Restore exact application and DNS initiation paths

A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.

Try this labAll CKA practice

Certification
CKA
Format
Artifact workspace
Difficulty
medium
Estimated time
40 min
Automated checks
10

The brief

Repair policies.yaml using only networking.k8s.io/v1 NetworkPolicies in storefront, checkout, ops, sandbox or rivals. Inventory is immutable. All ten Pods must be isolated for both ingress and egress in both stages. Allow exactly these new connections: storefront/ui -> checkout/api-a and api-b at their TCP api named port; both APIs -> checkout/db TCP/5432; UI and both APIs -> ops/dns UDP/53 and TCP/53. Deny every other initiation between distinct supplied Pods, including other ports/protocols for allowed pairs. Replies need no separate initiation grant. Pod labels: ui has role=frontend, client=store; storefront/debug-ui has role=debug; checkout/api-a,b have role=api; checkout/db role=db; checkout/debug-core role=debug; ops/dns k8s-app=kube-dns; ops/agent role=monitor; sandbox/attacker and rivals/outsider both role=frontend, client=store. APIs have release=old and named api TCP/8080 initially, then release=new and api TCP/8181. db names postgres TCP/5432; dns names dns at UDP/53 and TCP/53. Namespace labels include immutable kubernetes.io/metadata.name; storefront/rivals also share tier=web, checkout tier=core, ops tier=system, sandbox tier=test. Policies add together. Both source egress and destination ingress must permit an isolated connection. In one peer, namespaceSelector AND podSelector apply; separate peers OR. A podSelector without namespaceSelector means the policy's own namespace. Empty selectors match all; empty rule/peer and port lists have their API meanings. Use labels/expressions, named or numeric ports/ranges; port names resolve on the destination. The supplied plugin supports ranges. This steady-state policy model checks all ports 1..65535 and TCP/UDP/SCTP, excluding Service NAT, host/node/self traffic, external IP peers, existing connections and HTTP/TLS. Inspect missing-flow and excess-grant witnesses, then repair without Reset.

What the checks verify

Your work is graded on 10 independent properties, not on matching one reference answer.

  • Only supported typed NetworkPolicy API fields, selectors and port forms are used.
  • Policies belong only to the supplied immutable inventory namespaces.
  • Every supplied Pod is ingress-isolated in both observed stages.
  • Every supplied Pod is egress-isolated in both observed stages.
  • The trusted UI can initiate to both API Pods at each stage's TCP api port.
  • Both API Pods can initiate to the intended database on TCP/5432 in both stages.
  • UI and both APIs can initiate UDP/53 queries to the exact ops DNS Pod in both stages.
  • UI and both APIs can initiate TCP/53 queries to the exact ops DNS Pod in both stages.
  • No supplied distinct-Pod pair outside the required connection set receives initiation permission.
  • Required Pod pairs receive no initiation permission on any other port or transport.

Where this sits in the CKA blueprint

Domain
Services and Networking
Objective
Network Policies
Skill
Additive Ingress and Egress Isolation

Part of CKA preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.