[120,666,131],{"class":130},[120,668,669],{"class":134},"web\n",[120,671,673,675],{"class":122,"line":672},23,[120,674,612],{"class":126},[120,676,153],{"class":130},[120,678,679,681,683],{"class":122,"line":53},[120,680,620],{"class":126},[120,682,131],{"class":130},[120,684,213],{"class":212},[87,686,687,690],{},[107,688,689],{},"ingressClassName"," decides which controller claims this object. With two controllers\ninstalled and no class set, either both claim it or neither does — both outcomes are\nconfusing to debug.",[99,692,694],{"id":693},"pathtype-matters-more-than-it-looks","pathType matters more than it looks",[243,696,697,707],{},[246,698,699],{},[249,700,701,704],{},[252,702,703],{},"Value",[252,705,706],{},"Matches",[262,708,709,719,733],{},[249,710,711,716],{},[267,712,713],{},[107,714,715],{},"Exact",[267,717,718],{},"The path string exactly, case-sensitive",[249,720,721,726],{},[267,722,723],{},[107,724,725],{},"Prefix",[267,727,728,729,732],{},"Split on ",[107,730,731],{},"\u002F",", element by element",[249,734,735,740],{},[267,736,737],{},[107,738,739],{},"ImplementationSpecific",[267,741,742],{},"Whatever the controller decides",[87,744,745,747,748,752,753,756,757,759,760,763,764,767],{},[107,746,725],{}," compares path ",[749,750,751],"em",{},"elements",", not characters. ",[107,754,755],{},"\u002Fapi"," matches ",[107,758,755],{}," and\n",[107,761,762],{},"\u002Fapi\u002Forders",", but not ",[107,765,766],{},"\u002Fapiary",". That distinction surprises people expecting a\nplain string prefix.",[87,769,770,772],{},[107,771,739],{}," is where portability quietly dies — an ingress-nginx regex\npath will not survive a move to a different controller.",[99,774,776],{"id":775},"tls","TLS",[112,778,780],{"className":114,"code":779,"language":116,"meta":11,"style":11},"spec:\n  tls:\n    - hosts:\n        - shop.example.com\n      secretName: shop-tls\n",[107,781,782,788,795,804,811],{"__ignoreMap":11},[120,783,784,786],{"class":122,"line":123},[120,785,170],{"class":126},[120,787,153],{"class":130},[120,789,790,793],{"class":122,"line":23},[120,791,792],{"class":126},"  tls",[120,794,153],{"class":130},[120,796,797,799,802],{"class":122,"line":12},[120,798,204],{"class":130},[120,800,801],{"class":126},"hosts",[120,803,153],{"class":130},[120,805,806,809],{"class":122,"line":156},[120,807,808],{"class":130},"        - ",[120,810,540],{"class":134},[120,812,813,816,818],{"class":122,"line":167},[120,814,815],{"class":126},"      secretName",[120,817,131],{"class":130},[120,819,820],{"class":134},"shop-tls\n",[87,822,823,824,827],{},"The Secret must be type ",[107,825,826],{},"kubernetes.io\u002Ftls",", must live in the same namespace as the\nIngress, and must already exist. A missing Secret does not block the Ingress from\nbeing created — it just serves the controller's default self-signed certificate,\nwhich looks like a certificate problem rather than a missing-object problem.",[829,830,831],"tip",{},[87,832,833],{},"In practice you rarely create these by hand. cert-manager watches Ingress objects\nand issues certificates automatically from an ACME issuer such as Let's Encrypt.",[99,835,837],{"id":836},"when-ingress-is-not-enough","When Ingress is not enough",[87,839,840],{},"Ingress only models HTTP and HTTPS. Raw TCP, UDP, gRPC routing rules and weighted\ntraffic splits all sit outside the spec, which is why every controller grew its own\nannotations — and why those annotations do not port between controllers.",[87,842,843],{},"The Gateway API is the successor that models these properly, with separate resources\nfor infrastructure and routing. New clusters should look at it before committing to\ncontroller-specific annotations.",[412,845,414],{},{"title":11,"searchDepth":12,"depth":12,"links":847},[848,849,850,851,852],{"id":442,"depth":23,"text":443},{"id":466,"depth":23,"text":467},{"id":693,"depth":23,"text":694},{"id":775,"depth":23,"text":776},{"id":836,"depth":23,"text":837},"HTTP routing in front of Services, and why the resource does nothing on its own.",{},"\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002Fingress",{"title":430,"description":853},"learn\u002Fen\u002Fcourses\u002Fnetworking\u002F02.ingress","ijcTN78jYH-ktpYMTtKJTvnbYvlGui3oJDXv_cjRfNA",{"id":860,"title":861,"access":6,"body":862,"description":1228,"extension":17,"lang":20,"meta":1229,"navigation":18,"order":12,"partial":15,"path":1230,"seo":1231,"stem":1232,"__hash__":1233},"lessons\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002F03.network-policies.md","Network policies",{"type":8,"value":863,"toc":1222},[864,867,870,876,880,887,1025,1032,1056,1060,1070,1116,1128,1132,1135,1145,1149,1152,1211,1220],[84,865,861],{"id":866},"network-policies",[87,868,869],{},"By default, every pod in a cluster can reach every other pod, in any namespace.\nThe flat network is a deliberate simplification — and a poor security posture the\nmoment you run more than one team's workloads.",[87,871,872,875],{},[107,873,874],{},"NetworkPolicy"," narrows it.",[99,877,879],{"id":878},"selecting-turns-on-default-deny","Selecting turns on default-deny",[87,881,882,883,886],{},"A NetworkPolicy does not add rules to a permissive baseline. The moment any policy\nselects a pod, that pod switches to default-deny ",[94,884,885],{},"for the directions the policy\nmentions",", and only the listed rules are permitted.",[112,888,890],{"className":114,"code":889,"language":116,"meta":11,"style":11},"apiVersion: networking.k8s.io\u002Fv1\nkind: NetworkPolicy\nmetadata:\n  name: payments-ingress\nspec:\n  podSelector:\n    matchLabels:\n      app: payments\n  policyTypes: [Ingress]\n  ingress:\n    - from:\n        - podSelector:\n            matchLabels:\n              app: checkout\n      ports:\n        - port: 8080\n",[107,891,892,900,909,915,924,930,937,944,953,966,973,982,991,998,1008,1015],{"__ignoreMap":11},[120,893,894,896,898],{"class":122,"line":123},[120,895,127],{"class":126},[120,897,131],{"class":130},[120,899,481],{"class":134},[120,901,902,904,906],{"class":122,"line":23},[120,903,140],{"class":126},[120,905,131],{"class":130},[120,907,908],{"class":134},"NetworkPolicy\n",[120,910,911,913],{"class":122,"line":12},[120,912,150],{"class":126},[120,914,153],{"class":130},[120,916,917,919,921],{"class":122,"line":156},[120,918,159],{"class":126},[120,920,131],{"class":130},[120,922,923],{"class":134},"payments-ingress\n",[120,925,926,928],{"class":122,"line":167},[120,927,170],{"class":126},[120,929,153],{"class":130},[120,931,932,935],{"class":122,"line":175},[120,933,934],{"class":126},"  podSelector",[120,936,153],{"class":130},[120,938,939,942],{"class":122,"line":183},[120,940,941],{"class":126},"    matchLabels",[120,943,153],{"class":130},[120,945,946,949,951],{"class":122,"line":193},[120,947,948],{"class":126},"      app",[120,950,131],{"class":130},[120,952,164],{"class":134},[120,954,955,958,961,963],{"class":122,"line":201},[120,956,957],{"class":126},"  policyTypes",[120,959,960],{"class":130},": [",[120,962,430],{"class":134},[120,964,965],{"class":130},"]\n",[120,967,968,971],{"class":122,"line":216},[120,969,970],{"class":126},"  ingress",[120,972,153],{"class":130},[120,974,975,977,980],{"class":122,"line":557},[120,976,204],{"class":130},[120,978,979],{"class":126},"from",[120,981,153],{"class":130},[120,983,984,986,989],{"class":122,"line":571},[120,985,808],{"class":130},[120,987,988],{"class":126},"podSelector",[120,990,153],{"class":130},[120,992,993,996],{"class":122,"line":582},[120,994,995],{"class":126},"            matchLabels",[120,997,153],{"class":130},[120,999,1000,1003,1005],{"class":122,"line":590},[120,1001,1002],{"class":126},"              app",[120,1004,131],{"class":130},[120,1006,1007],{"class":134},"checkout\n",[120,1009,1010,1013],{"class":122,"line":598},[120,1011,1012],{"class":126},"      ports",[120,1014,153],{"class":130},[120,1016,1017,1019,1021,1023],{"class":122,"line":609},[120,1018,808],{"class":130},[120,1020,207],{"class":126},[120,1022,131],{"class":130},[120,1024,224],{"class":212},[87,1026,1027,1028,1031],{},"Payments now accepts traffic from checkout on 8080 and nothing else. Egress is\nuntouched, because ",[107,1029,1030],{},"policyTypes"," does not list it.",[332,1033,1034],{},[87,1035,1036,1037,1040,1041,1043,1044,1047,1048,1051,1052,1055],{},"Listing ",[107,1038,1039],{},"Egress"," in ",[107,1042,1030],{}," with an empty ",[107,1045,1046],{},"egress"," block denies ",[749,1049,1050],{},"all","\noutbound traffic — including DNS to ",[107,1053,1054],{},"kube-dns",". Name resolution stops, so every\noutbound connection fails with a resolution error rather than a connection error,\nand the policy looks unrelated to the symptom. Always allow UDP and TCP 53 to the\nDNS namespace when you start restricting egress.",[99,1057,1059],{"id":1058},"namespace-selectors-need-labels","Namespace selectors need labels",[87,1061,1062,1065,1066,1069],{},[107,1063,1064],{},"namespaceSelector"," matches on namespace labels, not names. Namespaces have no\nuseful labels by default beyond ",[107,1067,1068],{},"kubernetes.io\u002Fmetadata.name",", which the control\nplane sets automatically:",[112,1071,1073],{"className":114,"code":1072,"language":116,"meta":11,"style":11},"ingress:\n  - from:\n      - namespaceSelector:\n          matchLabels:\n            kubernetes.io\u002Fmetadata.name: monitoring\n",[107,1074,1075,1081,1090,1099,1106],{"__ignoreMap":11},[120,1076,1077,1079],{"class":122,"line":123},[120,1078,47],{"class":126},[120,1080,153],{"class":130},[120,1082,1083,1086,1088],{"class":122,"line":23},[120,1084,1085],{"class":130},"  - ",[120,1087,979],{"class":126},[120,1089,153],{"class":130},[120,1091,1092,1095,1097],{"class":122,"line":12},[120,1093,1094],{"class":130},"      - ",[120,1096,1064],{"class":126},[120,1098,153],{"class":130},[120,1100,1101,1104],{"class":122,"line":156},[120,1102,1103],{"class":126},"          matchLabels",[120,1105,153],{"class":130},[120,1107,1108,1111,1113],{"class":122,"line":167},[120,1109,1110],{"class":126},"            kubernetes.io\u002Fmetadata.name",[120,1112,131],{"class":130},[120,1114,1115],{"class":134},"monitoring\n",[87,1117,1118,1119,1121,1122,1124,1125,1127],{},"Combining ",[107,1120,1064],{}," and ",[107,1123,988],{}," in a single ",[107,1126,979],{}," entry is an AND.\nListing them as two entries is an OR. One character of YAML indentation separates\n\"Prometheus pods in the monitoring namespace\" from \"anything in monitoring, plus\nPrometheus pods anywhere\".",[99,1129,1131],{"id":1130},"the-cni-has-to-implement-it","The CNI has to implement it",[87,1133,1134],{},"Like Ingress, the object is only a declaration. Calico, Cilium and Antrea enforce\npolicies. Flannel, on its own, does not.",[1136,1137,1138],"danger",{},[87,1139,1140,1141,1144],{},"Applying NetworkPolicy on a CNI that ignores it produces no error and no warning.\n",[107,1142,1143],{},"kubectl get networkpolicy"," lists the object, the API accepted it, and traffic\nflows exactly as before. A policy you believe is enforced but is not is worse than\nno policy — verify by actually attempting a connection that should be denied.",[99,1146,1148],{"id":1147},"a-sensible-starting-point","A sensible starting point",[87,1150,1151],{},"Deny everything inbound in a namespace, then open specific paths:",[112,1153,1155],{"className":114,"code":1154,"language":116,"meta":11,"style":11},"apiVersion: networking.k8s.io\u002Fv1\nkind: NetworkPolicy\nmetadata:\n  name: default-deny-ingress\nspec:\n  podSelector: {}\n  policyTypes: [Ingress]\n",[107,1156,1157,1165,1173,1179,1188,1194,1201],{"__ignoreMap":11},[120,1158,1159,1161,1163],{"class":122,"line":123},[120,1160,127],{"class":126},[120,1162,131],{"class":130},[120,1164,481],{"class":134},[120,1166,1167,1169,1171],{"class":122,"line":23},[120,1168,140],{"class":126},[120,1170,131],{"class":130},[120,1172,908],{"class":134},[120,1174,1175,1177],{"class":122,"line":12},[120,1176,150],{"class":126},[120,1178,153],{"class":130},[120,1180,1181,1183,1185],{"class":122,"line":156},[120,1182,159],{"class":126},[120,1184,131],{"class":130},[120,1186,1187],{"class":134},"default-deny-ingress\n",[120,1189,1190,1192],{"class":122,"line":167},[120,1191,170],{"class":126},[120,1193,153],{"class":130},[120,1195,1196,1198],{"class":122,"line":175},[120,1197,934],{"class":126},[120,1199,1200],{"class":130},": {}\n",[120,1202,1203,1205,1207,1209],{"class":122,"line":183},[120,1204,957],{"class":126},[120,1206,960],{"class":130},[120,1208,430],{"class":134},[120,1210,965],{"class":130},[87,1212,1213,1214,1216,1217,1219],{},"An empty ",[107,1215,988],{}," selects every pod in the namespace. With no ",[107,1218,47],{}," rules,\nnothing is allowed in. Layer permissive policies on top per service — policies are\nadditive, so any rule that allows traffic wins over the baseline denial.",[412,1221,414],{},{"title":11,"searchDepth":12,"depth":12,"links":1223},[1224,1225,1226,1227],{"id":878,"depth":23,"text":879},{"id":1058,"depth":23,"text":1059},{"id":1130,"depth":23,"text":1131},{"id":1147,"depth":23,"text":1148},"Narrowing a default-allow flat network, and the traps in doing it.",{},"\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002Fnetwork-policies",{"title":861,"description":1228},"learn\u002Fen\u002Fcourses\u002Fnetworking\u002F03.network-policies","6JfTFK0E4FUQ3up_YPMrK33esdPME_tZFDmROIyTNDw",{"course":24},{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1236},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Crect width=\"6\" height=\"6\" x=\"16\" y=\"16\" rx=\"1\"\u002F>\u003Crect width=\"6\" height=\"6\" x=\"2\" y=\"16\" rx=\"1\"\u002F>\u003Crect width=\"6\" height=\"6\" x=\"9\" y=\"2\" rx=\"1\"\u002F>\u003Cpath d=\"M5 16v-3a1 1 0 0 1 1-1h12a1 1 0 0 1 1 1v3m-7-4V8\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1238},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M21.801 10A10 10 0 1 1 17 3.335\"\u002F>\u003Cpath d=\"m9 11l3 3L22 4\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1240},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M6 18H4a2 2 0 0 1-2-2v-5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2v5a2 2 0 0 1-2 2h-2M6 9V3a1 1 0 0 1 1-1h10a1 1 0 0 1 1 1v6\"\u002F>\u003Crect width=\"12\" height=\"8\" x=\"6\" y=\"14\" rx=\"1\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1242},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M21.42 10.922a1 1 0 0 0-.019-1.838L12.83 5.18a2 2 0 0 0-1.66 0L2.6 9.08a1 1 0 0 0 0 1.832l8.57 3.908a2 2 0 0 0 1.66 0zM22 10v6\"\u002F>\u003Cpath d=\"M6 12.5V16a6 3 0 0 0 12 0v-3.5\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1244},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M10 2v8l3-3l3 3V2\"\u002F>\u003Cpath d=\"M4 19.5v-15A2.5 2.5 0 0 1 6.5 2H19a1 1 0 0 1 1 1v18a1 1 0 0 1-1 1H6.5a1 1 0 0 1 0-5H20\"\u002F>\u003C\u002Fg>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1246},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M13.4 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2v-7.4M2 6h4m-4 4h4m-4 4h4m-4 4h4\"\u002F>\u003Cpath d=\"M21.378 5.626a1 1 0 1 0-3.004-3.004l-5.01 5.012a2 2 0 0 0-.506.854l-.837 2.87a.5.5 0 0 0 .62.62l2.87-.837a2 2 0 0 0 .854-.506z\"\u002F>\u003C\u002Fg>",{"id":1248,"title":5,"course":24,"description":1249,"extension":1250,"lang":20,"meta":1251,"passingScore":1252,"questions":1253,"shuffle":18,"stem":1383,"__hash__":1384},"quizzes\u002Flearn\u002Fen\u002Fcourses\u002Fnetworking\u002Fquiz.yml","Nine questions on Services, Ingress and network policy.","yml",{},70,[1254,1271,1286,1300,1315,1329,1341,1355,1369],{"id":1255,"question":1256,"type":1257,"difficulty":1258,"options":1259,"correct":1269,"explanation":1270},"svc-nodeport","Which Service type allocates the same port on every node in the cluster?","single","easy",[1260,1262,1264,1266],{"id":1261,"text":271},"a",{"id":1263,"text":284},"b",{"id":1265,"text":301},"c",{"id":1267,"text":1268},"d","Headless",[1263],"NodePort opens an identical port on all nodes and forwards to the Service. LoadBalancer builds on top of it, so it also has a node port — but the allocation belongs to NodePort.\n",{"id":1272,"question":1273,"type":1257,"difficulty":1274,"options":1275,"correct":1284,"explanation":1285},"svc-ping","Why does pinging a ClusterIP fail even when the Service works?","medium",[1276,1278,1280,1282],{"id":1261,"text":1277},"ICMP is blocked by default in every CNI",{"id":1263,"text":1279,"so no host answers ICMP":39},"The IP exists only as DNAT rules",{"id":1265,"text":1281},"Ping requires the Service to have a LoadBalancer",{"id":1267,"text":1283},"kube-proxy drops ICMP to conserve conntrack entries",[1263],"A ClusterIP is not assigned to any interface. kube-proxy installs rules that rewrite the destination for the ports the Service declares. Nothing owns the address, so there is nothing to reply to ICMP.\n",{"id":1287,"question":1288,"type":1257,"difficulty":1274,"options":1289,"correct":1298,"explanation":1299},"svc-headless","What does setting clusterIP: None achieve?",[1290,1292,1294,1296],{"id":1261,"text":1291},"DNS returns the individual pod IPs rather than one virtual IP",{"id":1263,"text":1293},"The Service is disabled until a ClusterIP is assigned",{"id":1265,"text":1295},"Traffic is load balanced per request instead of per connection",{"id":1267,"text":1297},"The Service becomes reachable from outside the cluster",[1261],"A headless Service skips the virtual IP entirely and returns one A record per ready endpoint. StatefulSets rely on this so each replica is addressable.\n",{"id":1301,"question":1302,"type":1257,"difficulty":1303,"options":1304,"correct":1313,"explanation":1314},"svc-grpc","Why does gRPC traffic through a ClusterIP often land unevenly on one pod?","hard",[1305,1307,1309,1311],{"id":1261,"text":1306},"gRPC ignores DNS TTLs",{"id":1263,"text":1308,"and HTTP\u002F2 reuses one connection":39},"kube-proxy balances per connection",{"id":1265,"text":1310},"EndpointSlices only expose the first ready pod",{"id":1267,"text":1312},"Readiness probes deregister the other pods",[1263],"An endpoint is chosen when the connection opens. HTTP\u002F2 carries every request over one long-lived connection, so all of them go to the pod picked first. Client-side balancing or an HTTP\u002F2-aware proxy is the fix.\n",{"id":1316,"question":1317,"type":1257,"difficulty":1258,"options":1318,"correct":1327,"explanation":1328},"ing-controller","What happens when you create an Ingress with no ingress controller installed?",[1319,1321,1323,1325],{"id":1261,"text":1320},"The API server rejects the object",{"id":1263,"text":1322},"Nothing — the object exists but no routing is configured",{"id":1265,"text":1324},"Kubernetes provisions a default controller automatically",{"id":1267,"text":1326},"Traffic falls back to the Service NodePort",[1263],"An Ingress is a declaration that a controller must act on. With no controller, it sits with an empty address and produces no events to explain why.\n",{"id":1330,"question":1331,"type":1332,"difficulty":1274,"options":1333,"correct":1339,"explanation":1340},"ing-prefix","With pathType Prefix, which paths does a rule for \u002Fapi match?","multiple",[1334,1335,1336,1337],{"id":1261,"text":755},{"id":1263,"text":762},{"id":1265,"text":766},{"id":1267,"text":1338},"\u002Fv1\u002Fapi",[1261,1263],"Prefix compares path elements split on slashes, not raw characters. \u002Fapiary is a different first element, and \u002Fv1\u002Fapi does not start with the prefix.\n",{"id":1342,"question":1343,"type":1257,"difficulty":1303,"options":1344,"correct":1353,"explanation":1354},"ing-tls","A TLS Secret named in an Ingress does not exist. What happens?",[1345,1347,1349,1351],{"id":1261,"text":1346},"The Ingress is rejected at admission",{"id":1263,"text":1348},"The controller serves its default self-signed certificate",{"id":1265,"text":1350},"TLS is disabled and the host serves plain HTTP",{"id":1267,"text":1352},"The controller generates a certificate from the cluster CA",[1263],"Nothing validates that the Secret exists. The controller falls back to its default certificate, which presents as a certificate error rather than a missing-object error.\n",{"id":1356,"question":1357,"type":1257,"difficulty":1303,"options":1358,"correct":1367,"explanation":1368},"np-egress","Which rule must you almost always add when you first restrict egress?",[1359,1361,1363,1365],{"id":1261,"text":1360},"Allow TCP 443 to the API server",{"id":1263,"text":1362},"Allow UDP and TCP 53 to the DNS namespace",{"id":1265,"text":1364},"Allow all traffic within the same namespace",{"id":1267,"text":1366},"Allow ICMP for health checking",[1263],"Listing Egress in policyTypes with no rules denies DNS as well. Resolution fails, so every outbound call fails in a way that looks unrelated to the policy.\n",{"id":1370,"question":1371,"type":1257,"difficulty":1274,"options":1372,"correct":1381,"explanation":1382},"np-cni","You apply a NetworkPolicy on a cluster running plain Flannel. What is the result?",[1373,1375,1377,1379],{"id":1261,"text":1374},"The policy is enforced by kube-proxy instead",{"id":1263,"text":1376},"The object is stored and silently ignored — traffic is unchanged",{"id":1265,"text":1378},"The API server rejects it with an unsupported error",{"id":1267,"text":1380},"All traffic to the selected pods is denied as a safe default",[1263],"Enforcement belongs to the CNI. Flannel on its own does not implement policy, so the object exists, appears applied, and does nothing — the most dangerous of the possible outcomes.\n","learn\u002Fen\u002Fcourses\u002Fnetworking\u002Fquiz","Dxb4K00x4PMEGq3LreaD5rXpA_sB5Qrg9JbxiE4df7g",{"id":4,"title":5,"access":6,"body":1386,"description":14,"draft":15,"estimatedMinutes":16,"extension":17,"featured":18,"icon":19,"lang":20,"level":21,"meta":1390,"navigation":18,"order":23,"path":24,"prerequisites":1391,"resources":1392,"seo":1395,"sku":39,"stem":40,"subjects":1396,"summary":43,"tags":1397,"updated":49,"__hash__":50},{"type":8,"value":1387,"toc":1388},[],{"title":11,"searchDepth":12,"depth":12,"links":1389},[],{},[26],[1393,1394],{"label":29,"file":30,"access":6,"size":31},{"label":33,"file":34,"access":35,"sku":36,"size":37},{"title":5,"description":14},[42],[45,46,47,48],{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1399},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m9 18l6-6l-6-6\"\u002F>",{"left":52,"top":52,"width":53,"height":53,"rotate":52,"vFlip":15,"hFlip":15,"body":1401},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M19 5L5 19\"\u002F>\u003Ccircle cx=\"6.5\" cy=\"6.5\" r=\"2.5\"\u002F>\u003Ccircle cx=\"17.5\" cy=\"17.5\" r=\"2.5\"\u002F>\u003C\u002Fg>",1787597905077]