Restore exact application and DNS initiation paths
A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- medium
- Estimated time
- 40 min
- Automated checks
- 10
The brief
Repair policies.yaml using only networking.k8s.io/v1 NetworkPolicies in storefront, checkout, ops, sandbox or rivals. Inventory is immutable. All ten Pods must be isolated for both ingress and egress in both stages. Allow exactly these new connections: storefront/ui -> checkout/api-a and api-b at their TCP api named port; both APIs -> checkout/db TCP/5432; UI and both APIs -> ops/dns UDP/53 and TCP/53. Deny every other initiation between distinct supplied Pods, including other ports/protocols for allowed pairs. Replies need no separate initiation grant. Pod labels: ui has role=frontend, client=store; storefront/debug-ui has role=debug; checkout/api-a,b have role=api; checkout/db role=db; checkout/debug-core role=debug; ops/dns k8s-app=kube-dns; ops/agent role=monitor; sandbox/attacker and rivals/outsider both role=frontend, client=store. APIs have release=old and named api TCP/8080 initially, then release=new and api TCP/8181. db names postgres TCP/5432; dns names dns at UDP/53 and TCP/53. Namespace labels include immutable kubernetes.io/metadata.name; storefront/rivals also share tier=web, checkout tier=core, ops tier=system, sandbox tier=test. Policies add together. Both source egress and destination ingress must permit an isolated connection. In one peer, namespaceSelector AND podSelector apply; separate peers OR. A podSelector without namespaceSelector means the policy's own namespace. Empty selectors match all; empty rule/peer and port lists have their API meanings. Use labels/expressions, named or numeric ports/ranges; port names resolve on the destination. The supplied plugin supports ranges. This steady-state policy model checks all ports 1..65535 and TCP/UDP/SCTP, excluding Service NAT, host/node/self traffic, external IP peers, existing connections and HTTP/TLS. Inspect missing-flow and excess-grant witnesses, then repair without Reset.
What the checks verify
Your work is graded on 10 independent properties, not on matching one reference answer.
- Only supported typed NetworkPolicy API fields, selectors and port forms are used.
- Policies belong only to the supplied immutable inventory namespaces.
- Every supplied Pod is ingress-isolated in both observed stages.
- Every supplied Pod is egress-isolated in both observed stages.
- The trusted UI can initiate to both API Pods at each stage's TCP api port.
- Both API Pods can initiate to the intended database on TCP/5432 in both stages.
- UI and both APIs can initiate UDP/53 queries to the exact ops DNS Pod in both stages.
- UI and both APIs can initiate TCP/53 queries to the exact ops DNS Pod in both stages.
- No supplied distinct-Pod pair outside the required connection set receives initiation permission.
- Required Pod pairs receive no initiation permission on any other port or transport.
Where this sits in the CKA blueprint
- Domain
- Services and Networking
- Objective
- Network Policies
- Skill
- Additive Ingress and Egress Isolation
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.