問題文
A team wants to allow their pods to reach destinations outside the cluster without hardcoding addresses of internal workloads. Which construct in a Cilium policy expresses a remote peer category rather than a specific address?
選択肢
- A namespaceSelector with an empty value.
- An entity such as world, which describes peers by category instead of by address.
- A CIDR selector with the value 0.0.0.0/0, which is the recommended way to express this because it makes the intended scope explicit in the manifest and avoids relying on a named category that could change meaning between versions.
- A toPorts section with the protocol set to ANY, which stands in for the whole category of peers that sit outside the cluster.