📚 Kubernetes Study - CKS Certification
Read full transcript 107 segments
-
all right looks like all right looks like the stream is going really an experience with going really an experience with streaming but it's showing that it's live it's showing that it's live so we'll see what so we'll see what so we'll see what happens so I'm going to start off with start with start wreck and turn on key okay casting the okay casting the keys clean up the terminal a bit oh y hello there it's already a bit oh y hello there it's already a viewer has tuned in that's interesting so I set up so I set up my directory here and my lab repo uh lab my directory here and my lab repo uh lab my directory here and my lab repo uh lab kubernetes cks so you can find that on kubernetes cks so you can find that on kubernetes cks so you can find that on my GitHub my GitHub my GitHub to currently just to currently just to currently just contains a read me file but I'm actually going to write a file but I'm actually going to write a little file here which I'll call
-
little file here which I'll call little file here which I'll call stream MD um I plan to show this file for a little um I plan to show this file for a little bit before I start streaming every time bit before I start streaming every time bit before I start streaming every time because I'll be talking for a little bit because I'll be talking for a little bit because I'll be talking for a little bit now but I'm basically planning on now but I'm basically planning on now but I'm basically planning on just uh streaming what I do and not just uh streaming what I do and not just uh streaming what I do and not necessarily being very interactive or necessarily being very interactive or necessarily being very interactive or talking a lot talking a lot talking a lot just showing you my process of taking just showing you my process of taking just showing you my process of taking notes how I implement the zle cast notes how I implement the zle cast notes how I implement the zle cast method and if I feel like it I will I method and if I feel like it I will I method and if I feel like it I will I will will will talk uh and if I don't I won't so I talk uh and if I don't I won't so I talk uh and if I don't I won't so I should write a bit of a note that should write a bit of a note that should write a bit of a note that captures that that I can show for the captures that that I can show for the captures that that I can show for the first minute of the stream so people first minute of the stream so people first minute of the stream so people know what to know what to know what to expect um this stream is not necessary um this stream is not necessary very very very interactive interactive interactive um I need to focus on actually cannot cannot respond to the chat constantly
-
constantly um I will talk with when I feel like it um I will talk with when I feel like it um I will talk with when I feel like it it and when it it and when it it and when it will Aid the will Aid the will Aid the understanding of the um idea is to um idea is to intention is to show you my studying intention is to show you my studying intention is to show you my studying process process process and how I use the zel and how I use the zel and how I use the zel Casten method and Casten method and Casten method and my second my second my second brain brain brain system for studying and productivity let's see the stream is not productivity let's see the stream is not necessarily very interactive I need to necessarily very interactive I need to necessarily very interactive I need to focus on actually studying which means I focus on actually studying which means I focus on actually studying which means I cannot respond to the chat cannot respond to the chat cannot respond to the chat constantly intention is to show my constantly intention is to show my constantly intention is to show my studying process and how I use the studying process and how I use the studying process and how I use the cellcast method and my second brain cellcast method and my second brain cellcast method and my second brain system for studying and system for studying and system for studying and productivity I'll talk when I feel like productivity I'll talk when I feel like productivity I'll talk when I feel like it and when it will Aid the it and when it will Aid the it and when it will Aid the understanding of the understanding of the understanding of the material but material but material but actually studying and actually studying and actually studying and focusing is the main priority okay I think that's all I want
-
priority okay I think that's all I want to establish before I get to establish before I get to establish before I get going um haven't done any study streams going um haven't done any study streams going um haven't done any study streams before ever so this is totally new I before ever so this is totally new I before ever so this is totally new I have had the intention though and one of have had the intention though and one of have had the intention though and one of the reasons I haven't done it yet is the reasons I haven't done it yet is the reasons I haven't done it yet is because courses are usually private because courses are usually private because courses are usually private right on a cloud Guru or you to me and right on a cloud Guru or you to me and right on a cloud Guru or you to me and you can't just start streaming that you can't just start streaming that you can't just start streaming that because then you you're infringing on because then you you're infringing on because then you you're infringing on copyright but the creator of killer h u copyright but the creator of killer h u copyright but the creator of killer h u he actually has a course on uny on the he actually has a course on uny on the he actually has a course on uny on the cks and he released it on YouTube so cks and he released it on YouTube so cks and he released it on YouTube so this course I can actually just do live this course I can actually just do live this course I can actually just do live so I thought it would be interesting to to you go through the course write to to you go through the course write the notes the notes the notes and do the work and show you how I do it and do the work and show you how I do it and do the work and show you how I do it and yeah maybe it's interesting maybe and yeah maybe it's interesting maybe and yeah maybe it's interesting maybe it's not if anything think it will be it's not if anything think it will be it's not if anything think it will be fun to document the journey on my fun to document the journey on my fun to document the journey on my channel I've had the cks course for a channel I've had the cks course for a channel I've had the cks course for a long time as a goal like over six months long time as a goal like over six months long time as a goal like over six months I've had this as a goal and now the the I've had this as a goal and now the the I've had this as a goal and now the the moment is finally here I feel like this moment is finally here I feel like this moment is finally here I feel like this is the right time to start because I is the right time to start because I is the right time to start because I might have some extra time during the might have some extra time during the might have some extra time during the coming weeks and um I'm just going to go coming weeks and um I'm just going to go coming weeks and um I'm just going to go for it
-
it so I I did start the so I I did start the so I I did start the course uh here and there I watched the course uh here and there I watched the course uh here and there I watched the first hour which is just basically first hour which is just basically first hour which is just basically introduction to kubernetes wasn't that introduction to kubernetes wasn't that introduction to kubernetes wasn't that interesting but good to refresh things interesting but good to refresh things interesting but good to refresh things and now I came to a point where um we're and now I came to a point where um we're and now I came to a point where um we're going to containers under the hood going going to containers under the hood going going to containers under the hood going into kernel space and user space and into kernel space and user space and into kernel space and user space and that's when I figured okay this is that's when I figured okay this is that's when I figured okay this is actually where I'm going to start taking actually where I'm going to start taking actually where I'm going to start taking some notes and that's when I figured some notes and that's when I figured some notes and that's when I figured okay this is the time to start um start okay this is the time to start um start okay this is the time to start um start the stream if that's what I want to want the stream if that's what I want to want the stream if that's what I want to want to do so all of the housekeeping and setup out so all of the housekeeping and setup out of the way I'm going to start my Pomo of the way I'm going to start my Pomo of the way I'm going to start my Pomo [Music] [Music] [Music] timer for 50 minutes and I'm going to timer for 50 minutes and I'm going to timer for 50 minutes and I'm going to get going going containers under the hood with this containers under the hood with this containers under the hood with this section you will get to know containers section you will get to know containers section you will get to know containers much better and in much more detail much better and in much more detail much better and in much more detail because from a kubernetes security because from a kubernetes security because from a kubernetes security perspective it is important to perspective it is important to perspective it is important to understand what containers are how they understand what containers are how they understand what containers are how they work and how they interact with our work and how they interact with our work and how they interact with our operating systems and for this we will operating systems and for this we will operating systems and for this we will start with containers and images we then start with containers and images we then start with containers and images we then have a look into Nam spaces and cgroups have a look into Nam spaces and cgroups have a look into Nam spaces and cgroups the kind of building blocks for
-
the kind of building blocks for the kind of building blocks for containers and we also have a look into containers and we also have a look into containers and we also have a look into some Hands-On scenarios which should some Hands-On scenarios which should some Hands-On scenarios which should make these things more clear to make these things more clear to make these things more clear to us so container and image what is a us so container and image what is a us so container and image what is a container what is an image let's start container what is an image let's start container what is an image let's start with a Docker file to explain this okay with a Docker file to explain this okay with a Docker file to explain this okay so we now explain this on the example of so we now explain this on the example of so we now explain this on the example of Docker containers because they're the Docker containers because they're the Docker containers because they're the most prevalent out there file it we can most prevalent out there file it we can most prevalent out there file it we can run Docker build and Docker build will run Docker build and Docker build will run Docker build and Docker build will build our image then we have a image and build our image then we have a image and build our image then we have a image and the could be described as a multi-layer could be described as a multi-layer binary representation of state which we binary representation of state which we binary representation of state which we described in our Docker file from that described in our Docker file from that described in our Docker file from that image we can then create a container so image we can then create a container so image we can then create a container so using docka run we actually create a using docka run we actually create a using docka run we actually create a container and we could say that a
-
container and we could say that a container and we could say that a container is a running instance of an container is a running instance of an container is a running instance of an image and there can be multiple running image and there can be multiple running image and there can be multiple running instances of an image so there can be instances of an image so there can be instances of an image so there can be multiple containers of the same multiple containers of the same multiple containers of the same image also very common once we build our image also very common once we build our image also very common once we build our image we actually push it into a image we actually push it into a image we actually push it into a container repository and then whenever container repository and then whenever container repository and then whenever we would like to run it we can actually we would like to run it we can actually we would like to run it we can actually docka pull that image and then docka run docka pull that image and then docka run docka pull that image and then docka run this image so that's as the simple this image so that's as the simple this image so that's as the simple difference between Docker file container difference between Docker file container difference between Docker file container image and the actual container so what is a container down container so what is a container down here we see Docker or connection of one here we see Docker or connection of one here we see Docker or connection of one or include all to run play a process or include all to run play a process or include all to run play a process which runs on the Linux kernel with some which runs on the Linux kernel with some which runs on the Linux kernel with some restrictions because it cannot see restrictions because it cannot see restrictions because it cannot see everything it is kind of at the broad everything it is kind of at the broad everything it is kind of at the broad architecture and to understand this architecture and to understand this architecture and to understand this let's have a look at the broad let's have a look at the broad let's have a look at the broad architecture architecture architecture on the bottom we have the hardware and on the bottom we have the hardware and on the bottom we have the hardware and on top of the hardware sits the Linux on top of the hardware sits the Linux on top of the hardware sits the Linux kernel and the Linux kernel actually kernel and the Linux kernel actually kernel and the Linux kernel actually provides a so-called sus call interface provides a so-called sus call interface provides a so-called sus call interface these sus calls or system calls like get these sus calls or system calls like get these sus calls or system calls like get P or reboot will then be provided to P or reboot will then be provided to P or reboot will then be provided to libraries like gipc or applications fire for libraries ID or reboot will
-
fire for libraries ID or reboot will then be provided to liaries like gipc or applications like Firefox or Cur gipc or applications like Firefox or Cur and in this scenario this doesn't play a and in this scenario this doesn't play a and in this scenario this doesn't play a big difference if these applications run big difference if these applications run big difference if these applications run directly on the Linux kernel or directly on the Linux kernel or directly on the Linux kernel or containerized in a Docker container containerized in a Docker container containerized in a Docker container which we will see soon so in the end we which we will see soon so in the end we which we will see soon so in the end we have down here the kernel space which have down here the kernel space which have down here the kernel space which includes the Linux kernel and the csol includes the Linux kernel and the csol includes the Linux kernel and the csol interface and then up here we have the interface and then up here we have the interface and then up here we have the user space where our libraries and user space where our libraries and user space where our libraries and applications applications applications run and the csol interface is then the run and the csol interface is then the run and the csol interface is then the possibility to communicate with the possibility to communicate with the possibility to communicate with the Linux kernel right and our the possibility to communicate with our the possibility to communicate with the Linux kernel right and and our applications can call the sus and our applications can call the sus call interface directly or our call interface directly or our call interface directly or our applications can go through libraries
-
applications can go through libraries applications can go through libraries which is open the case and then these which is open the case and then these which is open the case and then these libraries communicate with our csal libraries communicate with our csal libraries communicate with our csal interface of the Linux kernel so the interface of the Linux kernel so the interface of the Linux kernel so the csal interface can kind of be seen as an csal interface can kind of be seen as an csal interface can kind of be seen as an API from the Linux kernel to allow for API from the Linux kernel to allow for API from the Linux kernel to allow for communication with it and then when we communication with it and then when we communication with it and then when we do some s calls then these will be do some s calls then these will be do some s calls then these will be reached down to the Linux kernel and the reached down to the Linux kernel and the reached down to the Linux kernel and the Linux kernel communicates with the Linux kernel communicates with the Linux kernel communicates with the hardware so we have to be we have to hardware so we have to be we have to hardware so we have to be we have to understand that our application like Firefox even if it's containerized like Firefox even if it's containerized like here can perform direct sus calls like here can perform direct sus calls like here can perform direct sus calls to the SS call to the SS call to the SS call interface let's have a look at this in interface let's have a look at this in interface let's have a look at this in another view we have the hardware on the another view we have the hardware on the another view we have the hardware on the bottom again here in yellow we have the bottom again here in yellow we have the bottom again here in yellow we have the Linux kernel and let's say we have an Linux kernel and let's say we have an Linux kernel and let's say we have an app1 process could be our Firefox app1 process could be our Firefox app1 process could be our Firefox process it's the app1 process and it is process it's the app1 process and it is process it's the app1 process and it is containerized it runs as a Docker containerized it runs as a Docker containerized it runs as a Docker container but this means that that container but this means that that container but this means that that process can still perform system calls process can still perform system calls process can still perform system calls against the host Linux kernel and the against the host Linux kernel and the against the host Linux kernel and the very same thing could do another process
-
very same thing could do another process very same thing could do another process let's call it app2 process which is let's call it app2 process which is let's call it app2 process which is running in a completely different Docker running in a completely different Docker running in a completely different Docker container and that app two process could container and that app two process could container and that app two process could also perform sus calls to the very same also perform sus calls to the very same also perform sus calls to the very same Linux Cur so this is something important Linux Cur so this is something important Linux Cur so this is something important to understand that if we schedule many to understand that if we schedule many to understand that if we schedule many containers on one operating system like containers on one operating system like containers on one operating system like we do in kubernetes we have a worker we do in kubernetes we have a worker we do in kubernetes we have a worker node and depending on how many free node and depending on how many free node and depending on how many free resources there are we can schedule 10 resources there are we can schedule 10 resources there are we can schedule 10 20 100 pots with various containers all 20 100 pots with various containers all 20 100 pots with various containers all on that note which means they all run on on that note which means they all run on on that note which means they all run on the same Linux kernel and they can all the same Linux kernel and they can all the same Linux kernel and they can all perform system calls to the same Linux and down here again we have have the
-
and down here again we have have the kernel space and here we have the user kernel space and here we have the user kernel space and here we have the user space for our so this means yes we can have one so this means yes we can have one container which is wrapped in a kernel container which is wrapped in a kernel container which is wrapped in a kernel group and we'll have a look at these group and we'll have a look at these group and we'll have a look at these kernel groups we now simply call them kernel groups we now simply call them kernel groups we now simply call them kernel groups we'll have a look at these kernel groups we'll have a look at these kernel groups we'll have a look at these soon so we have our app1 process we have soon so we have our app1 process we have soon so we have our app1 process we have our app2 process we have our app three
-
our app2 process we have our app three our app2 process we have our app three process and the thing from the security process and the thing from the security process and the thing from the security perspective is that if these all run on perspective is that if these all run on perspective is that if these all run on the same Linux kernel and if these all the same Linux kernel and if these all the same Linux kernel and if these all can perform CIS calls to the Linux can perform CIS calls to the Linux can perform CIS calls to the Linux kernel then these all could also exploit kernel then these all could also exploit kernel then these all could also exploit some Linux kernel bugs and there have some Linux kernel bugs and there have some Linux kernel bugs and there have been some in the future and there been some in the future and there been some in the future and there probably are some right now which means probably are some right now which means probably are some right now which means that it could be that there's not a too that it could be that there's not a too that it could be that there's not a too strong isolation between for example the strong isolation between for example the strong isolation between for example the app1 process and the app2 process if app1 process and the app2 process if app1 process and the app2 process if there is an exploit or some exploit there is an exploit or some exploit there is an exploit or some exploit aable security issue in the Cur but we aable security issue in the Cur but we aable security issue in the Cur but we will explore this as well further in the will explore this as well further in the will explore this as well further in the cks training course this is right now cks training course this is right now cks training course this is right now only as an overview of how containers only as an overview of how containers only as an overview of how containers work and how they run and how they work and how they run and how they work and how they run and how they interact with the operating interact with the operating interact with the operating system so what's the difference then system so what's the difference then system so what's the difference then between a container and a virtual between a container and a virtual between a container and a virtual machine so if we have a virtual machine machine so if we have a virtual machine machine so if we have a virtual machine then it has an operating system and the then it has an operating system and the then it has an operating system and the kernel and on top of this we actually kernel and on top of this we actually kernel and on top of this we actually simulate another operating system with simulate another operating system with simulate another operating system with another kernel which means our another kernel which means our another kernel which means our application process app process actually application process app process actually application process app process actually runs on a different kernel and not on runs on a different kernel and not on runs on a different kernel and not on the host operating system kernel down the host operating system kernel down the host operating system kernel down here we have a look at containers on the here we have a look at containers on the here we have a look at containers on the left then it's a bit different we have left then it's a bit different we have left then it's a bit different we have our operating system we have our host our operating system we have our host our operating system we have our host kernel and our application process could kernel and our application process could kernel and our application process could directly run on that kernel or we wrap directly run on that kernel or we wrap directly run on that kernel or we wrap that application process in a kernel that application process in a kernel that application process in a kernel group we kind of cont containerize it we
-
group we kind of cont containerize it we group we kind of cont containerize it we put it in a container but it means that put it in a container but it means that put it in a container but it means that application process still runs on the application process still runs on the application process still runs on the same kernel which means here on the left same kernel which means here on the left same kernel which means here on the left that kernel can actually directly access that kernel can actually directly access that kernel can actually directly access the app process whereas here on the the app process whereas here on the the app process whereas here on the right that host kernel down here cannot right that host kernel down here cannot right that host kernel down here cannot access the app process at least directly access the app process at least directly access the app process at least directly it has to go through like a arbitrary it has to go through like a arbitrary it has to go through like a arbitrary binary layer of the simulated operating binary layer of the simulated operating binary layer of the simulated operating system so that's as a simple difference system so that's as a simple difference system so that's as a simple difference between containers and virtual machine between containers and virtual machine between containers and virtual machine maches and now let's have a look at maches and now let's have a look at maches and now let's have a look at Linux kernel namespaces Nam spaces isolate processes namespaces Nam spaces isolate processes and this is necessary because we want to and this is necessary because we want to and this is necessary because we want to create containers containers are simply create containers containers are simply create containers containers are simply processes on the same Linux kernel but processes on the same Linux kernel but processes on the same Linux kernel but we want to isolate them so we put them we want to isolate them so we put them we want to isolate them so we put them in namespaces there is for example the p in namespaces there is for example the p in namespaces there is for example the p namespace and the P namespace isolates namespace and the P namespace isolates namespace and the P namespace isolates processes from each other one process processes from each other one process processes from each other one process cannot see others and for example cannot see others and for example cannot see others and for example process ID 10 can exist multiple times process ID 10 can exist multiple times process ID 10 can exist multiple times once in every once in every once in every namespace there's the mount namespace namespace there's the mount namespace namespace there's the mount namespace which restricts access to mounts or root which restricts access to mounts or root which restricts access to mounts or root file system there's the network file system there's the network file system there's the network namespace which only allows access to namespace which only allows access to namespace which only allows access to certain network devices firewall routing certain network devices firewall routing certain network devices firewall routing rulle socket port numbers so not able to rulle socket port numbers so not able to rulle socket port numbers so not able to see all traffic or contact all endpoints see all traffic or contact all endpoints see all traffic or contact all endpoints so Network isolation so Network isolation so Network isolation and there's the username space which
-
and there's the username space which and there's the username space which means a different set of user IDs is means a different set of user IDs is means a different set of user IDs is used and for example user Z root inside used and for example user Z root inside used and for example user Z root inside one namespace can be different from user one namespace can be different from user one namespace can be different from user zero inside another namespace and this zero inside another namespace and this zero inside another namespace and this also means that the host root user zero also means that the host root user zero also means that the host root user zero is different than the user zero inside a is different than the user zero inside a is different than the user zero inside a container because of name container because of name container because of name spaces so if we talk about container spaces so if we talk about container spaces so if we talk about container isolation and how containers and Docker isolation and how containers and Docker isolation and how containers and Docker containers are built then we have the containers are built then we have the containers are built then we have the name spaces to restrict what processes name spaces to restrict what processes name spaces to restrict what processes can see and by this we kind of simulate can see and by this we kind of simulate can see and by this we kind of simulate an isolation layer between these and we an isolation layer between these and we an isolation layer between these and we kind of create the containers through kind of create the containers through kind of create the containers through this and this can for example be this and this can for example be this and this can for example be restrict other processes users or file restrict other processes users or file restrict other processes users or file system access and then there are also system access and then there are also system access and then there are also cgroups and these cgroups restrict the cgroups and these cgroups restrict the cgroups and these cgroups restrict the resource usage of processes and this can resource usage of processes and this can resource usage of processes and this can for example be restricting the ram for example be restricting the ram for example be restricting the ram memory usage disk usage or CPU usage and memory usage disk usage or CPU usage and memory usage disk usage or CPU usage and using these namespaces and these c using these namespaces and these c using these namespaces and these c groups we can create isolation container groups we can create isolation container groups we can create isolation container isolation and we can actually create containers in this session we will have containers in this session we will have a a a look and these c groups we wrapped look
-
wrapped look at so what's simulate another operating at so what's simulate another operating at so what's simulate another operating system with FD Nam spaces to restrict system with FD Nam spaces to restrict system with FD Nam spaces to restrict what processes can see and by this we what processes can see and by this we what processes can see and by this we kind of simulate an isolation layer kind of simulate an isolation layer kind of simulate an isolation layer between these and we kind of create the between these and we kind of create the between these and we kind of create the containers through this and this can for containers through this and this can for containers through this and this can for example be restrict other processes example be restrict other processes example be restrict other processes users or file system access and then users or file system access and then users or file system access and then there are also c groups and c groups there are also c groups and c groups there are also c groups and c groups restrict Nam inside like so that's as a simple inside like so that's as a simple difference and now let's have a look at difference and now let's have a look at difference and now let's have a look at Linux kernel namespaces Nam spaces isolate processes namespaces Nam spaces isolate processes and this is necessary because we want to and this is necessary because we want to and this is necessary because we want to create containers containers are simply create containers containers are simply create containers containers are simply processes on the same Linux kernel but processes on the same Linux kernel but processes on the same Linux kernel but we want to isolate them so we put them we want to isolate them so we put them we want to isolate them so we put them in namespaces there is for example the P in namespaces there is for example the P in namespaces there is for example the P ID Nam space ID Nam space ID Nam space and the P name space isolates processes and the P name space isolates processes and the P name space isolates processes from each other one process cannot see from each other one process cannot see from each other one process cannot see others and for example process ID 10 can others and for example process ID 10 can others and for example process ID 10 can exist multiple times once in every name space there's the Mount namespace which space there's the Mount namespace which restricts access to mounts or root file
-
system Mount namespace which restricts system Mount namespace which restricts access to mounts or root file there's the network namespace which only there's the network namespace which only allows access to certain network devices allows access to certain network devices allows access to certain network devices firewall routing rules socket port so not able to see all traffic or so not able to see all traffic or contact all endpoints so Network contact all endpoints so Network contact all endpoints so Network isolation and there's the user name isolation and there's the user name isolation and there's the user name space which means a different set of space which means a different set of space which means a different set of user IDs is used and for example user user IDs is used and for example user user IDs is used and for example user zero root inside one namespace can be zero root inside one namespace can be zero root inside one namespace can be different from user zero inside another different from user zero inside another different from user zero inside another namespace and this also means that the namespace and this also means that the namespace and this also means that the host root
-
user zero is different than the user user zero is different than the user zero inside a container because of name zero inside a container because of name zero inside a container because of name spaces so if we talk about container spaces so if we talk about container spaces so if we talk about container isolation and how containers and Docker isolation and how containers and Docker isolation and how containers and Docker containers are built then we have the containers are built then we have the containers are built then we have the name spaces to restrict what processes name spaces to restrict what processes name spaces to restrict what processes can see and by this we kind of simulate can see and by this we kind of simulate can see and by this we kind of simulate an isolation layer between these and we an isolation layer between these and we an isolation layer between these and we kind of create the containers through kind of create the containers through kind of create the containers through this and this can for example be this and this can for example be this and this can for example be restrict other processes users or file restrict other processes users or file restrict other processes users or file system access and then there are also system access and then there are also system access and then there are also cgroups and these c e restrict resource usage of processes
-
e restrict resource usage of processes and this can for example will be restricting the RAM example will be restricting the RAM memory usage dis usage or CPU usage and using these Nam spaces and usage and using these Nam spaces and these c groups we can create isolation these c groups we can create isolation these c groups we can create isolation container isolation and we can actually container isolation and we can actually container isolation and we can actually create containers containers in this session we will have a look at in this session we will have a look at in this session we will have a look at container tools and the tools are Docker container tools and the tools are Docker container tools and the tools are Docker container D greyl potman and we will container D greyl potman and we will container D greyl potman and we will actually build a very simple container actually build a very simple container actually build a very simple container using these tools so to have a short using these tools so to have a short using these tools so to have a short Overlook what is Docker Docker container Overlook what is Docker Docker container Overlook what is Docker Docker container D container runtime especially not D container runtime especially not D container runtime especially not anymore or C compatible container run anymore or C compatible container run anymore or C compatible container run times the universe with Docker and then times the universe with Docker and then times the universe with Docker and then pman is a container and potman as our pman is a container and potman as our pman is a container and potman as our managing tool so and what we do is we
-
managing tool so and what we do is we managing tool so and what we do is we start from bash so this means there is start from bash so this means there is start from bash so this means there is already an existing image in this case a already an existing image in this case a already an existing image in this case a Docker image bash and we inherit Docker image bash and we inherit Docker image bash and we inherit everything from everything from everything from bash and what we do with this is we bash and what we do with this is we bash and what we do with this is we simply run one comment ping with the simply run one comment ping with the simply run one comment ping with the argument killer. sh two lines this is argument killer. sh two lines this is argument killer. sh two lines this is our Docker file really simple really our Docker file really simple really our Docker file really simple really small really straightforward we save straightforward we save this so here we have our Docker file so this so here we have our Docker file so this so here we have our Docker file so a Docker file is a text an image and all a Docker file is a text an image and all a Docker file is a text an image and all images I grab for images I grab for images I grab for Docker that's all Docker can do because Docker that's all Docker can do because Docker that's all Docker can do because same as pman and we now run been design same as pman and we now run been design same as pman and we now run been design the name Docker with the name Docker with the name Docker with pman so this means we can also set pman so this means we can also set pman so this means we can also set potman image LS and there we potman image LS and there we potman image LS and there we I with potman now let's also talk about cre CTL potman now let's also talk about cre CTL let's Okay since kubernetes version 1.22 let's Okay since kubernetes version 1.22 let's Okay since kubernetes version 1.22 we use container D so what we can do we use container D so what we can do we use container D so what we can do here is we run cctl PS and here we see here is we run cctl PS and here we see here is we run cctl PS and here we see our containers and if we have a look at our containers and if we have a look at our containers and if we have a look at the config the config the config of of of cctl then we actually see it's cctl then we actually see it's cctl then we actually see it's configured to communicate with the
-
configured to communicate with the configured to communicate with the container D runtime so in this config it container D runtime so in this config it container D runtime so in this config it could also be that it's configured to could also be that it's configured to could also be that it's configured to talk to Docker or to another runtime so talk to Docker or to another runtime so talk to Docker or to another runtime so in this case what we see right here is in this case what we see right here is in this case what we see right here is we use cctl to communicate with we use cctl to communicate with we use cctl to communicate with container container container D okay so I think this should give you a D okay so I think this should give you a D okay so I think this should give you a nice introduction into the we can use in nice introduction into the we can use in nice introduction into the we can use in this Hands-On session we will now this Hands-On session we will now this Hands-On session we will now actually see Docker container isolation actually see Docker container isolation actually see Docker container isolation in action we will create two containers in action we will create two containers in action we will create two containers and check that their processes cannot and check that their processes cannot and check that their processes cannot see each other and we will then run them see each other and we will then run them see each other and we will then run them in the very same P ID namespace and see in the very same P ID namespace and see in the very same P ID namespace and see what happens so it's the handson session what happens so it's the handson session what happens so it's the handson session follow me along do the same thing on follow me along do the same thing on follow me along do the same thing on your master note we won't interact with your master note we won't interact with your master note we won't interact with kubernetes right now we will simply run kubernetes right now we will simply run kubernetes right now we will simply run Docker containers for this we can run a Docker containers for this we can run a Docker containers for this we can run a Docker container Docker run we give it a Docker container Docker run we give it a Docker container Docker run we give it a name first one is C1 we would like to name first one is C1 we would like to name first one is C1 we would like to run Ubuntu and we would like to run it run Ubuntu and we would like to run it run Ubuntu and we would like to run it uh detached let's do it like this in uh detached let's do it like this in uh detached let's do it like this in detached mode yuntu and we execute sh detached mode yuntu and we execute sh detached mode yuntu and we execute sh and say this simply sleeps one day okay and say this simply sleeps one day okay and say this simply sleeps one day okay we just created a yuntu container which we just created a yuntu container which we just created a yuntu container which sleeps one day and runs in the sleeps one day and runs in the sleeps one day and runs in the background we see here the ID we could background we see here the ID we could background we see here the ID we could now use the ID but because we gave it a now use the ID but because we gave it a now use the ID but because we gave it a name we can also use that name so we can name we can also use that name so we can name we can also use that name so we can simply do doer XX
-
simply do doer XX simply do doer XX C1 PS and then we see okay few processes C1 PS and then we see okay few processes C1 PS and then we see okay few processes in that container very clean and here we in that container very clean and here we in that container very clean and here we actually have our sleep container actually have our sleep container actually have our sleep container running our sleep process running in running our sleep process running in running our sleep process running in that that that container let's do the same for a container let's do the same for a container let's do the same for a container named C2 and instead of container named C2 and instead of container named C2 and instead of sleeping one day we say we sleep 999 days there we go container created 999 days there we go container created and if we now exec into that container and if we now exec into that container and if we now exec into that container then we also see three processes but we then we also see three processes but we then we also see three processes but we see they're different here we have that see they're different here we have that see they're different here we have that sleep one with 999 days and here we sleep one with 999 days and here we sleep one with 999 days and here we actually have that sleep one with one actually have that sleep one with one actually have that sleep one with one day so this means these processes run on day so this means these processes run on day so this means these processes run on the same Linux ker but these are the same Linux ker but these are the same Linux ker but these are isolated from each other because Docker isolated from each other because Docker isolated from each other because Docker automatically wraps these processes in automatically wraps these processes in automatically wraps these processes in name spaces name spaces name spaces and if we now actually have a look if we and if we now actually have a look if we and if we now actually have a look if we now grab for processes called Sleep on now grab for processes called Sleep on now grab for processes called Sleep on our host Linux system then we actually our host Linux system then we actually our host Linux system then we actually see we see both processes right we see see we see both processes right we see see we see both processes right we see the Sleep one day and we see the Sleep the Sleep one day and we see the Sleep the Sleep one day and we see the Sleep 999 days why because the container 999 days why because the container 999 days why because the container processes simply run on the same Linux processes simply run on the same Linux processes simply run on the same Linux kernel now let's actually delete the kernel now let's actually delete the kernel now let's actually delete the second container so we can simply do second container so we can simply do second container so we can simply do Docker RM C2 and forse Docker RM C2 and forse Docker RM C2 and forse our C2 container is our C2 container is our C2 container is gun and we recreate the container again gun and we recreate the container again gun and we recreate the container again but with an addition we can actually
-
but with an addition we can actually but with an addition we can actually Define the P ID namespace so the reason I'm not seeing namespace so the reason I'm not seeing this on my Mac OS system is because I'm this on my Mac OS system is because I'm this on my Mac OS system is because I'm using Rancher using Rancher using Rancher desktop um to run Docker so let's see if desktop um to run Docker so let's see if desktop um to run Docker so let's see if we can actually enter the enter Rancher we can actually enter the enter Rancher we can actually enter the enter Rancher desktop desktop desktop if we can actually connect to the VM can VM can I actually enter that VM VM [Music] [Music] [Music] because desktop these are the containers because desktop these are the containers because desktop these are the containers I'm running so you can see them here but can I actually enter this VM but can I actually enter this VM somehow oral volumes don't think I can just enter volumes don't think I can just enter that can I see the processes on here I don't really want to get into Linux VM I don't really want to get into Linux VM right now I'm just wanted right now I'm just wanted right now I'm just wanted to see
-
this yeah I I mean I intended to follow this yeah I I mean I intended to follow on follow along on all the handson stuff on follow along on all the handson stuff on follow along on all the handson stuff but I I do fully understand what's going but I I do fully understand what's going but I I do fully understand what's going on here on here on here so I I think I'm okay with this let's so I I think I'm okay with this let's so I I think I'm okay with this let's just continue and we set it to the Nam just continue and we set it to the Nam just continue and we set it to the Nam space of an existing container called C1 space of an existing container called C1 space of an existing container called C1 okay so we create the container C2 and okay so we create the container C2 and okay so we create the container C2 and with this little addition we now say with this little addition we now say with this little addition we now say this container will run in the very same this container will run in the very same this container will run in the very same P ID name spaces name space as container P ID name spaces name space as container P ID name spaces name space as container one let's run it there we go and let's one let's run it there we go and let's one let's run it there we go and let's have a look let's exec into container C2 have a look let's exec into container C2 have a look let's exec into container C2 look for processes and yes there we look for processes and yes there we look for processes and yes there we actually see our own processes and the actually see our own processes and the actually see our own processes and the ones from the other container and if we ones from the other container and if we ones from the other container and if we now have a look at container run we run now have a look at container run we run now have a look at container run we run the same command for container one then the same command for container one then the same command for container one then we actually see both containers are now we actually see both containers are now we actually see both containers are now in the same P ID name space and can see in the same P ID name space and can see in the same P ID name space and can see their same processes because of this and this section gave us a nice this and this section gave us a nice little overview about what containers little overview about what containers little overview about what containers are and there's a very great talk by LZ are and there's a very great talk by LZ are and there's a very great talk by LZ rice what have namespaces done for you rice what have namespaces done for you rice what have namespaces done for you lately where she actually shows in a bit lately where she actually shows in a bit lately where she actually shows in a bit more detail and also practical how more detail and also practical how more detail and also practical how containers are created and what containers are created and what containers are created and what containers actually containers actually containers actually are
-
in in I currently work for a company called I currently work for a company called I currently work for a company called aqua Security in this section we talked about Security in this section we talked about containers in general we made a containers in general we made a containers in general we made a comparison towards virtual machines we comparison towards virtual machines we comparison towards virtual machines we talked about Linux kernel namespaces and talked about Linux kernel namespaces and talked about Linux kernel namespaces and c groups in the Linux kernel and we c groups in the Linux kernel and we c groups in the Linux kernel and we actually saw these in action by creating actually saw these in action by creating actually saw these in action by creating Docker certification certification so what is so what is so what is the it's probably this one then the it's probably this one then the it's probably this one then container name environment uh I think I had that open environment uh I think I had that open the other day
-
course course environment scenarios yeah contain name space is scenarios yeah contain name space is Docker name space is podman okay let's check it out container name okay let's check it out container name space is space is space is [Music] [Music] [Music] Docker well I had a big mouth and said Docker well I had a big mouth and said Docker well I had a big mouth and said that I understood what was going on so that I understood what was going on so that I understood what was going on so now we're going to see if I actually do how much do they charge for the Plus do how much do they charge for the Plus Membership 10 bucks a Min okay I might have actually go for Min okay I might have actually go for that membership for this uh study for a that membership for this uh study for a that membership for this uh study for a month this is going to be really month this is going to be really month this is going to be really annoying annoying annoying to wait for these cues that at any point in time you can reset that at any point in time you can reset your cluster anytime you like you can your cluster anytime you like you can your cluster anytime you like you can delete your instances recreate them and
-
delete your instances recreate them and delete your instances recreate them and create your cluster again because every create your cluster again because every create your cluster again because every new section in this course works with a new section in this course works with a new section in this course works with a fresh cluster this doesn't mean that you fresh cluster this doesn't mean that you fresh cluster this doesn't mean that you have to work with a fresh cluster when have to work with a fresh cluster when have to work with a fresh cluster when the because every new networks Network policy new networks Network policy okay that is the one that I have okay that is the one that I have okay that is the one that I have um that's going to be the next um that's going to be the next um that's going to be the next section and thator policies are section and thator policies are section and thator policies are definitely my one of my weaknesses and I definitely my one of my weaknesses and I definitely my one of my weaknesses and I have set up a new set of daily routines have set up a new set of daily routines have set up a new set of daily routines for myself where I'm going to be doing for myself where I'm going to be doing for myself where I'm going to be doing rback scenarios and rback scenarios and rback scenarios and also Network policy scenarios every day also Network policy scenarios every day also Network policy scenarios every day just to get um get it into my fingers Docker solve in the remote desktop Docker solve in the remote desktop environment okay yes let's start run two Docker okay yes let's start run two Docker containers app1 app2 with the following containers app1 app2 with the following containers app1 app2 with the following attributes they should run image engine attributes they should run image engine attributes they should run image engine X X X Alpine should share the same P kernel
-
namespace and check which container sees namespace and check which container sees which processes and makes sense of why which processes and makes sense of why which processes and makes sense of why okay I should R share the same P kernel okay I should R share the same P kernel okay I should R share the same P kernel Nam Nam Nam space well that was exactly what he was space well that was exactly what he was space well that was exactly what he was doing here here see see see to to to so first we so first we so first we will will will Docker the one that I was using oops her oops her name F1 images and it images and it was Infinity I should run in the background Infinity I should run in the background that's what I do here with the D D and
-
that's what I do here with the D D and that's what I do here with the D D and they should share the same P curdle name they should share the same P curdle name they should share the same P curdle name space so app1 can just run like okay Docker okay Docker PS that's running now the second one is PS that's running now the second one is PS that's running now the second one is going to the what was the command the ID is the what was the command the ID is [Music] [Music] [Music] container One One [Music] [Music] [Music] MH then MH then MH then docker docker docker exac annoying sleep Infinity sleep Infinity annoying sleep Infinity sleep Infinity so the in the docker the app1 container so the in the docker the app1 container so the in the docker the app1 container is now seeing both of
-
is now seeing both of is now seeing both of them and the app2 them and the app2 them and the app2 container can also see both of them so container can also see both of them so container can also see both of them so they're it is they're it is they're it is mutual it like they can see both sleep it like they can see both sleep Infinity yeah I think I've solved it Infinity yeah I think I've solved it Infinity yeah I think I've solved it let's check let's check let's check it congratulations you solved the it congratulations you solved the it congratulations you solved the challenge okay challenge okay challenge okay nice then we're going back to the scenarios scenarios and the next one was and the next one was and the next one was on then going to save that command that's then going to save that command that's actually quite a useful to so Infinity oh this one loaded a lot Infinity oh this one loaded a lot quicker okay so I can just go straight
-
quicker okay so I can just go straight quicker okay so I can just go straight forward run two potman containers f one forward run two potman containers f one forward run two potman containers f one yeah so it's basically the same but here yeah so it's basically the same but here yeah so it's basically the same but here we're not using Docker but we're using we're not using Docker but we're using we're not using Docker but we're using CRI CTL CRI CTL CRI CTL probably uh which probably uh which probably uh which Docker Docker Docker which which z which which z which which z i bman okay so is potman running bman okay so is potman running [Music] okay I see so this this was just Docker okay I see so this this was just Docker run and then now he wants me to do it in run and then now he wants me to do it in run and then now he wants me to do it in podman and that's interesting I have podman and that's interesting I have podman and that's interesting I have actually I haven't been using podman at actually I haven't been using podman at actually I haven't been using podman at all all all so run two potman containers at one so so run two potman containers at one so so run two potman containers at one so let's just check it out if it is exactly let's just check it out if it is exactly let's just check it out if it is exactly the same or the same or the same or not Locker run just trying if it is actually the
-
run just trying if it is actually the same same same command bman R name bman R name F1 yeah why did it come as image Alpine it yeah why did it come as image Alpine it should be engine X okay so pman PS does that work yeah okay so pman PS does that work yeah that's just the okay set- okay set- OVI botman OVI botman OVI botman run app run app run app two the ID is two the ID is two the ID is container it is it that easy it's just just it is it that easy it's just just mutually
-
potman xac app to PS potman xac app to PS o see it from there and F1 can see it o see it from there and F1 can see it o see it from there and F1 can see it from there too so this should be the from there too so this should be the from there too so this should be the solution then let's check solution then let's check solution then let's check it congratulations you solved the it congratulations you solved the it congratulations you solved the challenge well that was easy I am going challenge well that was easy I am going challenge well that was easy I am going to copy this command okay botman okay botman run y yeah so these are exactly the same so y yeah so these are exactly the same so what I've learned is actually going back to my CS notes actually going back to my CS notes that potman and Docker command same at least as far as I've seen up same at least as far as I've seen up until no these commands no these commands run two containers in the same P Nam
-
space can check the running can check if space can check the running can check if they they they are running in the running in the same Nam same Nam same Nam Space by Space by Space by running the thing the Sleep command thing the Sleep command appears twice in each container with a appears twice in each container with a appears twice in each container with a different B ID also also [Music] [Music] [Music] note that there are note that there are note that there are multiple processes running as roots okay that was the first section roots okay that was the first section and I actually have three poo three um and I actually have three poo three um and I actually have three poo three um minutes left on my Pomodoro minutes left on my Pomodoro minutes left on my Pomodoro Timer so that is actually a nice uh Timer so that is actually a nice uh Timer so that is actually a nice uh point to take a point to take a point to take a break I have now finished the this break I have now finished the this break I have now finished the this section of the course I've generated section of the course I've generated section of the course I've generated quite a couple of not notes Here quite a couple of not notes Here quite a couple of not notes Here container isolation containerized
-
container isolation containerized container isolation containerized applications I learned that the Linux applications I learned that the Linux applications I learned that the Linux kernel also has name spaces for kernel also has name spaces for kernel also has name spaces for isolation I actually I only know name spaces in the actually I only know name spaces in the kubernetes context so that was cool to kubernetes context so that was cool to kubernetes context so that was cool to learn that it's actually on the Linux learn that it's actually on the Linux learn that it's actually on the Linux level as level as level as well and yeah some some good notes here already and now I will take a 10minute already and now I will take a 10minute break and I am going to continue with break and I am going to continue with break and I am going to continue with network policies and that is like network policies and that is like network policies and that is like Network policies I I have them in my Network policies I I have them in my Network policies I I have them in my home lab I know how they work but to home lab I know how they work but to home lab I know how they work but to actually do them actually do them actually do them of the cough on an exam like that will of the cough on an exam like that will of the cough on an exam like that will definitely need a lot more practice definitely need a lot more practice definitely need a lot more practice so let's see can I can I run some sort so let's see can I can I run some sort so let's see can I can I run some sort of nice of nice of nice countdown timary in that's something I'll have to do but that's something I'll have to do but I'll just do I'll just do I'll just do the Pomo start I'll just do another Pomo
-
the Pomo start I'll just do another Pomo the Pomo start I'll just do another Pomo and if this reaches to 40 I'll be back and if this reaches to 40 I'll be back and if this reaches to 40 I'll be back figlet on a figlet on a figlet on a break biglet will return When Pomo break biglet will return When Pomo break biglet will return When Pomo reaches got a couple of minutes left and I
-
got a couple of minutes left and I realized I had another can of Coke that realized I had another can of Coke that realized I had another can of Coke that was nice I hardly ever drink soda but was nice I hardly ever drink soda but was nice I hardly ever drink soda but now I felt like I could use now I felt like I could use now I felt like I could use one uh I need to figure out if I'm going one uh I need to figure out if I'm going one uh I need to figure out if I'm going to be streaming more I'll need to have a to be streaming more I'll need to have a to be streaming more I'll need to have a way of doing this better and I just way of doing this better and I just way of doing this better and I just remembered that remembered that remembered that Rob he has this term down Rob he has this term down Rob he has this term down thing thing thing Rob maybe it's in his DOT files repo repo term term down I think term down was the command down I think term down was the command that he has oh it's not even his turn has oh it's not even his turn down countdown timer and stopwatch in down countdown timer and stopwatch in down countdown timer and stopwatch in your terminal okay so that's a terminal okay so that's a pip pip pip package pip three install term down okay apparently I have
-
down okay apparently I have a no wow I don't have any wow I don't have any python pip install term python pip install term python pip install term down I thought I had python packages down I thought I had python packages down I thought I had python packages installed that's installed that's installed that's interesting so will only run as a I didn't find it like that no available I didn't find it like that no available formula with term formula with term formula with term down I know it's pip pip 3 install term down I know it's pip pip 3 install term down I know it's pip pip 3 install term down but it is um apparently have some down but it is um apparently have some down but it is um apparently have some sort of python environment configured sort of python environment configured sort of python environment configured for my Brew I was not aware of
-
that yeah I probably like I this is that yeah I probably like I this is probably not something that I should probably not something that I should probably not something that I should dive into right now but is there a dive into right now but is there a dive into right now but is there a countdown countdown timer in terminal if countdown countdown timer in terminal if countdown countdown timer in terminal if I have a quick solution for that and if not like my my Brak is that and if not like my my Brak is already over by the way it's yeah no I'm already over by the way it's yeah no I'm already over by the way it's yeah no I'm not going to fix this not going to fix this not going to fix this now but what I did was actually quite now but what I did was actually quite now but what I did was actually quite quite handy that I what I had going on quite handy that I what I had going on quite handy that I what I had going on here on a break will return When PMA here on a break will return When PMA here on a break will return When PMA reaches 40 minutes I could just write a reaches 40 minutes I could just write a reaches 40 minutes I could just write a script for that call it break and then script for that call it break and then script for that call it break and then at least I have something to at least I have something to at least I have something to show but like which break is that a show but like which break is that a show but like which break is that a command already oh let's do new here no it did do with in my scripts here no it did do with in my scripts directory so I'll just go to directory so I'll just go to directory so I'll just go to V break then I'll just V break then I'll just V break then I'll just add biglet on a brake
-
break will return When PMA reaches 40 break will return When PMA reaches 40 minutes this is a quick solution for now and then I'll do it solution for now and then I'll do it later so break ah break will break ah break will okay uh okay uh okay uh dot CD break yeah that will work on a break break yeah that will work on a break will return When P reaches 40 minutes will return When P reaches 40 minutes will return When P reaches 40 minutes and then it has a timer up here so now I and then it has a timer up here so now I and then it has a timer up here so now I have a quick little script okay that have a quick little script okay that have a quick little script okay that works uh um feed add Brak um feed add Brak script okay that only took a few minutes script okay that only took a few minutes script okay that only took a few minutes I wasn't distracted too long so now I I wasn't distracted too long so now I I wasn't distracted too long so now I can continue with can continue with can continue with my with my uh CS studies P my with my uh CS studies P my with my uh CS studies P start okay so I just finished the start okay so I just finished the start okay so I just finished the [Music] [Music] [Music] container um isolation container um isolation container um isolation exercises exercises exercises those work pretty those work pretty those work pretty well uh I had no problem solving those well uh I had no problem solving those well uh I had no problem solving those [Music] [Music] [Music] so cks now going and moving on to the so cks now going and moving on to the so cks now going and moving on to the next section which is going to be
-
next section which is going to be next section which is going to be Network policies hey hervey hey Ben Archer nice policies hey hervey hey Ben Archer nice to see you guys starting the new Pomo timer and guys starting the new Pomo timer and starting the next section Network starting the next section Network starting the next section Network policies and with this little addition policies and with this little addition policies and with this little addition we now say this container various import container various import fresh network security fresh network security fresh network security policies very important and interesting policies very important and interesting policies very important and interesting topic in my opinion what we will do at topic in my opinion what we will do at topic in my opinion what we will do at first I'll go into detail what network first I'll go into detail what network first I'll go into detail what network policies are and how they work policies are and how they work policies are and how they work afterwards we will Define our own afterwards we will Define our own afterwards we will Define our own default deny policy following by various default deny policy following by various default deny policy following by various scenarios that we're going to implement scenarios that we're going to implement scenarios that we're going to implement after this you will understand network after this you will understand network after this you will understand network security security security policies what are they Network policies policies what are they Network policies policies what are they Network policies well they are the firewall rules in well they are the firewall rules in well they are the firewall rules in kubernetes they are implemented by the kubernetes they are implemented by the kubernetes they are implemented by the cni by the container network interface cni by the container network interface cni by the container network interface which is installed in the cluster so which is installed in the cluster so which is installed in the cluster so like Calico or we so if the cni um like Calico or we so if the cni um like Calico or we so if the cni um doesn't support network policies you can doesn't support network policies you can doesn't support network policies you can still create the kubernetes resources still create the kubernetes resources still create the kubernetes resources but that just don't do anything they're but that just don't do anything they're but that just don't do anything they're not not not enforced they are created on namespace enforced they are created on namespace enforced they are created on namespace level they're only valid in one level they're only valid in one level they're only valid in one namespace we will see this later and namespace we will see this later and namespace we will see this later and well yeah they restrict Ingress and well yeah they restrict Ingress and well yeah they restrict Ingress and agress for a specific group of PODS agress for a specific group of PODS agress for a specific group of PODS based on certain rules and
-
based on certain rules and based on certain rules and conditions without network policy so if conditions without network policy so if conditions without network policy so if we have a vanilla kubernetes cluster we have a vanilla kubernetes cluster we have a vanilla kubernetes cluster then by default every poort can access then by default every poort can access then by default every poort can access every pot pots are not isolated and this every pot pots are not isolated and this every pot pots are not isolated and this is actually a feature from kubernetes is actually a feature from kubernetes is actually a feature from kubernetes right like it's one condition um that right like it's one condition um that right like it's one condition um that every pot in the cluster doesn't matter every pot in the cluster doesn't matter every pot in the cluster doesn't matter on which note it's scheduled every pot on which note it's scheduled every pot on which note it's scheduled every pot can communicate with every pot um can communicate with every pot um can communicate with every pot um without network address without network address without network address translation so let's have a look at what translation so let's have a look at what translation so let's have a look at what network policies can do just in some network policies can do just in some network policies can do just in some graphical overview examples that we're graphical overview examples that we're graphical overview examples that we're going to run through before we go and going to run through before we go and going to run through before we go and look into yl and write we can pots based look into yl and write we can pots based look into yl and write we can pots based on their labels okay in Orange here and on their labels okay in Orange here and on their labels okay in Orange here and to these pots to these pots to these pots based on the pot selector to these pots based on the pot selector to these pots based on the pot selector to these pots will our Network policy rules will our Network policy rules will our Network policy rules applied then let's say we have another applied then let's say we have another applied then let's say we have another uh group of pots here so we specify uh group of pots here so we specify uh group of pots here so we specify another pot selector and now what we another pot selector and now what we another pot selector and now what we specify in our Network policy is that specify in our Network policy is that specify in our Network policy is that for that pot selector in Orange we allow for that pot selector in Orange we allow for that pot selector in Orange we allow policy type erress we allow outgoing policy type erress we allow outgoing policy type erress we allow outgoing traffic to these pots okay should be traffic to these pots okay should be traffic to these pots okay should be really simple from a source pots we really simple from a source pots we really simple from a source pots we allow outgoing traffic to to another pot allow outgoing traffic to to another pot allow outgoing traffic to to another pot selector to these pots based on selector to these pots based on selector to these pots based on labels also possible same scenario but labels also possible same scenario but labels also possible same scenario but from or to these pot selector in Orange from or to these pot selector in Orange from or to these pot selector in Orange we allow incoming traffic so Ingress we allow incoming traffic so Ingress we allow incoming traffic so Ingress traffic from these pots also possible traffic from these pots also possible traffic from these pots also possible okay and if we have a look at this okay and if we have a look at this okay and if we have a look at this example right now then this PT
-
example right now then this PT example right now then this PT one can only receive incoming traffic one can only receive incoming traffic one can only receive incoming traffic from pots of this pot from pots of this pot from pots of this pot selector because as soon as you specify selector because as soon as you specify selector because as soon as you specify one network policy yet now in this case one network policy yet now in this case one network policy yet now in this case for example Network policy of type for example Network policy of type for example Network policy of type Ingress then you restrict all other Ingress then you restrict all other Ingress then you restrict all other Ingress and you only allow that Ingress Ingress and you only allow that Ingress Ingress and you only allow that Ingress that you kind of WID listed in your that you kind of WID listed in your that you kind of WID listed in your network policies if there are no network network policies if there are no network network policies if there are no network policies then everything is a lot another example instead of using a lot another example instead of using a pot selector is also that we use a pot selector is also that we use a pot selector is also that we use a namespace selector so in this scenario namespace selector so in this scenario namespace selector so in this scenario for these bunch of pots based on the pot for these bunch of pots based on the pot for these bunch of pots based on the pot selector we allow incoming traffic from selector we allow incoming traffic from selector we allow incoming traffic from all poorts in a certain all poorts in a certain all poorts in a certain namespace and what's also possible is to namespace and what's also possible is to namespace and what's also possible is to use an IP block definition where we say use an IP block definition where we say use an IP block definition where we say in this example now we allow these pots in this example now we allow these pots in this example now we allow these pots to have outgoing traffic to this IP to have outgoing traffic to this IP to have outgoing traffic to this IP address range and we could also specify address range and we could also specify address range and we could also specify that this IP address range or that these that this IP address range or that these that this IP address range or that these pots can receive Ingress traffic from pots can receive Ingress traffic from pots can receive Ingress traffic from this IP address range okay and this we this IP address range okay and this we this IP address range okay and this we could do in two separate Network could do in two separate Network could do in two separate Network policies then there would be merged policies then there would be merged policies then there would be merged we're going to look at this uh in more we're going to look at this uh in more we're going to look at this uh in more detail but we could also create this in detail but we could also create this in detail but we could also create this in one network policy where we have one network policy where we have one network policy where we have actually rules for the agress and the Ingress in the section before we had a Ingress in the section before we had a look at Network policies for like a top look at Network policies for like a top look at Network policies for like a top overview um and we saw what they're like
-
overview um and we saw what they're like overview um and we saw what they're like capable of in theory now we're going to capable of in theory now we're going to capable of in theory now we're going to look at one extensive example of a look at one extensive example of a look at one extensive example of a network policy in yaml and we dive into network policy in yaml and we dive into network policy in yaml and we dive into detail and every section so that you can detail and every section so that you can detail and every section so that you can create afterwards every kind of network create afterwards every kind of network create afterwards every kind of network policy that you kind of policy that you kind of policy that you kind of want this network policy we see kind want this network policy we see kind want this network policy we see kind Network policy is created in namespace Network policy is created in namespace Network policy is created in namespace default and we have a pot selector for default and we have a pot selector for default and we have a pot selector for pots with the label ID front end okay so pots with the label ID front end okay so pots with the label ID front end okay so that means this network policy will be that means this network policy will be that means this network policy will be applied to pots with ID front end in applied to pots with ID front end in applied to pots with ID front end in namespace default now we have default now we have another um section here policy types another um section here policy types another um section here policy types policy types uh can receive an array of policy types uh can receive an array of policy types uh can receive an array of entries Ingress or aress and this in entries Ingress or aress and this in entries Ingress or aress and this in this case we only specify aress this this case we only specify aress this this case we only specify aress this network policy that we see here right network policy that we see here right network policy that we see here right now is already a valid policy okay we now is already a valid policy okay we now is already a valid policy okay we could create that policy right now what could create that policy right now what could create that policy right now what does it do it denies all outgoing does it do it denies all outgoing does it do it denies all outgoing traffic from pots with label ID frontend traffic from pots with label ID frontend traffic from pots with label ID frontend in namespace in namespace in namespace default okay it denies all outgoing default okay it denies all outgoing default okay it denies all outgoing traffic because we said that this traffic because we said that this traffic because we said that this network policy is about outgoing traffic network policy is about outgoing traffic network policy is about outgoing traffic and we didn't specify any rules to allow and we didn't specify any rules to allow and we didn't specify any rules to allow any traffic this which means that this any traffic this which means that this any traffic this which means that this policy right now simply doesn't allow policy right now simply doesn't allow policy right now simply doesn't allow any outgoing traffic so it prevents it any outgoing traffic so it prevents it any outgoing traffic so it prevents it disallows any outgoing traffic now let's disallows any outgoing traffic now let's disallows any outgoing traffic now let's allow some allow some allow some traffic yeah so that's that's why I traffic yeah so that's that's why I traffic yeah so that's that's why I always get it wrong right I I I have always get it wrong right I I I have always get it wrong right I I I have some Network policies here these are um some Network policies here these are um some Network policies here these are um celium Network policies so they are a
-
celium Network policies so they are a celium Network policies so they are a little bit different than uh the normal little bit different than uh the normal little bit different than uh the normal standard Network policies that he's standard Network policies that he's standard Network policies that he's talking about talking about talking about but just the fact that this is already a but just the fact that this is already a but just the fact that this is already a valid Network policy that is definitely valid Network policy that is definitely valid Network policy that is definitely something something something I going to note down so see going back to see going back to my cks notes here and I'm debating whether I should here and I'm debating whether I should have one network policy note or if I'm have one network policy note or if I'm have one network policy note or if I'm going to make different Zs out of this going to make different Zs out of this going to make different Zs out of this but just go for Network policies for Network policies for now start writing some notes but what now start writing some notes but what now start writing some notes but what I'm actually want to I'm actually want to I'm actually want to do is see gu going to create some Network is see gu going to create some Network policy um files here I'm going to create policy um files here I'm going to create policy um files here I'm going to create a directory called Network erress erress [Music]
-
for for policy policy policy types a valid a valid policy this will deny all outgoing policy this will deny all outgoing policy this will deny all outgoing traffic traffic traffic from pods the label ID is front pods the label ID is front end so that is something that I'll have end so that is something that I'll have end so that is something that I'll have to like I fully want to internalize this will deny all outgoing this will deny all outgoing traffic from the pot so I understand traffic from the pot so I understand traffic from the pot so I understand that this like Network policies is my my that this like Network policies is my my that this like Network policies is my my my weakness and I'm going to put in a my weakness and I'm going to put in a my weakness and I'm going to put in a lot of practice into this so I'm just lot of practice into this so I'm just lot of practice into this so I'm just going to really make sure I understand what is to really make sure I understand what is going on here so
-
so what he was saying before if you have no policies then before if you have no policies then everything is allowed but as soon as you everything is allowed but as soon as you everything is allowed but as soon as you apply some sort of policy nothing is apply some sort of policy nothing is apply some sort of policy nothing is allowed except for what you allowed except for what you allowed except for what you define that is actually something I define that is actually something I define that is actually something I should note down here should note down here should note down here so by so by so by default all PS can communicate with each default all PS can communicate with each default all PS can communicate with each other that's something I knew I also other that's something I knew I also other that's something I knew I also kind of knew that uh if kind of knew that uh if kind of knew that uh if you if no policy only that policy is allowed is policy only that policy is allowed is that what he said like did I get that that what he said like did I get that that what he said like did I get that right let's check it out is created in namespace default and out is created in namespace default and we have a PO we have a PO we have a PO select traffic from this in one in the select traffic from this in one in the select traffic from this in one in the section before what there like capable section before what there like capable section before what there like capable Network policies for make a top overview Network policies for make a top overview Network policies for make a top overview in outgoing traffic to these parts okay in outgoing traffic to these parts okay in outgoing traffic to these parts okay should be really simple from a should be really simple from a should be really simple from a source very I'll go into detail and our source very I'll go into detail and our source very I'll go into detail and our what are in the cluster youat and well what are in the cluster youat and well what are in the cluster youat and well yeah there yeah there yeah there if we have a vanilla kubernetes cluster
-
if we have a vanilla kubernetes cluster if we have a vanilla kubernetes cluster then by default every pot can access then by default every pot can access then by default every pot can access every pot pots are not isolated and this every pot pots are not isolated and this every pot pots are not isolated and this is actually a feature from kubernetes is actually a feature from kubernetes is actually a feature from kubernetes right like it's one condition um that right like it's one condition um that right like it's one condition um that every pot in the cluster doesn't matter every pot in the cluster doesn't matter every pot in the cluster doesn't matter on which note it's scheduled every pot on which note it's scheduled every pot on which note it's scheduled every pot can communicate with every pot um can communicate with every pot um can communicate with every pot um without network address without network address without network address translation so let's have a look at what translation so let's have a look at what translation so let's have a look at what netet we're going to run through is netet we're going to run through is netet we're going to run through is class and network policy rules class and network policy rules class and network policy rules applied on the pot selector to these applied on the pot selector to these applied on the pot selector to these pots will our Network policy rules pots will our Network policy rules pots will our Network policy rules applied another pot selector and now applied another pot selector and now applied another pot selector and now what we specify in our Network policy is what we specify in our Network policy is what we specify in our Network policy is that for that pot selector in Orange we that for that pot selector in Orange we that for that pot selector in Orange we allow policy type erress we allow allow policy type erress we allow allow policy type erress we allow outgoing traffic to these pots okay outgoing traffic to these pots okay outgoing traffic to these pots okay should be really simple from a source should be really simple from a source should be really simple from a source pots we allow outgoing traffic to to pots we allow outgoing traffic to to pots we allow outgoing traffic to to another pot selector to these pots based another pot selector to these pots based another pot selector to these pots based on on on labels also possible same labels also possible same labels also possible same we we we allow can only resp then this possible allow can only resp then this possible allow can only resp then this possible okay and if we have a look at this okay and if we have a look at this okay and if we have a look at this example right now then this port example right now then this port example right now then this port one can only receive incoming traffic one can only receive incoming traffic one can only receive incoming traffic from pots of this pot from pots of this pot from pots of this pot selector because as soon as you specify selector because as soon as you specify selector because as soon as you specify one network policy yet now in this case one network policy yet now in this case one network policy yet now in this case for example po of type Ingress then you for example po of type Ingress then you for example po of type Ingress then you restrict all other Ingress and you only restrict all other Ingress and you only restrict all other Ingress and you only allow that Ingress that you kind of WID
-
allow that Ingress that you kind of WID allow that Ingress that you kind of WID listed in your network policies if there listed in your network policies if there listed in your network policies if there are yeah that was what I wanted to get are yeah that was what I wanted to get are yeah that was what I wanted to get so if so if so if you if you specify a network you if you specify a network you if you specify a network policy then only that is allowed nothing policy then only that is allowed nothing policy then only that is allowed nothing else like did I get that right am I else like did I get that right am I else like did I get that right am I understanding that right as you specify understanding that right as you specify understanding that right as you specify from pots of this pot from pots of this pot from pots of this pot selector because as soon as you specify selector because as soon as you specify selector because as soon as you specify one network policy yet now in this case one network policy yet now in this case one network policy yet now in this case for example networ policy of type for example networ policy of type for example networ policy of type Ingress then you restrict all other Ingress then you restrict all other Ingress then you restrict all other Ingress and you only allow that Ingress Ingress and you only allow that Ingress Ingress and you only allow that Ingress that you kind of wide listed in your that you kind of wide listed in your that you kind of wide listed in your network policies if yeah network policies if yeah network policies if yeah yeah only if you apply one so that's so that's why if I just say policy egress here if I'm not saying the the ESS can here if I'm not saying the the ESS can go to go to go to somewhere then there is no egress somewhere then there is no egress somewhere then there is no egress traffic allowed at all because I'm not traffic allowed at all because I'm not traffic allowed at all because I'm not saying you can go here I'm just saying saying you can go here I'm just saying saying you can go here I'm just saying the the the policy type is policy type is policy type is ESS and I'm not specifying any rules Ah
-
ESS and I'm not specifying any rules Ah ESS and I'm not specifying any rules Ah that's why it case because no ESS rules traffic is case because no ESS rules traffic is allowed is defined yeah defined yeah because no ESS rule is because no ESS rule is because no ESS rule is defined no ESS traffic is allowed either that's why it either that's why it is yeah I think I fully grasp it now is yeah I think I fully grasp it now is yeah I think I fully grasp it now this particular one I think I fully this particular one I think I fully this particular one I think I fully grasp why this is a a valid grasp why this is a a valid grasp why this is a a valid policy I select these pods policy I select these pods policy I select these pods I'm just saying egress and I'm not I'm just saying egress and I'm not I'm just saying egress and I'm not defining any rules for the defining any rules for the defining any rules for the egress egress egress therefore if I don't specify you can do therefore if I don't specify you can do therefore if I don't specify you can do this then nothing can be this then nothing can be this then nothing can be done okay there are no network policies then okay there are no network policies then everything is
-
aot another example instead of using a aot another example instead of using a PO selector is also that we use po PO selector is also that we use po PO selector is also that we use po select and what's also possible is to select and what's also possible is to select and what's also possible is to use an i in your favorite editor this use an i in your favorite editor this use an i in your favorite editor this one and this we applied allow incoming one and this we applied allow incoming one and this we applied allow incoming traffic possible is to use an IP block traffic possible is to use an IP block traffic possible is to use an IP block definition where we say in this example definition where we say in this example definition where we say in this example now we allow these pots to have outgoing now we allow these pots to have outgoing now we allow these pots to have outgoing traffic to this and we didn't specify traffic to this and we didn't specify traffic to this and we didn't specify any rules to allow any traffic this any rules to allow any traffic this any rules to allow any traffic this which means that this policy right now which means that this policy right now which means that this policy right now simply doesn't allow any outgoing simply doesn't allow any outgoing simply doesn't allow any outgoing traffic so it prevents it disallows any traffic so it prevents it disallows any traffic so it prevents it disallows any outgoing traffic now let's allow some outgoing traffic now let's allow some outgoing traffic now let's allow some traffic same NE policy as before um we traffic same NE policy as before um we traffic same NE policy as before um we just extended it here on on the bottom just extended it here on on the bottom just extended it here on on the bottom and we will go now again through all the and we will go now again through all the and we will go now again through all the various things various things various things okay just to test myself here I realize okay just to test myself here I realize okay just to test myself here I realize here I see here I see here I see policy type is egress and by creating policy type is egress and by creating policy type is egress and by creating the egress block this is where you the egress block this is where you the egress block this is where you actually Define the rules so I'm saying actually Define the rules so I'm saying actually Define the rules so I'm saying you're allowed to go have outbound you're allowed to go have outbound you're allowed to go have outbound traffic egress traffic to this namespace um on only through this namespace um on only through this protocol to those ports so you can only protocol to those ports so you can only protocol to those ports so you can only go to this namespace this port and you go to this namespace this port and you go to this namespace this port and you can only connect to can only connect to can only connect to pods that have the label back end so if pods that have the label back end so if pods that have the label back end so if there are pods in there that have any
-
there are pods in there that have any there are pods in there that have any other label or No other label or No other label or No Label it cannot connect to it we have Label it cannot connect to it we have Label it cannot connect to it we have the select let's see if I get that right the select let's see if I get that right the select let's see if I get that right on top as before ID front end will be on top as before ID front end will be on top as before ID front end will be applied this netback policy will be applied this netback policy will be applied this netback policy will be applied to these parts this netback applied to these parts this netback applied to these parts this netback policy is about outgoing policy is about outgoing policy is about outgoing traffic then we have the first outgoing traffic then we have the first outgoing traffic then we have the first outgoing traffic rule first ous rule and this traffic rule first ous rule and this traffic rule first ous rule and this rule can be read as allow outgoing rule can be read as allow outgoing rule can be read as allow outgoing traffic to name space with label ID ns1 traffic to name space with label ID ns1 traffic to name space with label ID ns1 and Port ad okay this array entry here and Port ad okay this array entry here and Port ad okay this array entry here we see one here we see one here this we see one here we see one here this we see one here we see one here this means is one rule so this is the second means is one rule so this is the second means is one rule so this is the second rule down here the second eress rule rule down here the second eress rule rule down here the second eress rule this in blue is the first eress rule so this in blue is the first eress rule so this in blue is the first eress rule so the first eress rule has two entries the the first eress rule has two entries the the first eress rule has two entries the first entry is the two colon and the first entry is the two colon and the first entry is the two colon and the second entry is the ports coer and these second entry is the ports coer and these second entry is the ports coer and these two will be connected end okay so we two will be connected end okay so we two will be connected end okay so we have an agress rule we allow agress have an agress rule we allow agress have an agress rule we allow agress traffic if traffic if traffic if the name space towards the traffic goes the name space towards the traffic goes the name space towards the traffic goes has the label ID has the label ID has the label ID ns1 and the port is 80 on ns1 and the port is 80 on ns1 and the port is 80 on TCP now let's have a look at the second TCP now let's have a look at the second TCP now let's have a look at the second rule in purple down here we allow rule in purple down here we allow rule in purple down here we allow aggress two pots with label ID backend aggress two pots with label ID backend aggress two pots with label ID backend in the same name space why in the same in the same name space why in the same in the same name space why in the same Nam space because we didn't specify a Nam space because we didn't specify a Nam space because we didn't specify a namespace selector here then the same namespace selector here then the same namespace selector here then the same namespace will be will be taken um namespace will be will be taken um namespace will be will be taken um within aha I was
-
within aha I was within aha I was wrong I was wrong I thought these wrong I was wrong I thought these wrong I was wrong I thought these would I didn't see when I was doing this would I didn't see when I was doing this would I didn't see when I was doing this explanation I didn't see that it was explanation I didn't see that it was explanation I didn't see that it was actually two actually two actually two rules but now I realized that this rule defines you can go that this rule defines you can go outside of the the namespace to here or outside of the the namespace to here or outside of the the namespace to here or to these pods in the same to these pods in the same to these pods in the same namespace yeah the N policy is apply to namespace yeah the N policy is apply to namespace yeah the N policy is apply to okay yeah we we have two agas rules here okay yeah we we have two agas rules here okay yeah we we have two agas rules here the blue one and the purple one and the blue one and the purple one and the blue one and the purple one and these two rules will be connected or these two rules will be connected or these two rules will be connected or okay yeah so we allow agress to name okay yeah so we allow agress to name okay yeah so we allow agress to name space with label ID ns1 and Port 80 or space with label ID ns1 and Port 80 or space with label ID ns1 and Port 80 or to Ports with label ID back end in the to Ports with label ID back end in the to Ports with label ID back end in the same name space now let's have a look what happens space now let's have a look what happens if we create that's actually a very if we create that's actually a very if we create that's actually a very useful image I'm going to grab notes in this notes in this image image image um um um they are two separate array the first second
-
array the first second block second block second block second two applies to the same name space two applies to the same name space two applies to the same name space because no name name space selector is because no name name space selector is because no name name space selector is given here now let's have a look what happens here now let's have a look what happens if we create multiple Network policies if we create multiple Network policies if we create multiple Network policies because it's possible to have multiple because it's possible to have multiple because it's possible to have multiple Network policies for the same pots for Network policies for the same pots for Network policies for the same pots for the same pot selector what happens there the same pot selector what happens there the same pot selector what happens there if a pot has more than one network if a pot has more than one network if a pot has more than one network policy well then they will be simply policy well then they will be simply policy well then they will be simply merged the union of all netback policies merged the union of all netback policies merged the union of all netback policies is applied to that partt and the order is applied to that partt and the order is applied to that partt and the order doesn't matter we have a look at it doesn't matter we have a look at it doesn't matter we have a look at it that's interesting multiple interesting multiple Network policies the order does not matter policies the order does not matter policies will be merged if you have multiple Network merged if you have multiple Network policies Target pods now what that actually means again pods now what that actually means again we have the same network policy that we we have the same network policy that we we have the same network policy that we took apart uh before already we see uh took apart uh before already we see uh took apart uh before already we see uh we have our two rules our two ESS rules we have our two rules our two ESS rules we have our two rules our two ESS rules down here now this netback policy example 2 a
-
here now this netback policy example 2 a only contains the first igas rule like only contains the first igas rule like only contains the first igas rule like here okay and now we create another here okay and now we create another here okay and now we create another netback policy example 2 B which down netback policy example 2 B which down netback policy example 2 B which down here only contains the igas rule uh the here only contains the igas rule uh the here only contains the igas rule uh the second igas rule from down here second igas rule from down here second igas rule from down here okay and what you have to understand is okay and what you have to understand is okay and what you have to understand is that this rule that this netback policy that this rule that this netback policy that this rule that this netback policy example is the same as example is the same as example is the same as example example 2 A Plus example 2 B example example 2 A Plus example 2 B example example 2 A Plus example 2 B merged because if we would create only merged because if we would create only merged because if we would create only this one and this one only the two on this one and this one only the two on this one and this one only the two on the right then they have the same pot the right then they have the same pot the right then they have the same pot selector for the same pots which means selector for the same pots which means selector for the same pots which means the Aras rules which are array entries the Aras rules which are array entries the Aras rules which are array entries will simply be merged so appended and it will simply be merged so appended and it will simply be merged so appended and it would um result in in this exactly same would um result in in this exactly same would um result in in this exactly same network policy here on the left we will now actually create our left we will now actually create our first Network policy it will be a first Network policy it will be a first Network policy it will be a default deny policy and that's good default deny policy and that's good default deny policy and that's good common practice to create default deny common practice to create default deny common practice to create default deny policies and then more policies to allow policies and then more policies to allow policies and then more policies to allow certain traffic and it's also important certain traffic and it's also important certain traffic and it's also important to know default deny policies for the to know default deny policies for the to know default deny policies for the ckss certification we'll create a very ckss certification we'll create a very ckss certification we'll create a very simple scenario with one frontend port simple scenario with one frontend port simple scenario with one frontend port one backend part and we check the one backend part and we check the one backend part and we check the connectivity between each before our connectivity between each before our connectivity between each before our Network policy after our Network policy Network policy after our Network policy Network policy after our Network policy and then afterwards we will extend our and then afterwards we will extend our and then afterwards we will extend our example further in more Hands-On example further in more Hands-On example further in more Hands-On sessions you should have access to your sessions you should have access to your sessions you should have access to your master node your classer should be
-
master node your classer should be master node your classer should be running you can see my master node my running you can see my master node my running you can see my master node my worker nodes are running we will now worker nodes are running we will now worker nodes are running we will now create a very simple scenario we just create a very simple scenario we just create a very simple scenario we just run four comments okay we simply create run four comments okay we simply create run four comments okay we simply create a front end po k run front a front end po k run front a front end po k run front end image our beloved engine X and the end image our beloved engine X and the end image our beloved engine X and the same for backend krun backend image let's see I'm going image let's see I'm going [Music] I have rencher desktop running now I'm I have rencher desktop running now I'm in my rer desktop in my rer desktop in my rer desktop context okay enginex and then the other one will be enginex and then the other one will be back end I suppose engine X now we expose balls we suppose engine X now we expose balls we create cluster internal services so that create cluster internal services so that create cluster internal services so that it will be simple for us to check
-
it will be simple for us to check it will be simple for us to check connectivity so we run KX Poe pot Front connectivity so we run KX Poe pot Front connectivity so we run KX Poe pot Front End we want to expose the port front end End we want to expose the port front end End we want to expose the port front end on Port 80 and we do the very same for on Port 80 and we do the very same for on Port 80 and we do the very same for the port back the port back the port back end and if we have a look at Parts and end and if we have a look at Parts and end and if we have a look at Parts and Services we all we do everything in the Services we all we do everything in the Services we all we do everything in the default space we see we have our backend default space we see we have our backend default space we see we have our backend po front end po we have a back end po front end po we have a back end po front end po we have a back end service front end service very simple service front end service very simple service front end service very simple now we check the connectivity from front now we check the connectivity from front now we check the connectivity from front end to back end so we simply exec into end to back end so we simply exec into end to back end so we simply exec into the front end p and run curl back end the front end p and run curl back end the front end p and run curl back end okay this works because backend is the okay this works because backend is the okay this works because backend is the backend service which points to the backend service which points to the backend service which points to the backend Po and we have kubernetes DNS backend Po and we have kubernetes DNS backend Po and we have kubernetes DNS resolution and we see connectivity from resolution and we see connectivity from resolution and we see connectivity from front front front end to back end Works let's try the end to back end Works let's try the end to back end Works let's try the other way other way other way around K ex into backend part and curl around K ex into backend part and curl around K ex into backend part and curl the front the front the front end and it works as well great now we end and it works as well great now we end and it works as well great now we will create our Network policy okay so will create our Network policy okay so will create our Network policy okay so create a new file in your favorite create a new file in your favorite create a new file in your favorite editor called default deny editor called default deny editor called default deny yo I actually have no idea if Rancher yo I actually have no idea if Rancher yo I actually have no idea if Rancher desktop has Network policies enabled so desktop has Network policies enabled so desktop has Network policies enabled so that's going to be interesting to to that's going to be interesting to to that's going to be interesting to to figure out as figure out as figure out as well because on a cluster without a well because on a cluster without a well because on a cluster without a network policy engine such as um or network policy engine such as um or network policy engine such as um or engine or what's it engine or what's it engine or what's it called Calico or celium is it an engine called Calico or celium is it an engine called Calico or celium is it an engine I don't know but you need to have that
-
I don't know but you need to have that I don't know but you need to have that on your cluster if not policies won't on your cluster if not policies won't on your cluster if not policies won't work you can create them it will accept work you can create them it will accept work you can create them it will accept them just fine but you need to have them just fine but you need to have them just fine but you need to have Calico installed for them to be functional but let's uh continue default functional but let's uh continue default deny. yo all right and we head to the deny. yo all right and we head to the deny. yo all right and we head to the documentation and steal documentation and steal documentation and steal examples simply search for Network policy and we can simply look for the policy and we can simply look for the first example there's another section first example there's another section first example there's another section for default deny actually also here but for default deny actually also here but for default deny actually also here but we will simply work with an example and we will simply work with an example and we will simply work with an example and create it into a default deny policy create it into a default deny policy create it into a default deny policy so simply copy the copy the example code so simply copy the copy the example code so simply copy the copy the example code we will have a PO selector we will have we will have a PO selector we will have we will have a PO selector we will have the policy types we don't need the whole example oh I can just use the other one example oh I can just use the other one I had okay okay [Music] selector copy the example code we will selector copy the example code we will have a PO selector we will have the have a PO selector we will have the have a PO selector we will have the policy types we don't need the whole example we copy it okay we will actually example we copy it okay we will actually first thing we will rename the network first thing we will rename the network first thing we will rename the network policy to default deny and the pot policy to default deny and the pot policy to default deny and the pot selector we now say look it should be
-
selector we now say look it should be selector we now say look it should be for all pots so we simply can leave it for all pots so we simply can leave it for all pots so we simply can leave it empty like this and here we have a empty like this and here we have a empty like this and here we have a default deny Network policy for Ingress default deny Network policy for Ingress default deny Network policy for Ingress and agress and agress and agress traffic save it and create it save it for like this and here we it save it for like this and here we have a default deny Network policy for have a default deny Network policy for have a default deny Network policy for Ingress and agress Ingress for good measure I'll put Ingress for good measure I'll put Ingress on top like he Ingress on top like he Ingress on top like he has pod selector empty Target all has pod selector empty Target all has pod selector empty Target all pods policy type Ingress egress so this pods policy type Ingress egress so this pods policy type Ingress egress so this means that no means that no means that no pods can have any sort of ingoing or pods can have any sort of ingoing or pods can have any sort of ingoing or outgoing outgoing outgoing connectivity that's what it should connectivity that's what it should connectivity that's what it should do pods cannot have Ingress or ESS do pods cannot have Ingress or ESS do pods cannot have Ingress or ESS traffic so you can't curl them from one traffic so you can't curl them from one traffic so you can't curl them from one another that's what he's probably going another that's what he's probably going another that's what he's probably going to get to get to get at save it and create it okay great now we can run the first it okay great now we can run the first XA commment again from front end to back XA commment again from front end to back XA commment again from front end to back end and we see doesn't look that good
-
end and we see doesn't look that good end and we see doesn't look that good anymore and we run the other EXA command anymore and we run the other EXA command anymore and we run the other EXA command from back end to front end okay end okay [Music] [Music] [Music] so kind Network so kind Network so kind Network policy running into an API error so policy running into an API error so policy running into an API error so something went something went something went [Music] wrong but is the latest API wrong but is the latest API version version version here we go apply that we go apply that then so I don't know if Rancher has uh a then so I don't know if Rancher has uh a then so I don't know if Rancher has uh a network network network policy if it has Calico installed or not policy if it has Calico installed or not policy if it has Calico installed or not but we're going to find out so now I but we're going to find out so now I but we're going to find out so now I should not be able to do should not be able to do should not be able to do the the the the the the curl yeah okay so it brancher desktop curl yeah okay so it brancher desktop curl yeah okay so it brancher desktop does have a way of enabling Network does have a way of enabling Network does have a way of enabling Network policies because I'm not able to curl policies because I'm not able to curl policies because I'm not able to curl anymore move this to one anymore move this to one anymore move this to one so just again to show okay delete hold Misha I have two pods front end and back
-
Misha I have two pods front end and back end end end and if I and if I and if I [Music] [Music] [Music] do a curl from front end to is it really curl back to is it really curl back end and we see yeah it's just that curl end and we see yeah it's just that curl end and we see yeah it's just that curl back end so if I delete K delete Network back end so if I delete K delete Network back end so if I delete K delete Network policies default policies default policies default deny and if I do the curl again now it deny and if I do the curl again now it deny and if I do the curl again now it does work so I curl from the front end pod to work so I curl from the front end pod to back end it back end it back end it works if I now apply my default deny. works if I now apply my default deny. works if I now apply my default deny. yaml and do the same yaml and do the same yaml and do the same curl it won't work could not resolve curl it won't work could not resolve curl it won't work could not resolve host back end okay so we know that host back end okay so we know that host back end okay so we know that Rancher desktop is enables Network Rancher desktop is enables Network Rancher desktop is enables Network policies and I fully understand my policies and I fully understand my policies and I fully understand my default deny policy here like I I I re I understand this I here like I I I re I understand this I select all the select all the select all the pods and these I know because because pods and these I know because because pods and these I know because because I'm saying Ingress egress but I'm not I'm saying Ingress egress but I'm not I'm saying Ingress egress but I'm not having any two rules down here it means having any two rules down here it means having any two rules down here it means that you own the deny you won't allow
-
that you own the deny you won't allow that you own the deny you won't allow any traffic it doesn't work anymore okay any traffic it doesn't work anymore okay any traffic it doesn't work anymore okay netback policies work our default deny netback policies work our default deny netback policies work our default deny policy works great and we set up this policy works great and we set up this policy works great and we set up this example and in the next Hands-On example and in the next Hands-On example and in the next Hands-On sessions we will then specifically allow sessions we will then specifically allow sessions we will then specifically allow certain traffic we will continue with our traffic we will continue with our example and we will now allow front end example and we will now allow front end example and we will now allow front end pods to connect to backend pods this pods to connect to backend pods this pods to connect to backend pods this means we will create one network policy means we will create one network policy means we will create one network policy to allow outgoing traffic from front end to allow outgoing traffic from front end to allow outgoing traffic from front end and one netback policy to to allow and one netback policy to to allow and one netback policy to to allow incoming traffic from front end to incoming traffic from front end to incoming traffic from front end to backend and we do it based on P backend and we do it based on P backend and we do it based on P selectors if you like feel free to go selectors if you like feel free to go selectors if you like feel free to go ahead pause the video Try It Yourself ahead pause the video Try It Yourself ahead pause the video Try It Yourself otherwise follow me along and see how I otherwise follow me along and see how I otherwise follow me along and see how I will try to implement it okay on my will try to implement it okay on my will try to implement it okay on my master note we still have the default master note we still have the default master note we still have the default deny Network policy it's still applied deny Network policy it's still applied deny Network policy it's still applied in the cluster we will now create a in the cluster we will now create a in the cluster we will now create a second policy called front end. yo prob second policy called front end. yo prob second policy called front end. yo prob the file called front and. yo and I'll the file called front and. yo and I'll the file called front and. yo and I'll head to the kubernetes documentation and head to the kubernetes documentation and head to the kubernetes documentation and I will steal that whole example that we I will steal that whole example that we I will steal that whole example that we see here and I'll adjust it to our needs see here and I'll adjust it to our needs see here and I'll adjust it to our needs okay here we are let's start from the okay here we are let's start from the okay here we are let's start from the very top I will change the name to front very top I will change the name to front very top I will change the name to front end the pot selector um so the network end the pot selector um so the network end the pot selector um so the network policy will be applied to pots with policy will be applied to pots with policy will be applied to pots with label run front end because we created label run front end because we created label run front end because we created the pods with Cube C run they the pods with Cube C run they the pods with Cube C run they automatically get the labels run that
-
automatically get the labels run that automatically get the labels run that policy let's have a look that policy policy let's have a look that policy policy let's have a look that policy will be from front end to back end so will be from front end to back end so will be from front end to back end so from front end we will allow egress from front end we will allow egress from front end we will allow egress outgoing traffic to outgoing traffic to outgoing traffic to backend which means I will delete the backend which means I will delete the backend which means I will delete the egress here and um we need the PO egress here and um we need the PO egress here and um we need the PO selector so what I will actually do I selector so what I will actually do I selector so what I will actually do I will delete the erress section will delete the erress section will delete the erress section here I will change this to egress we here I will change this to egress we here I will change this to egress we will allow so we allow egress we will will allow so we allow egress we will will allow so we allow egress we will now create our first egress rule now create our first egress rule now create our first egress rule two and then we have already the pot two and then we have already the pot two and then we have already the pot selector here that we can selector here that we can selector here that we can steal great so we'll allow ESS steal great so we'll allow ESS steal great so we'll allow ESS to to to run back end okay it's called front end so we'll allow end so we'll allow ESS okay that's pretty ESS okay that's pretty ESS okay that's pretty straightforward straightforward straightforward to then to then to then Al Al Al [Music] second second to to to run back end okay it's called front end run back end okay it's called front end run back end okay it's called front end it will be applied to pots with run it will be applied to pots with run it will be applied to pots with run front end and will allow outgoing front end and will allow outgoing front end and will allow outgoing traffic to pots with back end all
-
traffic to pots with back end all traffic to pots with back end all right let's create the front end Network ESS there we ESS there we go we still have our exec commands here go we still have our exec commands here go we still have our exec commands here so what I try now kxc I connect from so what I try now kxc I connect from so what I try now kxc I connect from Front End curl back end okay and we see Front End curl back end okay and we see Front End curl back end okay and we see it doesn't work why doesn't it work well it doesn't work why doesn't it work well it doesn't work why doesn't it work well we can't think right now that it doesn't we can't think right now that it doesn't we can't think right now that it doesn't work because the backend pots still work because the backend pots still work because the backend pots still don't low incoming don't low incoming don't low incoming traffic um from Front End PS because our traffic um from Front End PS because our traffic um from Front End PS because our default deny policy still applies default deny policy still applies default deny policy still applies Y what we can do now is we will create Y what we can do now is we will create Y what we can do now is we will create another policy backend and for this we another policy backend and for this we another policy backend and for this we can simply copy front end to back end can simply copy front end to back end can simply copy front end to back end because they will be very because they will be very because they will be very similar and in the backend policy I will similar and in the backend policy I will similar and in the backend policy I will change the name I'll change it to change the name I'll change it to change the name I'll change it to backend and this policy will now be backend and this policy will now be backend and this policy will now be applied to backend pods for the backend applied to backend pods for the backend applied to backend pods for the backend pods we allow incoming traffic so pods we allow incoming traffic so pods we allow incoming traffic so Ingress and we will create one Ingress Ingress and we will create one Ingress Ingress and we will create one Ingress rule from coming from CS with the label rule from coming from CS with the label rule from coming from CS with the label front front front end end end okay let's have a look if we can create okay let's have a look if we can create okay let's have a look if we can create this one without this one without this one without any let front so we Define an Ingress rule where we
-
so we Define an Ingress rule where we say from front from front end like I I understand this we are we end like I I understand this we are we end like I I understand this we are we are saying all of the backend are saying all of the backend are saying all of the backend pods will'll get an ingress pods will'll get an ingress pods will'll get an ingress rule which states that traffic from rule which states that traffic from rule which states that traffic from frontend pods are frontend pods are frontend pods are allowed okay let's have a look if we can create okay let's have a look if we can create this one without any issues yes let's this one without any issues yes let's this one without any issues yes let's have a look if we have a look if we have a look if we can now connect from front end to back can now connect from front end to back can now connect from front end to back end and we see it still doesn't work end and we see it still doesn't work end and we see it still doesn't work okay the thing now is that if we want okay the thing now is that if we want okay the thing now is that if we want our front end port to connect to the our front end port to connect to the our front end port to connect to the backend service then we need DNS backend service then we need DNS backend service then we need DNS resolution cluster internal DNS resolution cluster internal DNS resolution cluster internal DNS resolution but our default deny policy resolution but our default deny policy resolution but our default deny policy right now even denies DNS traffic on right now even denies DNS traffic on right now even denies DNS traffic on Port 53 yeah so what we can do now is actually we have a look at all actually we have a look at all pots and their IP addresses and we pots and their IP addresses and we pots and their IP addresses and we connect via IP address okay here we can connect via IP address okay here we can connect via IP address okay here we can see we have our backend pot it has the see we have our backend pot it has the see we have our backend pot it has the label run backend front end po has the label run backend front end po has the label run backend front end po has the label run front end okay now now what we label run front end okay now now what we label run front end okay now now what we do is we exec into frontend part and we
-
do is we exec into frontend part and we do is we exec into frontend part and we do a curl not on the name but towards do a curl not on the name but towards do a curl not on the name but towards the IP address of the backend the IP address of the backend the IP address of the backend part and receip part and receip part and receip works just a short update if you works just a short update if you works just a short update if you actually would like to allow DNS actually would like to allow DNS actually would like to allow DNS resolution for example between front end resolution for example between front end resolution for example between front end and back end pods you could extend your and back end pods you could extend your and back end pods you could extend your default Deni policy where you would default Deni policy where you would default Deni policy where you would allow some agress to the ports 53 TCP allow some agress to the ports 53 TCP allow some agress to the ports 53 TCP ports towards the okay well let's just ports towards the okay well let's just ports towards the okay well let's just try that first kgp so it takes the IP of the back and kgp so it takes the IP of the back and pod which is work work and then to allow DNS we'll have and then to allow DNS we'll have and then to allow DNS we'll have to and we see to and we see to and we see works just a short update if you works just a short update if you works just a short update if you actually would like to allow DNS actually would like to allow DNS actually would like to allow DNS resolution for example between frontend resolution for example between frontend resolution for example between frontend and backend pods you could extend your and backend pods you could extend your and backend pods you could extend your default Deni policy where you would default Deni policy where you would default Deni policy where you would allow some agress to the ports 53 TCP allow some agress to the ports 53 TCP allow some agress to the ports 53 TCP and 53 UDP the link to an example of and 53 UDP the link to an example of and 53 UDP the link to an example of this is also in the resources section of this is also in the resources section of this is also in the resources section of this this this video okay and we also can try the other
-
video okay and we also can try the other video okay and we also can try the other way around we will try to connect to the way around we will try to connect to the way around we will try to connect to the front end part the part the IP let's try that now I've added this to IP let's try that now I've added this to IP let's try that now I've added this to my default it's configured so now I should be able it's configured so now I should be able to curl the back end like this yeah to curl the back end like this yeah to curl the back end like this yeah using the DNS name all using the DNS name all using the DNS name all right that right that right that works and works and works and now can I go from back end to front now can I go from back end to front now can I go from back end to front end no it won't work because I haven't end no it won't work because I haven't end no it won't work because I haven't allowed any ESS allowed any ESS allowed any ESS rules or Ingress rules for that the back rules or Ingress rules for that the back rules or Ingress rules for that the back end part end part end part and it doesn't work right because we and it doesn't work right because we and it doesn't work right because we only allowed one way we only allowed only allowed one way we only allowed only allowed one way we only allowed outgoing traffic from front end and outgoing traffic from front end and outgoing traffic from front end and incoming traffic into back end from incoming traffic into back end from incoming traffic into back end from front end if you didn't manage to get it to end if you didn't manage to get it to run yourself maybe I was a bit too fast run yourself maybe I was a bit too fast run yourself maybe I was a bit too fast at some places you can also head to the at some places you can also head to the at some places you can also head to the course repository it's linked in the course repository it's linked in the course repository it's linked in the video resources okay so I'm in course video resources okay so I'm in course video resources okay so I'm in course content cluster set up Network policies content cluster set up Network policies content cluster set up Network policies and in network policies I'm in the front and in network policies I'm in the front and in network policies I'm in the front and backend example we can have a look and backend example we can have a look and backend example we can have a look there's also the default deny example there's also the default deny example there's also the default deny example that we used before and then the networ that we used before and then the networ that we used before and then the networ policies front and back end um there you
-
policies front and back end um there you policies front and back end um there you have the front end uh you can just copy have the front end uh you can just copy have the front end uh you can just copy it and it'll work and there's also the it and it'll work and there's also the it and it'll work and there's also the back end you can copy and it will work okay we will extend now our example of okay we will extend now our example of final time and we still have our front final time and we still have our front final time and we still have our front end part our back end part the end part our back end part the end part our back end part the communication works and now we will communication works and now we will communication works and now we will actually create another pot Cassandra actually create another pot Cassandra actually create another pot Cassandra and we will allow back end to talk to and we will allow back end to talk to and we will allow back end to talk to Cassandra to our database pods and we Cassandra to our database pods and we Cassandra to our database pods and we will do this by also creating a new will do this by also creating a new will do this by also creating a new namespace so the Cassandra pod will be namespace so the Cassandra pod will be namespace so the Cassandra pod will be running in a new namespace Cassandra and running in a new namespace Cassandra and running in a new namespace Cassandra and we will allow backend pods to have we will allow backend pods to have we will allow backend pods to have agress traffic to the namespace agress traffic to the namespace agress traffic to the namespace [Music] [Music] [Music] candra okay for this let's create um the candra okay for this let's create um the candra okay for this let's create um the new namespace create new namespace create new namespace create namespace Cassandra okay and we can namespace Cassandra okay and we can namespace Cassandra okay and we can simply edit the simply edit the simply edit the namespace and apply some nabels labels namespace and apply some nabels labels namespace and apply some nabels labels to it okay we have to it okay we have to it okay we have metadata labels and we will apply the metadata labels and we will apply the metadata labels and we will apply the label label label namespace Cassandra to it because when namespace Cassandra to it because when namespace Cassandra to it because when we work with network policies and we work with network policies and we work with network policies and namespace selectors it always works with namespace selectors it always works with namespace selectors it always works with labels so our Nam spaces in this case labels so our Nam spaces in this case labels so our Nam spaces in this case have to have labels have to have labels have to have labels okay that's done then let's create a okay that's done then let's create a okay that's done then let's create a Cassandra Po in namespace Cassandra we Cassandra Po in namespace Cassandra we Cassandra Po in namespace Cassandra we run
-
run run Cassandra image engine X just for Cassandra image engine X just for Cassandra image engine X just for testing here okay testing here okay testing here okay great let's have a look at that pot and great let's have a look at that pot and great let's have a look at that pot and the IP address of that pot so we do get po- or white there we pot so we do get po- or white there we go and now we try to EXA from from our go and now we try to EXA from from our go and now we try to EXA from from our back end pot and we will try to exec to back end pot and we will try to exec to back end pot and we will try to exec to that to curl that that to curl that that to curl that IP and we see it's not allowed why IP and we see it's not allowed why IP and we see it's not allowed why because we didn't specifically allow it because we didn't specifically allow it because we didn't specifically allow it yet okay if we have a look in our yet okay if we have a look in our yet okay if we have a look in our backend policy then right now we then backend policy then right now we then backend policy then right now we then right now we actually don't allow any right now we actually don't allow any right now we actually don't allow any aggress traffic we only allow certain aggress traffic we only allow certain aggress traffic we only allow certain Ingress traffic but the default deny Ingress traffic but the default deny Ingress traffic but the default deny policy is still in place and the default policy is still in place and the default policy is still in place and the default deny policies still allows any outgoing deny policies still allows any outgoing deny policies still allows any outgoing traffic from any pot so what we have to traffic from any pot so what we have to traffic from any pot so what we have to do here now is to specifically allow do here now is to specifically allow do here now is to specifically allow outgoing outgoing outgoing traffic to the namespace traffic to the namespace traffic to the namespace Cassandra and we can okay I'm going to Cassandra and we can okay I'm going to Cassandra and we can okay I'm going to try to do try to do try to do that myself is he going to do that here that myself is he going to do that here that myself is he going to do that here do this by saying that this policy yeah do this by saying that this policy yeah do this by saying that this policy yeah so before it does this I'm going to try so before it does this I'm going to try so before it does this I'm going to try myself myself myself so I'm going to say ESS so I'm going to say ESS so I'm going to say ESS here then I'm going here then I'm going here then I'm going to add an egress
-
block saying block saying [Music] [Music] [Music] two and then it was selector I thought we had an example selector I thought we had an example with namespace selector already with namespace selector already with namespace selector already apparently I don't um so don't um so is it this then Nam space is it this then Nam space is it this then Nam space selector selector selector [Music] [Music] [Music] two Nam two Nam two Nam space space space selector match selector match selector match labels NS labels NS labels NS Cassandra because that's what he just showed here we showed here we go that's what he just showed so I'm go that's what he just showed so I'm go that's what he just showed so I'm saying frontend saying frontend saying frontend pods no all backend pods can get incoming traffic from Front pods can get incoming traffic from Front End pods and they may go out
-
End pods and they may go out End pods and they may go out [Music] [Music] [Music] to to to pods in the Cassandra Nam space so if I pods in the Cassandra Nam space so if I pods in the Cassandra Nam space so if I apply this now if I this now if I do the curl do the curl do the curl again now it the Cassandra pod in in the Cassandra the Cassandra pod in in the Cassandra namespace and it works because I've namespace and it works because I've namespace and it works because I've added the eras traffic so I solve that added the eras traffic so I solve that added the eras traffic so I solve that by myself that's that's by myself that's that's by myself that's that's nice we're now all nice we're now all nice we're now all contain outgoing traffic rules and I rules and I copy selector um Cassandra so we allow to selector um Cassandra so we allow to namespaces which have the namespace namespaces which have the namespace namespaces which have the namespace label NS the NS the name that's exactly what I did let's name that's exactly what I did let's name that's exactly what I did let's apply our apply our apply our changes seems to be changes seems to be changes seems to be configured and let's try to run our Cur configured and let's try to run our Cur configured and let's try to run our Cur comment again and there we go it works comment again and there we go it works comment again and there we go it works okay so now we actually allowed the
-
okay so now we actually allowed the okay so now we actually allowed the backend to connect to Cassandra we can backend to connect to Cassandra we can backend to connect to Cassandra we can go now even further and also Implement a go now even further and also Implement a go now even further and also Implement a default deny policy in the namespace default deny policy in the namespace default deny policy in the namespace Cassandra because now that's good Cassandra because now that's good Cassandra because now that's good practice right so what we do is we copy practice right so what we do is we copy practice right so what we do is we copy our default deny to default deny Cassandra or I or not default deny Cassandra or I or not default deny default is the so we call it Cassandra deny and what I change is the deny and what I change is the name I call it here Cassandra name I call it here Cassandra name I call it here Cassandra deny and in the names space space Cassandra okay we create the one and we try to connect from our one and we try to connect from our backend port to Cassandra again and we backend port to Cassandra again and we backend port to Cassandra again and we see it doesn't work we now have to see it doesn't work we now have to see it doesn't work we now have to explicitly okay that's interesting explicitly okay that's interesting explicitly okay that's interesting [Music] [Music] [Music] so candra deny I made a typo there Cassandra I'm almost coming up to my Cassandra I'm almost coming up to my break but I just want to test test if yeah so if I apply this now apply if yeah so if I apply this now apply if yeah so if I apply this now apply F Cassandra default deny now my curl
-
F Cassandra default deny now my curl F Cassandra default deny now my curl should not work should not work should not work anymore nope it doesn't work okay so I anymore nope it doesn't work okay so I anymore nope it doesn't work okay so I did did that did did that did did that correctly but my break is now uh correctly but my break is now uh correctly but my break is now uh done or it is now break time this is my done or it is now break time this is my done or it is now break time this is my second Pomo I definitely have another second Pomo I definitely have another second Pomo I definitely have another Pomo in me so I'm going to take a break Pomo in me so I'm going to take a break Pomo in me so I'm going to take a break and I'm going to continue after and I'm going to continue after and I'm going to continue after that that that so let me see if I move this now I have so let me see if I move this now I have so let me see if I move this now I have my snazzy little script that should if I my snazzy little script that should if I my snazzy little script that should if I work if I do start break here we go on a break we'll return When here we go on a break we'll return When Pomo reaches 40 minutes so I'll um answer some chat questions so I'll um answer some chat questions when I get back from my break and I'll when I get back from my break and I'll when I get back from my break and I'll I'll just uh take 10 minutes see you see I'll just uh take 10 minutes see you see I'll just uh take 10 minutes see you see you it was a little bit longer than uh
-
it was a little bit longer than uh expected but I had some delicious expected but I had some delicious expected but I had some delicious avocado tomato avocado tomato avocado tomato toast needed to have some food to keep toast needed to have some food to keep toast needed to have some food to keep the brain fueled start the new Pomo timer and take fueled start the new Pomo timer and take a couple of questions a couple of questions a couple of questions um what resource are you studying um what resource are you studying um what resource are you studying from uh if you just search on YouTube from uh if you just search on YouTube from uh if you just search on YouTube cks course there there is like an cks course there there is like an cks course there there is like an 11-hour course yeah 11h hour course yeah 11h hour course that was published two months ago course that was published two months ago course that was published two months ago it was actually a paid udemy course but it was actually a paid udemy course but it was actually a paid udemy course but the guy the guy the guy uh decided to publish it for free he's uh decided to publish it for free he's uh decided to publish it for free he's actually the creator of killer actually the creator of killer actually the creator of killer sh and killer Koda so I I think he he is sh and killer Koda so I I think he he is sh and killer Koda so I I think he he is he's just U he's just U he's just U financially independent at this point to financially independent at this point to financially independent at this point to say the say the say the least all of those people taking the cka least all of those people taking the cka least all of those people taking the cka exams or really cool what he has built exams or really cool what he has built exams or really cool what he has built and what he has done really and what he has done really and what he has done really inspiring so I'm going to do it one more inspiring so I'm going to do it one more inspiring so I'm going to do it one more promo 50 minutes of network policies and promo 50 minutes of network policies and promo 50 minutes of network policies and then um it will be 3 hours of studying then um it will be 3 hours of studying then um it will be 3 hours of studying this fine this fine this fine Sunday so without further ado Sunday so without further ado Sunday so without further ado I'm going to
-
continue allow continue allow Ingress coming from backend pods into Ingress coming from backend pods into Ingress coming from backend pods into Cassandra Cassandra Cassandra okay for this what I do now is I simply okay for this what I do now is I simply okay for this what I do now is I simply copy the backend. yaml and I call it copy the backend. yaml and I call it copy the backend. yaml and I call it cassandra. cassandra. cassandra. yo and I edit yo and I edit yo and I edit it it it okay I changed the name to Cassandra okay I changed the name to Cassandra okay I changed the name to Cassandra that Network policy will be running in that Network policy will be running in that Network policy will be running in the namespace Cassandra it will be the namespace Cassandra it will be the namespace Cassandra it will be applied to pots with the label run applied to pots with the label run applied to pots with the label run Cassandra we will only allow incoming Cassandra we will only allow incoming Cassandra we will only allow incoming traffic traffic traffic Ingress and we will allow incoming Ingress and we will allow incoming Ingress and we will allow incoming traffic um let's also do it by a traffic um let's also do it by a traffic um let's also do it by a namespace selector so we allow incoming namespace selector so we allow incoming namespace selector so we allow incoming traffic from namespace namespace default okay so Cassandra namespace default okay so Cassandra Cassandra namespace what Cassandra we Cassandra namespace what Cassandra we Cassandra namespace what Cassandra we allow incoming traffic Ingress from the allow incoming traffic Ingress from the allow incoming traffic Ingress from the Nam space with the label namespace NS Cassandra Cassandra Ingress Ingress Ingress only yeah so all
-
yeah so all pods which have the pods which have the pods which have the label run label run label run Cassandra are allowed to receive traffic Cassandra are allowed to receive traffic Cassandra are allowed to receive traffic traffic from the default name space traffic from the default name space traffic from the default name space that's what we're it let's run our exit command again it let's run our exit command again and yeah it it didn't work yet why well and yeah it it didn't work yet why well and yeah it it didn't work yet why well our default namespace doesn't have the our default namespace doesn't have the our default namespace doesn't have the label yet so I'll edit the default name label yet so I'll edit the default name label yet so I'll edit the default name space and okay so testing a curl no that and okay so testing a curl no that doesn't work work and and and now still doesn't work and I add the now still doesn't work and I add the now still doesn't work and I add the label and as default ah it doesn't work label and as default ah it doesn't work label and as default ah it doesn't work because I didn't apply the policy works because I didn't apply the policy works because I didn't apply the policy works okay so what we did in the whole okay so what we did in the whole okay so what we did in the whole scenario is we allowed one way of scenario is we allowed one way of scenario is we allowed one way of connection from front end to back end connection from front end to back end connection from front end to back end based on labels and then from back end based on labels and then from back end based on labels and then from back end to to to Cassandra okay so I apply it now and if Cassandra okay so I apply it now and if Cassandra okay so I apply it now and if I now do the I now do the I now do the curl curl curl it works
-
yeah based on namespace labels so the yeah based on namespace labels so the first one on pot labels the second one first one on pot labels the second one first one on pot labels the second one on namespace labels I think that's very on namespace labels I think that's very on namespace labels I think that's very a good base right now for Network a good base right now for Network a good base right now for Network policies and but if you like you like to policies and but if you like you like to policies and but if you like you like to extend the scenario a little bit more extend the scenario a little bit more extend the scenario a little bit more you could restrict it a bit more right you could restrict it a bit more right you could restrict it a bit more right now the back end um can connect to now the back end um can connect to now the back end um can connect to Cassandra just based on the label you Cassandra just based on the label you Cassandra just based on the label you could also restrict it on pots right you could also restrict it on pots right you could also restrict it on pots right you could add an additional pot restriction could add an additional pot restriction could add an additional pot restriction that the connections from backend to that the connections from backend to that the connections from backend to candra will only be allowed on Port 0 candra will only be allowed on Port 0 candra will only be allowed on Port 0 where the engine X is running by default where the engine X is running by default where the engine X is running by default in our scenario and also for this example that scenario and also for this example that we just did you can also find the we just did you can also find the we just did you can also find the solution in our gab repos example okay solution in our gab repos example okay solution in our gab repos example okay let's try that then and also extend this let's try that then and also extend this let's try that then and also extend this to to to restrict back and Cassandra based on restrict back and Cassandra based on restrict back and Cassandra based on additional pot label and additional additional pot label and additional additional pot label and additional Port so the Cassandra pods are now currently so the Cassandra pods are now currently allowing all allowing all allowing all traffic from the name space but we also traffic from the name space but we also traffic from the name space but we also just want to just want to just want to say um where was the one that we had with ports where was the one that we had with ports did we have any with did we have any with did we have any with ports just do it like
-
ports ports so it's like this it's not an array we so it's like this it's not an array we so it's like this it's not an array we say ports we are only going to allow Port ports we are only going to allow Port 80 and protocol well did he say anything 80 and protocol well did he say anything 80 and protocol well did he say anything about Protocol no right we'll just try Port right we'll just try Port 80 80 80 [Music] Port no I'm getting this wrong I'm Port no I'm getting this wrong I'm saying I'll only allow Ingress traffic saying I'll only allow Ingress traffic saying I'll only allow Ingress traffic that's coming from Port 80 so is that what he means only be 80 so is that what he means only be allowed on Port also restricted on pots allowed on Port also restricted on pots allowed on Port also restricted on pots right you could add an ADD add Port right you could add an ADD add Port right you could add an ADD add Port restriction that the connections from restriction that the connections from restriction that the connections from back end to Cassandra will only be back end to Cassandra will only be back end to Cassandra will only be allowed on Port 80 where the engine X is allowed on Port 80 where the engine X is allowed on Port 80 where the engine X is running by default in our scenario on the N label you could also scenario on the N label you could also restrict that on pots right you could restrict that on pots right you could restrict that on pots right you could add an additional pot restriction that add an additional pot restriction that add an additional pot restriction that the connections from backand to the connections from backand to the connections from backand to Cassandra connections from beend to so we're going to add a pod selector as
-
so we're going to add a pod selector as well from backend to conundra will only well from backend to conundra will only well from backend to conundra will only be allowed on Port 80 where the will be allowed on Port 80 where the will be allowed on Port 80 where the will only be allowed the engine X is running only be allowed the engine X is running only be allowed the engine X is running by default in our scenario from Port 80 but here I'm saying it's only from 80 but here I'm saying it's only from Port 80 so I'm wondering I'm probably Port 80 so I'm wondering I'm probably Port 80 so I'm wondering I'm probably not getting this right but anyway let's not getting this right but anyway let's not getting this right but anyway let's let's try to add let's try to add let's try to add the Pod end end so we're only allowing pods so we're only allowing pods so we're only allowing pods from from the default name space with from from the default name space with from from the default name space with the backend the backend the backend label label label to Port 80 and also for this example that we 80 and also for this example that we just did you can also find the solution just did you can also find the solution just did you can also find the solution in our gab repository Network policies in our gab repository Network policies in our gab repository Network policies example front and backend database there example front and backend database there example front and backend database there you have all files and you can just use you have all files and you can just use you have all files and you can just use them apply them and play around with them apply them and play around with them apply them and play around with them and the link to it is also um them and the link to it is also um them and the link to it is also um available in the resources section of available in the resources section of available in the resources section of this video okay okay let's try that then I video okay okay let's try that then I don't think I did it correctly but
-
don't think I did it correctly but don't think I did it correctly but hey going to apply cassandra. yo okay so it still yo okay so it still works so what is the solution that works so what is the solution that works so what is the solution that he proposed them for content content what was the path an additional allow example path an additional allow example policies example front and back and de policies example front and back and de policies example front and back and de cluster setup Network database there you have all files and database there you have all files and you can just use them apply them and you can just use them apply them and you can just use them apply them and play around with them and the link to it play around with them and the link to it play around with them and the link to it is also um aail ailable in the resources is also um aail ailable in the resources is also um aail ailable in the resources section of this video section of this video section of this video okay and to close the section Network
-
okay and to close the section Network okay and to close the section Network policies I really recommend reading in policies I really recommend reading in policies I really recommend reading in this case through the documentation so this case through the documentation so this case through the documentation so the link is in the resources but also the link is in the resources but also the link is in the resources but also simply go to the documentation dat simply go to the documentation dat simply go to the documentation dat policies and read through it it should policies and read through it it should policies and read through it it should make things should make more sense let's make things should make more sense let's make things should make more sense let's have have a look at the examples listed have have a look at the examples listed have have a look at the examples listed there as there as there as well and yeah well we talked about well and yeah well we talked about well and yeah well we talked about Network policies I hope you understand Network policies I hope you understand Network policies I hope you understand it now way better than before we talked it now way better than before we talked it now way better than before we talked about aggress and Ingress rules you can about aggress and Ingress rules you can about aggress and Ingress rules you can have them in one network policy or in have them in one network policy or in have them in one network policy or in different ones then they will be merged different ones then they will be merged different ones then they will be merged you can have default deny policies you can have default deny policies you can have default deny policies there's also a section in the kubernetes there's also a section in the kubernetes there's also a section in the kubernetes documentation about it should you need documentation about it should you need documentation about it should you need it in the ckss certification exam we WID it in the ckss certification exam we WID it in the ckss certification exam we WID list allow then based on the default list allow then based on the default list allow then based on the default denies we create other policies which denies we create other policies which denies we create other policies which WID list allow some egress some Ingress WID list allow some egress some Ingress WID list allow some egress some Ingress rules and yeah we did it on various rules and yeah we did it on various rules and yeah we did it on various selectors like pot selectors selectors like pot selectors selectors like pot selectors and names space selectors okay let's solve some selectors okay let's solve some scenarios see if I have actually grasped scenarios see if I have actually grasped scenarios see if I have actually grasped the see nbook see nbook policy Nam space
-
policy Nam space policy Nam space selector there are only apparently that Poli create default apparently that Poli create default deny deny deny start there are existing pods in start there are existing pods in start there are existing pods in namespace app we did a new default deny namespace app we did a new default deny namespace app we did a new default deny Network policy named deny out for all Network policy named deny out for all Network policy named deny out for all outgoing traffic from namespace outgoing traffic from namespace outgoing traffic from namespace App it should still allow DNS traffic on App it should still allow DNS traffic on App it should still allow DNS traffic on Port 53 TCP and UDP UDP okay so there is the namespace there will you need a new default deny there will you need a new default deny Network policy named deny out all Network policy named deny out all Network policy named deny out all outgoing traffic from namespace app app there's no create command for Network policy so then I'll have to trade myself policy so then I'll have to trade myself to quickly find that on the
-
docks that's docks that's okay try it like this Vim deny out yaml so name is going to be yaml so name is going to be deny out in the namespace app for all outgoing traffic from app for all outgoing traffic from namespace app so the Pod selector is then this app so the Pod selector is then this because we are going to select all of because we are going to select all of because we are going to select all of the pods outgoing traffic so it's going to pods outgoing traffic so it's going to be be be Ingress no EG egress no 53 53 and UDP we need a new default deny Network UDP we need a new default deny Network policy named deny out for all outgoing
-
policy named deny out for all outgoing policy named deny out for all outgoing traffic from traffic from traffic from namespace it it let's compare it with the default deny let's compare it with the default deny let's compare it with the default deny that we have here default deny no it's exactly what I what I have here no it's exactly what I what I have here so I think this is so I think this is so I think this is it okay apply F deny out that it okay apply F deny out that it okay apply F deny out that yo is created let's check yo is created let's check yo is created let's check it yes I solved yes I solved it all it all it all right let's go back and check out the right let's go back and check out the right let's go back and check out the solution SEL yeah it's exactly what I will be fun to keep as will be fun to keep as well so I Me Network policies in my
-
well so I Me Network policies in my well so I Me Network policies in my repo um make their course um make their course content move all to course content move all to course content move all to course content make a new directory yo just saving this one for future yo just saving this one for future reference okay so that's the first reference okay so that's the first reference okay so that's the first challenge challenge challenge solved solved solved back to the cks back to the cks back to the cks scenarios and the network scenarios and the network scenarios and the network policies metadata protection let's check policies metadata protection let's check policies metadata protection let's check out that one and this is I plan to do these one and this is I plan to do these exercises every single day until exercises every single day until exercises every single day until I can do it blind and until the exam I can do it blind and until the exam I can do it blind and until the exam basically because Network policies basically because Network policies basically because Network policies are besides rback are my weakest point are besides rback are my weakest point are besides rback are my weakest point and I just want to be able to do it and I just want to be able to do it and I just want to be able to do it blindly without blindly without blindly without thinking every day just do a bunch of thinking every day just do a bunch of thinking every day just do a bunch of these exercises because now I'm on the these exercises because now I'm on the these exercises because now I'm on the cks one but the cka and the ckad D all cks one but the cka and the ckad D all cks one but the cka and the ckad D all of them have Network
-
of them have Network of them have Network policy practices as policy practices as policy practices as well well well so so so on to the next challenge create a new network policy to challenge create a new network policy to restrict access to restrict access to restrict access to IP Cloud providers can have metadata IP Cloud providers can have metadata IP Cloud providers can have metadata servers which expose critical servers which expose critical servers which expose critical information for example gcp or AWS you assume that there is a metadata AWS you assume that there is a metadata server server server 111 you can test that with 111 you can test that with 111 you can test that with this okay create a network create a network policy named metadata server is a policy named metadata server is a policy named metadata server is a namespace default which restricts all namespace default which restricts all namespace default which restricts all egress traffic to that IP should only affect pods with label IP should only affect pods with label trust is nope okay so then we're going to copy nope okay so then we're going to copy our example again and just to test how
-
our example again and just to test how our example again and just to test how do I reach it I go to kubernetes IO exam do I reach it I go to kubernetes IO exam do I reach it I go to kubernetes IO exam test I'm going to search for Network policy I'm going to search for Network policy here I am and here is the policy and one other good thing to test policy and one other good thing to test is some I've heard horror stories where is some I've heard horror stories where is some I've heard horror stories where the search was not working on the the search was not working on the the search was not working on the website so it's also good to learn how website so it's also good to learn how website so it's also good to learn how to navigate the website properly so Concepts and then that should be Concepts and then that should be networking nope I was nope I was wrong oh here Network policies here we wrong oh here Network policies here we wrong oh here Network policies here we go and here we go here is our Network go and here we go here is our Network go and here we go here is our Network policy try not to rely on search too policy try not to rely on search too policy try not to rely on search too much yo create a network policy named yo create a network policy named metadata server restricts all egress traffic to that IP
-
restricts all egress traffic to that IP okay so it should allow it should allow all egas except allow it should allow all egas except for that IP so is it this block then so then so is it is it is it then 000000 it should only affect pods with label it should only affect pods with label trust is nope okay so the Pod selector trust is nope okay so the Pod selector trust is nope okay so the Pod selector is is is trust rules no ports are rules no ports are mentioned I which restricts all egress traffic to which restricts all egress traffic to that IP to ESS with this cider except for this IP I
-
ESS with this cider except for this IP I think this is think this is think this is it let's check out the there are existing pods with labels we there are existing pods with labels we can use for can use for can use for testing is let's is let's see this is a hint I okay so my poo is not completely right okay so my poo is not completely right it has to okay okay it's not a valid cider of it's not a valid cider of it's not a valid cider of course this needs to be a so it should restrict all egress traffic
-
so it should restrict all egress traffic to the IP so no trust this pod should not be IP so no trust this pod should not be able to access it and that one should so able to access it and that one should so able to access it and that one should so if I if I if I [Music] 1.1.1 1.1.1 okay that I can okay that I can okay that I can do but if I do it from the no do but if I do it from the no do but if I do it from the no trust it won't it won't work and if I delete Network policies networking met delete Network policies networking met server if I delete the network policy server if I delete the network policy server if I delete the network policy and then do the exec from no trust it and then do the exec from no trust it and then do the exec from no trust it works yep I solved works yep I solved works yep I solved it I solved it I solved it I solved it so if I this should be it okay apply it so if I this should be it okay apply it so if I this should be it okay apply F po.
-
it cool I solved the challenge all right it cool I solved the challenge all right maybe I'm better at this than I thought maybe I'm better at this than I thought maybe I'm better at this than I thought I I thought I didn't understand Network I I thought I didn't understand Network I I thought I didn't understand Network policies that policies that policies that well but I am able to solve these exam well but I am able to solve these exam well but I am able to solve these exam questions questions questions I just need to get quick at I just need to get quick at I just need to get quick at them but I was able to just them but I was able to just them but I was able to just discern like I've never done this from discern like I've never done this from discern like I've never done this from I've never used those IP blocks and then I've never used those IP blocks and then I've never used those IP blocks and then an exception to them but I was able to an exception to them but I was able to an exception to them but I was able to figure it out figure it out figure it out so getting more confident uh p y going to save this confident uh p y going to save this one one one because it's nice to have a bit of a because it's nice to have a bit of a because it's nice to have a bit of a reference v um IP block accept reference v um IP block accept reference v um IP block accept yo oops that's a nice oops that's a nice little example actually I'm going to rename example actually I'm going to rename MK to killer Solutions and I'm committing all of this
-
Solutions and I'm committing all of this to my lab repo is this is Misha to my lab repo is this is Misha to my lab repo is this is Misha Vandenberg laab and then it's in my Vandenberg laab and then it's in my Vandenberg laab and then it's in my kubernetes cks network policies killer kubernetes cks network policies killer kubernetes cks network policies killer Coda if you want Coda if you want Coda if you want to see what I'm committing so doing pretty good so far committing so doing pretty good so far I've solved all of these challenges I've solved all of these challenges I've solved all of these challenges without any real struggle struggle [Music] [Music] [Music] so let's go to the next one solved I literally literally just solve solved I literally literally just solve that that that one well let's do it one more time like one well let's do it one more time like one well let's do it one more time like I literally have it thought I even had it on my clipboard it thought I even had it on my clipboard but check validation successful okay going check validation successful okay going back to the
-
scenarios here now it's marked as done scenarios here now it's marked as done yeah I was getting a little yeah I was getting a little yeah I was getting a little bit autistic on the check mark I needed bit autistic on the check mark I needed bit autistic on the check mark I needed to have the check mark there so I know to have the check mark there so I know to have the check mark there so I know that I can do that I can do that I can do it next network network policy namespace it next network network policy namespace it next network network policy namespace selector allow communication between two selector allow communication between two selector allow communication between two namespaces cool let's try it out there are existing pods in namespace out there are existing pods in namespace space one and space two we need a new space one and space two we need a new space one and space two we need a new network policy named NP that restricts network policy named NP that restricts network policy named NP that restricts all pods in nam space one to have all pods in nam space one to have all pods in nam space one to have outgoing traffic to pods in space outgoing traffic to pods in space outgoing traffic to pods in space two incoming traffic is not two incoming traffic is not two incoming traffic is not affected we also need a new that affected we also need a new that affected we also need a new that restricts all pods two only have restricts all pods two only have restricts all pods two only have incoming traffic okay sure sure the network policies should still allow the network policies should still allow the network policies should still allow outgoing traffic okay let's break it down and traffic okay let's break it down and just do it one by just do it one by just do it one by one start with this one start with this one start with this one incoming traffic not affected so one incoming traffic not affected so one incoming traffic not affected so that's going to be an egress Network that's going to be an egress Network that's going to be an egress Network policy so I'm going to call this one policy so I'm going to call this one policy so I'm going to call this one np.
-
np. np. yo again I'm going to go to the yo again I'm going to go to the yo again I'm going to go to the kubernetes kubernetes kubernetes documentation documentation documentation Concepts Concepts Concepts networking Network networking Network networking Network policies copy this use that as an example incoming traffic not affected so example incoming traffic not affected so delete anything that has to do with delete anything that has to do with delete anything that has to do with Ingress keeping it around for an Ingress keeping it around for an Ingress keeping it around for an example the example the example the ESS that restricts all pods in nam space one to only have outgoing traffic to one to only have outgoing traffic to pods in namespace 2 pods in namespace 2 pods in namespace 2 so the name is so the name is so the name is NP it lives in nam space space one and NP it lives in nam space space one and NP it lives in nam space space one and then the Pod selector is going to be then the Pod selector is going to be then the Pod selector is going to be this because we're going to select all this because we're going to select all this because we're going to select all the pods in namespace one to only have outgoing traffic to one to only have outgoing traffic to pods in space pods in space pods in space two space
-
space two let's check out the K get NS two let's check out the K get NS two let's check out the K get NS space okay edit NS Space space okay edit NS Space space okay edit NS Space [Music] [Music] [Music] 2 does it have any okay only have Alor traffic to pods in okay only have Alor traffic to pods in namespace it and it's saying we also need a new uh it and it's saying we also need a new uh the network policy should still allow the network policy should still allow the network policy should still allow outgoing DNS protocol protocol PCP PCP PCP Port
-
no no this is an a separate rule because if I don't have it as a rule because if I don't have it as a separate rule I think this should be it because rule I think this should be it because if I don't have it as a separate rule if I don't have it as a separate rule if I don't have it as a separate rule I'm saying you can only go to Port 53 in I'm saying you can only go to Port 53 in I'm saying you can only go to Port 53 in this entire this entire this entire namespace so it should be like this then namespace so it should be like this then namespace so it should be like this then let's check out this it in space one select all the it in space one select all the pods then we're saying you may go to Nam pods then we're saying you may go to Nam pods then we're saying you may go to Nam space space space to and you can make may go to and you can make may go to and you can make may go to anything that has Port TCP in Port to call this to call this one we also need a new network policy one we also need a new network policy one we also need a new network policy named named named NP
-
name oh so I should just use the same name oh so I should just use the same one one one then that restricts all pods in names then that restricts all pods in names then that restricts all pods in names space two to only have incoming traffic space two to only have incoming traffic space two to only have incoming traffic from pods in space one outgoing not affected oh they can have the same name affected oh they can have the same name but in different name spaces sure but in different name spaces sure but in different name spaces sure [Music] [Music] [Music] so let's just test if this one will ports okay so now it ports okay so now it works we need a new network policy named NP so we need a new network policy named NP so I'm going to copy this I'm going to copy this I'm going to copy this one to one to one to mp2 yaml has the same name but this one yaml has the same name but this one lives in space lives in space lives in space two only have incoming traffic so this two only have incoming traffic so this two only have incoming traffic so this is going to be an Ingress Ingress policy policy policy Ingress
-
one okay so then it will one okay so then it will be uh K edit NS space be uh K edit NS space be uh K edit NS space one the network policy should still allow the network policy should still allow outgoing DNS traffic so if it says outgoing DNS traffic so if it says outgoing DNS traffic so if it says outgoing traffic not outgoing traffic not outgoing traffic not affected I will still need an egress affected I will still need an egress affected I will still need an egress block right cuz now I'm block right cuz now I'm block right cuz now I'm saying only Ingress traffic is allowed saying only Ingress traffic is allowed saying only Ingress traffic is allowed so I I will need an egress block block ESS
-
oops oops like tip for learning you can check out the tip for learning you can check out the network policy editor yeah I've done that yeah I've done that correctly correctly correctly okay shall we just do run the check and okay shall we just do run the check and okay shall we just do run the check and see if I did it I'll just check it H wow what I just did it H wow what I just did that I solved it that I solved it that I solved it without damn I did not expect myself to just damn I did not expect myself to just solve that without even looking at the solve that without even looking at the solve that without even looking at the documentation or anything documentation or anything documentation or anything I turns out I do understand Network I turns out I do understand Network I turns out I do understand Network policies policies policies apparently I just did that without any apparently I just did that without any apparently I just did that without any looking anything up just talking myself looking anything up just talking myself looking anything up just talking myself through it
-
cool solution part cool solution part one yeah that's exactly what I did ah one yeah that's exactly what I did ah one yeah that's exactly what I did ah well he uses this one I just added a well he uses this one I just added a well he uses this one I just added a name so let's check out the ESS one imp this one imp this one AR to to ah so I did do it differently he has one rule so it's only differently he has one rule so it's only to this to this to this space and you may only go to these ports space and you may only go to these ports space and you may only go to these ports in that namespace and what I did is I'm in that namespace and what I did is I'm in that namespace and what I did is I'm saying you may go to that name space and saying you may go to that name space and saying you may go to that name space and you can go out you can go out you can go out anywhere to Port anywhere to Port anywhere to Port 53 two yeah okay so I took that a little two yeah okay so I took that a little bit too literally bit too literally bit too literally like I at this erass apparently is not like I at this erass apparently is not like I at this erass apparently is not necessary or it's not checking
-
it pretty it pretty cool I'm not going to save the these or cool I'm not going to save the these or cool I'm not going to save the these or well like the only difference I did was well like the only difference I did was well like the only difference I did was this so I I just delete this one and this so I I just delete this one and this so I I just delete this one and this this this one then I basically have the same um V Space 2 um V Space 2 [Music] this space this space two one. pretty one. pretty cool four minutes left on my Pomodoro cool four minutes left on my Pomodoro cool four minutes left on my Pomodoro and I've worked through the network and I've worked through the network and I've worked through the network policies module policies module policies module completely and I solved all of the completely and I solved all of the completely and I solved all of the challenges are there any more Network policies here
-
are there any more Network policies here no not on this one so for the ckss I've no not on this one so for the ckss I've no not on this one so for the ckss I've solved all of the network policies solved all of the network policies solved all of the network policies here what is the next section that is here what is the next section that is here what is the next section that is going to be cluster setup guey elements okay I finished the solving the killer okay I finished the solving the killer Koda control access to guey elements control control access to guey elements control access to guey elements okay well that's access to guey elements okay well that's access to guey elements okay well that's going to be the next round of study it's going to be the next round of study it's going to be the next round of study it's been three hours of study this been three hours of study this been three hours of study this Sunday now I think I will do some Sunday now I think I will do some Sunday now I think I will do some shopping and prepare some food for the week but I and prepare some food for the week but I do have three minutes left on my do have three minutes left on my do have three minutes left on my Pomodoro Timer so let's quickly see if Pomodoro Timer so let's quickly see if Pomodoro Timer so let's quickly see if there are some more there are some more there are some more Network policies for me to ckad is that the same one network policy ckad is that the same one network policy namespace yeah oh no no these are it is a yeah oh no no these are it is a different one okay there are existing different one okay there are existing different one okay there are existing pods in namespace one and two we need a pods in namespace one and two we need a pods in namespace one and two we need a new network policy named MP that new network policy named MP that new network policy named MP that restricts all pods in space one to only
-
restricts all pods in space one to only restricts all pods in space one to only have outgoing traffic to pods in space have outgoing traffic to pods in space have outgoing traffic to pods in space two incoming is not two incoming is not two incoming is not affected okay p. yaml can I do this affected okay p. yaml can I do this affected okay p. yaml can I do this within what is it three minutes that I within what is it three minutes that I within what is it three minutes that I have two two minutes two and a half have two two minutes two and a half have two two minutes two and a half minutes minutes minutes left can I do this the name space should be n the name this the name space should be n the name should be should be should be NP restricts all parts in name space one the PO selector is this because it's one the PO selector is this because it's all all all pods in space one pods in space one pods in space one only have outgoing traffic so no tube so it is an ESS block with a tube so it is an ESS block with a namespace and what are the
-
and what are the [Music] [Music] [Music] labels okay labels okay labels okay so so so have two pods in namespace space two so have two pods in namespace space two so have two pods in namespace space two so I'm going to copy this label label okay should be this then okay should be this then okay should be this then name NP restricts all pods in space name NP restricts all pods in space name NP restricts all pods in space one one one yeah yeah yeah eress to pod selector oh no wait this is selector oh no wait this is wrong erress 2 namespace selector selector label name Space label name Space label name Space 2 yeah this should be it okay what am I doing
-
okay what am I doing wrong name NP all pods in space wrong name NP all pods in space wrong name NP all pods in space one pods oh it is a separate two so here it pods oh it is a separate two so here it is a separate two rule is a separate two rule is a separate two rule then it okay yeah because I was what I was it okay yeah because I was what I was saying was exactly what maybe there's a saying was exactly what maybe there's a saying was exactly what maybe there's a mistake in the other one then but as mistake in the other one then but as mistake in the other one then but as what I was saying in the other what I was saying in the other what I was saying in the other one like I was only allowing to this one like I was only allowing to this one like I was only allowing to this space space space to and these ports but it should be a to and these ports but it should be a to and these ports but it should be a separate rule so that separate rule so that separate rule so that [Music] [Music] [Music] works you can use this template sure well that's easy then then you just sure well that's easy then then you just need to add the namespace
-
selector selector huh solution I fixed it so I'm happy just solution I fixed it so I'm happy just to try out ports I mean this is exactly what I'm ports I mean this is exactly what I'm doing here no doing here no doing here no wait here okay that's here okay that's it yeah now check this one yeah all right well that's the last one yeah all right well that's the last Network policy 3 minutes over time but Network policy 3 minutes over time but Network policy 3 minutes over time but hey at least I uh solved it so okay I hey at least I uh solved it so okay I hey at least I uh solved it so okay I seem to be able to fix these these seem to be able to fix these these seem to be able to fix these these Solutions so that's interesting I Solutions so that's interesting I Solutions so that's interesting I thought I was I would do a lot worse
-
thought I was I would do a lot worse thought I was I would do a lot worse than is that I would have to look up than is that I would have to look up than is that I would have to look up more information but apparently I'm more information but apparently I'm more information but apparently I'm doing doing okay I'm happy with this let's see a couple of questions in this let's see a couple of questions in the chat how to handle pressure in scrum the chat how to handle pressure in scrum the chat how to handle pressure in scrum Sprints as a Java Sprints as a Java Sprints as a Java developer o how to handle developer o how to handle developer o how to handle pressure pressure pressure um well you you have to think about is um well you you have to think about is um well you you have to think about is it unreasonable pressure or is it is it it unreasonable pressure or is it is it it unreasonable pressure or is it is it like is it because of you or or is the like is it because of you or or is the like is it because of you or or is the scrub Master too uh to on your on your scrub Master too uh to on your on your scrub Master too uh to on your on your neck I don't like it when people are on neck I don't like it when people are on neck I don't like it when people are on my neck that actually has my neck that actually has my neck that actually has a adverse effect but I don't I don't a adverse effect but I don't I don't a adverse effect but I don't I don't work as a developer so I'm I'm sorry I work as a developer so I'm I'm sorry I work as a developer so I'm I'm sorry I can't really answer that the only thing you can do is just that the only thing you can do is just be very clear on your feelings and be very clear on your feelings and be very clear on your feelings and communicate Comm unicate them communicate Comm unicate them communicate Comm unicate them well and uh I think that's one way of well and uh I think that's one way of well and uh I think that's one way of handling the pressure to communicate handling the pressure to communicate handling the pressure to communicate that you feel too much pressure and that you feel too much pressure and that you feel too much pressure and maybe talk to your teammates about maybe talk to your teammates about maybe talk to your teammates about it kubernetes are just server clusters it kubernetes are just server clusters it kubernetes are just server clusters right yeah any way yeah it's just right yeah any way yeah it's just right yeah any way yeah it's just virtual machines talking in virtual machines talking in virtual machines talking in intelligently to each other okay was a three-hour Sunday study other okay was a three-hour Sunday study session I'm happy with the progress I
-
session I'm happy with the progress I session I'm happy with the progress I made today the first actual study made today the first actual study made today the first actual study session for my cks exam I have about uh session for my cks exam I have about uh session for my cks exam I have about uh nine hours left in the course but at nine hours left in the course but at nine hours left in the course but at least I'm happy I'm I can get going with least I'm happy I'm I can get going with least I'm happy I'm I can get going with practicing Network policies every day practicing Network policies every day practicing Network policies every day now so thank you so much for tuning in now so thank you so much for tuning in now so thank you so much for tuning in and uh hope to see you in the next and uh hope to see you in the next and uh hope to see you in the next session have a good day guys
Summary
The stream focuses on demonstrating a personal study process using the Zettelkasten method and a second brain system, exemplified by working through a Kubernetes CKS course available on YouTube. The main takeaway is that this stream is intended for focused learning and note-taking, not for constant chat interaction, with the presenter speaking only when it aids understanding.