Option D uses the correct structure for permitting egress from selected endpoints to the local host entity. The endpointSelector selects endpoints whose label env equals dev . Because the intended traffic travels from those endpoints toward the host, the policy must contain an egress rule. An egress peer is expressed through toEntities , and host is the reserved entity representing the local host, including host-networked containers on that node.
Option A is invalid because fromEntities is an ingress-oriented field and cannot express an egress destination. Option B uses nodeSelector , which selects nodes rather than workload endpoints and is only valid for node-level rules in a CiliumClusterwideNetworkPolicy ; it is not valid in the displayed namespaced CiliumNetworkPolicy . It also combines ingress with toEntities , reversing the rule direction. Option C has a valid workload selector but again uses toEntities under ingress ; ingress rules describe sources through constructs such as fromEntities .
Applying option D places the selected endpoints into egress default-deny mode and then expressly permits traffic whose destination is the host entity. Other egress traffic must be allowed separately.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit