Chuyển đến nội dung chính

Bài 7: Ingress, Network Policies & CNI

Ingress resources và controllers. Network Policies isolate traffic. CNI plugins: Flannel, Calico, Cilium. Troubleshoot Pod networking.

Ingress Routing và NetworkPolicy — L7 routing và network segmentation

1. Ingress

Ingress cung cấp HTTP/HTTPS routing vào cluster. Cần Ingress Controller (nginx-ingress, Traefik, ALB) để xử lý Ingress resources.

Internet
   │
[Ingress Controller] (nginx Pod, port 80/443)
   │
   ├── /api/* ──────────────► Service: api-svc:8080
   ├── /web/* ──────────────► Service: web-svc:80
   └── shop.example.com ───► Service: shop-svc:3000
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: app-ingress
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  ingressClassName: nginx
  rules:
  - host: api.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: api-svc
            port:
              number: 8080
  tls:
  - hosts:
    - api.example.com
    secretName: tls-secret  # TLS cert stored in Secret

Exam tip: Ingress không hoạt động nếu không có Ingress Controller. CKA exam thường đã có controller cài sẵn. Kiểm tra kubectl get ingressclass để xem class name cần dùng trong spec.ingressClassName.

2. Network Policies — CKA Depth

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-frontend-to-backend
  namespace: app
spec:
  podSelector:
    matchLabels:
      app: backend      # Apply to backend pods
  policyTypes:
  - Ingress             # Control incoming traffic
  ingress:
  - from:
    - podSelector:
        matchLabels:
          app: frontend  # Only from frontend pods
    ports:
    - protocol: TCP
      port: 8080

---
# Deny all ingress (default deny)
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: deny-all
spec:
  podSelector: {}     # Select ALL pods
  policyTypes:
  - Ingress           # No ingress rules = block all ingress
SelectorÝ nghĩa
podSelector: {}Select tất cả Pods trong namespace
namespaceSelectorCho phép traffic từ specific namespace
ipBlockCho phép traffic từ CIDR range

3. CNI Plugins

CNINetwork Policy?Đặc điểm
FlannelKhôngSimple overlay, VXLAN/host-gw
CalicoCóBGP routing, high performance, enterprise
CiliumCó (eBPF)eBPF-based, L7 policies, observability
Weave NetCóSimple, mesh network

Exam tip: Calico và Cilium hỗ trợ NetworkPolicy. Flannel không. Nếu exam hỏi "configure network policies" → phải có Calico/Cilium. Trên kubeadm lab, Calico là lựa chọn phổ biến nhất.

4. Pod Network Troubleshooting

# Test pod-to-pod connectivity
kubectl exec -it pod1 -- ping 10.244.1.5
kubectl exec -it pod1 -- curl http://pod2:8080

# Check pod's IP
kubectl get pod pod1 -o jsonpath='{.status.podIP}'

# Check CNI config on node
ls /etc/cni/net.d/
cat /etc/cni/net.d/10-calico.conflist

# Check kube-proxy rules
kubectl get pod -n kube-system -l k8s-app=kube-proxy
iptables -t nat -L KUBE-SERVICES | head -20

5. Cheat Sheet

TaskCommand/Object
HTTP routing into clusterIngress (+ IngressClass)
Block all traffic to a PodNetworkPolicy with empty ingress: []
Allow traffic from namespaceNetworkPolicy with namespaceSelector
Check CNI pluginsls /etc/cni/net.d/
Check ingressclasskubectl get ingressclass

6. Practice Questions

Q1: You create an Ingress resource but it has no ADDRESS and traffic doesn't route. What is the most likely cause?

  • A) The Service type must be LoadBalancer
  • B) No Ingress Controller is installed in the cluster ✓
  • C) The Ingress must be in the kube-system namespace
  • D) The IngressClass must be set to "default"

Explanation: An Ingress resource is just configuration — it has no effect without an Ingress Controller (nginx, Traefik, etc.) to implement it. The controller watches Ingress objects and configures the actual proxy.

Q2: A NetworkPolicy selects Pods with label app=database and specifies policyTypes: [Ingress]. No ingress rules are defined. What is the effect?

  • A) All traffic is allowed (no rules = allow all)
  • B) All ingress traffic to database Pods is blocked ✓
  • C) Only egress traffic is affected
  • D) The policy is invalid and has no effect

Explanation: A NetworkPolicy with policyTypes: [Ingress] but empty ingress rules acts as a default deny for all ingress traffic to the selected Pods. This is a common way to implement default-deny policies.

Q3: Which CNI plugin should you choose if you need both pod networking AND NetworkPolicy enforcement?

  • A) Flannel
  • B) Calico ✓
  • C) CoreDNS
  • D) kube-proxy

Explanation: Flannel provides only overlay networking without NetworkPolicy support. Calico (and Cilium, Weave) implement the NetworkPolicy API. CoreDNS is DNS, and kube-proxy handles Service load balancing — they're not CNI plugins.