⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] Kubernetes Networking Staff SRE Scenario [L3]

Q: You have a microservices app where Service A should never talk directly to Service C, only through Service B. How do you enforce this in Kubernetes?

Use NetworkPolicy. By default, all pods can talk to all other pods. NetworkPolicy lets you restrict this.

#Kubernetes #Networking #L3 #Container Orchestration #K8s #Ingress
🎙️ Candidate Opening & Architectural Context
""Kubernetes is a declarative desired state system; understanding the reconciliation loop is how you diagnose this quickly. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

Use NetworkPolicy. By default, all pods can talk to all other pods. NetworkPolicy lets you restrict this. Example — block direct traffic to Service C except from Service B: This says: "Only accept incoming traffic to pods labeled app: service-c if it comes from pods labeled app: service-b." Note: NetworkPolicy requires a CNI plugin that supports it (Calico, Cilium, Weave). Flannel does not support NetworkPolicy by default.

apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-only-from-b
spec:
  podSelector:
    matchLabels:
      app: service-c
  ingress:
  - from:
    - podSelector:
        matchLabels:
          app: service-b
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Use NetworkPolicy. By default, all pods can talk to all other pods. NetworkPolicy lets you restrict this.."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: Use NetworkPolicy. By default, all pods can talk to all other pods. NetworkPolicy lets you rest
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Kubernetes scenarios?
Explore our complete collection of scenario-based Kubernetes interview runbooks.
Browse All Kubernetes Questions →

📚 Related Production Scenarios in Kubernetes