Traffic Security · wrap-up
Cheat sheet & self-check
9 questions across 3 lessons. Each answer links back to the lesson it came from.
Pick an answer to see if you got it, and why.
Q1. What does TLS termination at the ingress controller mean?
Show answer
B. Termination lets the controller route by host and path. With re-encryption it opens a new TLS connection to the backend as well.
From lesson 07 · Ingress controllers & TLSQ2. Why does SNI matter for ingress TLS?
Show answer
B. Without SNI, a shared ingress IP couldn't pick the right certificate. Test with -servername / --resolve to see what a given host gets.
From lesson 07 · Ingress controllers & TLSQ3. An Ingress has no ingressClassName and nothing happens. Why?
Show answer
B. Controllers only act on Ingresses of their class. Without a class (and without a default IngressClass), nobody picks it up.
From lesson 07 · Ingress controllers & TLSQ4. In Gateway API, who typically owns the Gateway object?
Show answer
B. Role separation is the point: infrastructure owns GatewayClasses, the platform owns Gateways, app teams own Routes.
From lesson 08 · Gateway APIQ5. An HTTPRoute in namespace shop stays unattached to a Gateway in namespace infra. What should you check first?
Show answer
B. Gateways explicitly allow route attachment from namespaces. The Route's status explains whether it was Accepted and why not.
From lesson 08 · Gateway APIQ6. What does a ReferenceGrant do?
Show answer
B. Cross-namespace references are denied by default. The namespace that owns the target must opt in with a ReferenceGrant.
From lesson 08 · Gateway APIQ7. You apply a default-deny egress policy and every app breaks, even calls to allowed Services. What did you forget?
Show answer
B. Name resolution is itself network traffic. Default-deny egress needs an explicit rule allowing DNS to kube-system.
From lesson 09 · Network policies & mTLSQ8. Do NetworkPolicies work with every CNI?
Show answer
B. The API server stores policies; the CNI (Calico, Cilium, others) implements them. With a non-enforcing CNI, policies have no effect.
From lesson 09 · Network policies & mTLSQ9. What does mTLS add that NetworkPolicy doesn't?
Show answer
B. NetworkPolicy filters by labels and IPs. mTLS encrypts traffic and proves which workload is on each end.
From lesson 09 · Network policies & mTLS