問題文
A team applies its very first CiliumNetworkPolicy to a namespace. The policy selects the payments pods and contains only an ingress section. Afterwards the payments pods can still reach an external service, but incoming traffic from an unrelated pod is refused. Which explanation accounts for the two directions behaving differently?
選択肢
- Because outbound traffic to destinations outside the cluster is never subject to policy.
- Because the transition into default-deny is per direction, and the rule only carried an ingress section.
- Because the policy was applied to the wrong namespace.
- Because ingress rules are evaluated before egress rules, and the evaluation stops as soon as one direction has produced a verdict, which leaves the other direction untouched until a second policy is applied to the same endpoint.