Learning bite
Identity, networking, storage, and ingress
Translate an application dependency into concrete target-side behavior.
On this page
Three independent reasons a connection can fail
Identity answers “who is calling?” Authorization answers “what may they do?” Networking supplies a path to the destination. Storage preserves bytes with particular lifetime and access behavior. A working Pod needs the relevant parts of all of these; success in one does not prove the others.
Portability depends on the seams
Review four areas independently. Identity determines which API calls a workload may make. Networking determines which endpoints it can reach. Storage determines where data survives. Ingress determines who can reach the application and how requests are authenticated and encrypted.
A Service with type LoadBalancer may allocate chargeable cloud infrastructure. A PVC may create a disk whose lifecycle differs from the Pod. A NetworkPolicy object has no intended effect unless the chosen networking implementation enforces it. Verify each control on the target where it will run.
Apply the seams to MicroBank
Keep databases private. Decide which service accesses each database and queue. Replace local endpoint overrides only after the new dependency exists and authentication is implemented. A UI login is not a substitute for API-side authorization; the inspected baseline must remain a private lab until that gap is resolved and tested.
Define storage behavior before migration: access mode, zone constraints, encryption, snapshots, restore procedure, and retention. A database deployed as a single Pod with a persistent disk is not a highly available database.
Diagnose a dependency in order
Use this paper case: Ledger cannot reach PostgreSQL after moving to a new target. Start with the error and the configured hostname, port and database name. Then choose a branch:
| Observation | Investigate first | Do not conclude yet |
|---|---|---|
| Name does not resolve | DNS name, namespace and resolver path | That the password is wrong |
| Connection times out | Routes, firewall/NetworkPolicy, endpoint reachability | That the database rejected authentication |
| Connection refused | Listener, port, service endpoints | That every network policy is correct |
| Authentication rejected | User, credential delivery and database access rules | That the database is unavailable |
| Connection succeeds but data is missing | Database/schema selection and restore history | That a connection check proves data recovery |
The table prioritizes checks; error details and intermediate proxies can change what you observe. Collect evidence before changing several layers at once.
For storage, trace a PVC to its provisioned volume and retention behavior. Deleting a Pod, deleting a PVC and deleting the underlying cloud disk are different operations. Before an optional cloud run, identify who can restore the database and where that restore was tested. A single database Pod with a persistent disk still has single-instance availability limits.
Try it
Create a dependency matrix with source service, destination, protocol, identity, expected allowed operation, and expected denied operation. For each target, add how the control is implemented. Include DNS and outbound access needed for image pulls and cloud SDK calls.
Then review a rendered overlay for hidden provider assumptions. Look for storage class names, annotations, node selectors, local host paths, and public Service types. For the first cloud exercise, test connectivity through a defined private administration route while keeping the demo application private.
Checkpoint and revision
Explain how to distinguish an identity failure from a network timeout or unavailable database. A target adapter must preserve the application's tested dependency contract while deliberately replacing the surrounding mechanisms.
Compare your reasoning
A NetworkPolicy applies only when the cluster's networking implementation enforces it. A frontend login does not secure an unauthenticated backend by itself. Keep the lab private while those controls remain outside the implemented profile.
Sources
Your notes and evidence
Record observations, questions, or links to your work. Keep credentials out of your notes.
Back up or restore this path
Progress and notes stay in this browser. A backup contains only this learning path.