Skip to content
← Platform engineering

Learning bite

Identity, networking, storage, and ingress

Translate an application dependency into concrete target-side behavior.

Documentation reviewed2026-10-01 · 3 min read
On this page

Three independent reasons a connection can fail

Identity answers “who is calling?” Authorization answers “what may they do?” Networking supplies a path to the destination. Storage preserves bytes with particular lifetime and access behavior. A working Pod needs the relevant parts of all of these; success in one does not prove the others.

Portability depends on the seams

Review four areas independently. Identity determines which API calls a workload may make. Networking determines which endpoints it can reach. Storage determines where data survives. Ingress determines who can reach the application and how requests are authenticated and encrypted.

A Service with type LoadBalancer may allocate chargeable cloud infrastructure. A PVC may create a disk whose lifecycle differs from the Pod. A NetworkPolicy object has no intended effect unless the chosen networking implementation enforces it. Verify each control on the target where it will run.

Apply the seams to MicroBank

Keep databases private. Decide which service accesses each database and queue. Replace local endpoint overrides only after the new dependency exists and authentication is implemented. A UI login is not a substitute for API-side authorization; the inspected baseline must remain a private lab until that gap is resolved and tested.

Define storage behavior before migration: access mode, zone constraints, encryption, snapshots, restore procedure, and retention. A database deployed as a single Pod with a persistent disk is not a highly available database.

Diagnose a dependency in order

Use this paper case: Ledger cannot reach PostgreSQL after moving to a new target. Start with the error and the configured hostname, port and database name. Then choose a branch:

ObservationInvestigate firstDo not conclude yet
Name does not resolveDNS name, namespace and resolver pathThat the password is wrong
Connection times outRoutes, firewall/NetworkPolicy, endpoint reachabilityThat the database rejected authentication
Connection refusedListener, port, service endpointsThat every network policy is correct
Authentication rejectedUser, credential delivery and database access rulesThat the database is unavailable
Connection succeeds but data is missingDatabase/schema selection and restore historyThat a connection check proves data recovery

The table prioritizes checks; error details and intermediate proxies can change what you observe. Collect evidence before changing several layers at once.

For storage, trace a PVC to its provisioned volume and retention behavior. Deleting a Pod, deleting a PVC and deleting the underlying cloud disk are different operations. Before an optional cloud run, identify who can restore the database and where that restore was tested. A single database Pod with a persistent disk still has single-instance availability limits.

Try it

Create a dependency matrix with source service, destination, protocol, identity, expected allowed operation, and expected denied operation. For each target, add how the control is implemented. Include DNS and outbound access needed for image pulls and cloud SDK calls.

Then review a rendered overlay for hidden provider assumptions. Look for storage class names, annotations, node selectors, local host paths, and public Service types. For the first cloud exercise, test connectivity through a defined private administration route while keeping the demo application private.

Checkpoint and revision

Explain how to distinguish an identity failure from a network timeout or unavailable database. A target adapter must preserve the application's tested dependency contract while deliberately replacing the surrounding mechanisms.

Compare your reasoning

A NetworkPolicy applies only when the cluster's networking implementation enforces it. A frontend login does not secure an unauthenticated backend by itself. Keep the lab private while those controls remain outside the implemented profile.

Sources

EKS storage↗, GKE networking↗, Kubernetes NetworkPolicy↗.

Your notes and evidence

Record observations, questions, or links to your work. Keep credentials out of your notes.

Loading saved progress…

Back up or restore this path

Progress and notes stay in this browser. A backup contains only this learning path.