Exam CKS Topic 2 Question 26 Discussion

Actual exam question for Linux Foundation's CKS exam
Question #: 26
Topic #: 2
You have a Kubernetes cluster running a web application. You want to enforce secure communication between the web server pods and the database pods in a separate namespace. How would you implement this using TLS certificates and Secrets?

Suggested Answer:

Solution (Step by Step):
1. Generate TLS Certificates: Generate a certificate authority (CA) certificate and server/client certificates.
- You can use tools like OpenSSL or Let's Encrypt to generate these certificates-
2. Create Secrets: Create Kubernetes Secrets to store the certificates.
- Secret for CA Certificate: Create a Secret with the CA certificate and private key.
- Secret for Server Certificate: Create a Secret With the server certificate and private key.
- Secret for Client Certificate: Create a Secret with the client certificate and private key (optional, if you want to enforce client authentication).
3. Mount Certificates: Mount the Secrets containing the certificates into the pods.
- Web Server Pods: Mount the CA certificate and server certificate Secret
- Database Pods: Mount the CA certificate and client certificate Secret (optional, if you want to enforce client authentication).
4. Configure TLS: Configure your web server and database applications to use the mounted certificates for TLS communication.
- Web Server: Configure it to use the server certificate and private key for HTTPS communication.
- Database: Configure it to accept TLS connections and use the client certificate (if client authentication is enabled).
Example using OpenSSL for generating certificates and Kubernetes Secrets:
Generating Certificates:
bash
# Generate a CA certificate and key
openssl req -x509 -newkey rsa:2048 -keyout ca.key -out ca.crt \
-days 365 -nodes -subj "/C=US/ST=CA/L=Los Angeles/O=Example Inc./CN=Example CA"
# Generate a server certificate and key
openssl req -newkey rsa:2048 -keyout server.key -out server.csr \
-subj Angeles/O=Example Inc./CN=example.com"
openssl x509 -req -in server.csr -CA cmcrt -CAkey cakey -CAcreateserial \
-out server.cn -days 365 -sha256 -extensions v3_req
# Generate a client certificate and key (optional)
openssl req -newkey rsa:2048 -keyout client.key -out client_csr \
-subj Angeles/O=Example Inc./CN=client.example.com"
openssl x509 -req -in client.csr -CA ca.crt -CAkey cakey -CAcreateseriaI
-out client.crt -days 365 -sha256 -extensions v3_req
Creating Secrets:

Mounting Secrets in Pods: - Web Server Pod: Mount the 'ca-cen' and 'server-cert Secrets. - Database Pod: Mount the 'ca-cert' and 'client-cert Secrets (if client authentication is enabled). Important Notes: - This implementation assumes you have the necessary knowledge about TLS certificates and secrets management in Kubernetes. - You need to configure your web server and database applications to use the certificates and enforce TLS communicatiom - Ensure the security of your certificates and private keys, as they are critical for secure communication.

by Yves at Jan 17, 2026, 05:26 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10