HomeCKS practice tasks › NetworkPolicies for Namespace Isolation
CKS · Cluster Hardening

NetworkPolicies for Namespace Isolation

First, create a NetworkPolicy named deny-policy in the prod namespace to block all ingress traffic. The prod namespace is labeled env:prod.

Solve this on a real cluster - free → All CKS tasks
🗓️ Free Task of the Week: one CKS task is unlocked free for everyone every week - no card, real cluster, auto-graded (2 tries/week). Create a free account and check whether this one is live now.

The task

Context

You must implement NetworkPolicies controlling the traffic flow of existing Deployments across namespaces.

Task

First, create a NetworkPolicy named deny-policy in the prod namespace to block all ingress traffic. The prod namespace is labeled env:prod.

Next, create a NetworkPolicy named allow-from-prod in the data namespace to allow ingress traffic only from Pods in the prod namespace. Use the label of the prod namespace to allow traffic. The data namespace is labeled env:data.

> Do not modify or delete any namespaces or Pods. Only create the required NetworkPolicies.

Exam
CKS
Domain
Cluster Hardening
Grading
Programmatic · partial credit

What this tests

Restrict RBAC and service accounts, tighten API server flags, and keep the cluster patched. On the CKS exam, Cluster Hardening tasks are graded purely on what you build in the cluster - not multiple choice - so the only way to get faster is to do them on a real cluster against a clock.

Practice it for real

prepium.sh drops you into your own isolated Kubernetes cluster in the browser - no install, no credit card. You solve the task in a real terminal, hit validate, and a programmatic checker scores exactly what you got right and wrong (with partial credit). The canonical solution unlocks after you attempt it, so you learn the fast, exam-ready way to do it.

Related CKS tasks