learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Network Lockdown (CKS)

Default-deny everywhere, a guarded metadata endpoint, and TLS at the edge.

An interactive Kubernetes lesson: 21 steps, about 32 minutes, on a live simulation in your browser.

Your shop runs in the namespace shop. Customers arrive through the Ingress and land on web. web calls api. api calls orders, the service that holds every customer's name, address and order history.

Three streams, all green. There is a fourth: the internet reaching orders directly through a port on the nodes. Nobody remembers opening it. Leave it for now.

What you will learn

  1. A flat network

    • The shop, exactly as it was built: Out of the box, every pod can reach every other pod in every namespace, and any address outside the cluster.
    • An attacker gets a shell
    • The address that hands out credentials: 169.254.169.254 hands the node's cloud identity to anything that can send it a packet. A pod that reaches it can act as the node.
  2. Deny by default

    • Deny everything coming in: A pod selected by no policy accepts everything. A pod selected by any policy accepts only what some policy lists.
    • One direction is not two: Ingress and Egress are two separate locks. policyTypes says which ones a policy closes. Replies to an allowed connection always pass.
    • Default-deny, both directions
  3. Open only what is needed

    • The first allow rule: Every connection needs two yeses: an egress rule on the sender and an ingress rule on the receiver.
    • DNS comes first: In a default-deny namespace, allow egress to kube-dns on port 53 before anything else. Without it nothing can be called by name.
    • One policy per app: Policies are allow-lists that add up. A pod's permissions are the union of every policy that selects it; nothing can subtract.
    • Break it: one dash too many: In from and to, each dash is an OR. Two selectors under one dash are an AND.
    • Drill: prove a path is closed
  4. The metadata endpoint

    • "Anywhere" is a big place
    • Carve the metadata address out: 0.0.0.0/0 includes the node's metadata service. Any rule that says "anywhere" needs except: 169.254.169.254/32.
  5. TLS at the edge

    • HTTPS with no certificate
    • A TLS Secret, referenced by the Ingress: The Ingress terminates TLS with a kubernetes.io/tls Secret in its own namespace. Behind the controller, traffic is plain HTTP.
    • Break it: the Secret moves house
    • Drill: create the TLS Secret
  6. Doors in the outer wall

    • Find every door, close the spare ones: Every NodePort and LoadBalancer is a door in the outer wall. Keep one, the Ingress, and make everything else ClusterIP.
    • The nodes have ports too: NetworkPolicy guards pods. A host firewall guards nodes. The kubelet, etcd and API server ports need a source range, never the whole internet.
  7. Recap & playground

    • Cheat sheet
    • Playground