問題文
A team is drawing the trust boundaries of their cluster so that they can reason about which components have to distrust one another. Where does the most important trust boundary lie between an application Pod and the cluster state?
選択肢
- At the API server, because it is the only component that authenticates the Pod's identity and decides which parts of the cluster state that identity may read or change.
- At the kubelet, because the kubelet is the component that actually starts the container, so it mediates every interaction between the workload and its environment.
- At the container runtime, because it is the component closest to the workload, and anything the workload does passes through it first.
- At the network plugin, because all requests travel over the network, so the plugin sees each one before the API server does.