問題文
A compliance requirement says that traffic between pods on different nodes must be encrypted without changing the applications. Which capability addresses that?
選択肢
- A NetworkPolicy with a toPorts section naming port 443, which turns on encryption for every flow that matches that port.
- The layer 7 policy engine, because routing the traffic through the node-local proxy means that the proxy terminates the connection and re-establishes it with encryption toward the destination pod on the remote node.
- The Hubble exporter.
- Transparent encryption, which can use IPsec or WireGuard for traffic between Cilium-managed endpoints.