The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Practitioner · Module 2: Kubernetes networking and storage · Lab

Allow Required Traffic and Block the Rest with an Enforcing CNI

55 min hands-on · Advanced

A local KinD cluster with an enforcing CNI installed (documented Calico path); a three-tier demo (frontend, backend, database). The default local CNI is not sufficient for this lab and the record must say which CNI enforced the result.

Local guide: run the steps below on your own machine in order, then check the validation list.

Objectives

  • Show the flat baseline where every pod reaches every pod
  • Apply default-deny plus allow rules for required flows only
  • Prove isolation with a quoted allow/block connection matrix
  1. Step 1

    Record the open field

    Before any policy, test connections between all three tiers in both directions and record the all-open baseline. Confirm which CNI serves the cluster and that it enforces policy.

  2. Step 2

    Deny then allow deliberately

    Apply default-deny for the namespace and show everything breaking, including DNS if its egress is missing. Then add allow rules for exactly the required flows (frontend to backend, backend to database, DNS egress) and show service restored.

  3. Step 3

    Quote the matrix

    Run the full connection matrix and quote it: required flows connect, all other pairs time out, DNS resolves. Name the enforcing CNI in the record; a matrix without a named enforcer is rejected.

How to confirm it worked

  • All-open baseline recorded with the CNI named
  • Default-deny breakage observed, including the DNS egress lesson
  • Allow rules cover exactly the required flows plus DNS
  • Quoted matrix shows allowed connects and denied timeouts