QuestionQ23

Network Element Programmability

Which two of the following are application-isolation options available when Kubernetes is deployed using the ACI CNI plug-in?

Choose two
  • A VM Isolation
  • B Cluster Isolation
  • C Server Isolation
  • D Process Isolation
  • E Namespace Isolation
Explanation

When Kubernetes is integrated with Cisco ACI through the ACI CNI plug-in, application traffic can be isolated at two levels: cluster isolation, the default mode in which ACI creates one endpoint group and bridge domain shared by the whole Kubernetes cluster, and namespace isolation, in which ACI maps each Kubernetes namespace to its own endpoint group so that ACI contracts enforce policy and segmentation between namespaces.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!