certslothcertsloth
KCSA/Topic 08

CNCF / Associate

Observability, PKI and Secure Connectivity

4 min read5 recall promptsReviewed 2026-10-10

Memory hook: Observe the action, authenticate the peer and authorize the connection.

Must remember

Metrics summarize numeric behavior over time, such as API errors, resource saturation or authentication failures. Logs record individual events. Traces connect spans of a request across services. Together they help distinguish a slow dependency, network rejection, application failure and malicious behavior. A graph alone rarely identifies who changed a permission; API audit logs are designed for that question.

Runtime monitoring examines behavior after deployment. Tools such as Falco can detect suspicious execution or file/network activity using configured event sources and rules. Image scanning answers questions about artifact contents; runtime detection answers questions about current behavior. Neither replaces the other. Tune rules, preserve context and connect alerts to an owner and response procedure.

Protect observability infrastructure: restrict access, authenticate agents, encrypt transport and retain evidence in a system the workload cannot freely modify. Redact credentials and sensitive payloads. Avoid unbounded or secret-bearing metric labels; they can expose data and produce excessive cardinality. Accurate clocks and stable workload/identity metadata make evidence easier to correlate.

PKI connects public keys to identities through certificates and trusted certificate authorities. A TLS client validates an appropriate trust chain, identity/SAN and certificate validity period. Protect private keys, restrict certificate issuance and rotate credentials before expiry. A certificate is normally public; its private key must remain private. Encryption without identity verification is vulnerable to impersonation.

With ordinary server-authenticated TLS, the client verifies the server. With mutual TLS, both ends authenticate using certificates. This supplies peer identity and protects transport; it does not inherently grant permission to call every API. Authorization policy still decides which identity may perform which operation. TLS termination at an ingress also does not automatically encrypt the onward connection to a backend.

A service mesh can supply workload identity, mTLS, traffic policy and telemetry across participating workloads. Its control plane distributes configuration/identity material; its data plane enforces applicable traffic behavior. Mesh coverage and configuration matter: workloads outside the managed path may not receive the same guarantees. Application-level user authorization, node hardening and network policy remain separate concerns.

Plan connectivity deliberately. Limit management endpoint reachability; use controlled private access paths where appropriate. North-south traffic crosses the environment edge; east-west traffic flows among services. Restrict ingress and egress separately, protect DNS resolution and allow only required destinations. A private address, ClusterIP Service or NAT path does not automatically provide encryption, identity or authorization. Validate the actual traffic path and effective policies instead of trusting a diagram alone.

Choose under exam pressure

Requirement Choice and reason
Follow one request through several microservices Use distributed traces, supported by relevant logs and metrics.
Identify an unexpected shell in a running application Use runtime behavior detection and investigate correlated workload/audit evidence.
Prove both services' identities in transit Use correctly configured mTLS with trusted workload identities.
Prevent an authenticated service calling an unrelated endpoint Apply authorization and traffic policy; mTLS alone establishes identity.

Traps

  • A mesh installed in the cluster does not imply every path is covered or mTLS is enforced.
  • A certificate expiry alert is an availability control as well as a credential-lifecycle concern.
  • TLS at the load balancer does not establish end-to-end encryption.
  • Logs can become a sensitive data store and require their own permissions.

Active recall

1. Which signal best reconstructs the path of a single distributed request?

A distributed trace, correlated with logs and metrics where needed.

2. Does mTLS automatically authorize every request from an authenticated peer?

No. Identity verification and authorization policy are separate.

3. Which is secret: the public certificate or its private key?

The private key. Public certificates may be distributed to establish identity and trust.

4. An image scan passed yesterday; a suspicious process starts today. Is runtime monitoring redundant?

No. Runtime behavior can reveal exploitation, misuse or malicious actions not established by the earlier scan.

5. The ingress terminates HTTPS and forwards HTTP to the Pod. Is that entire path encrypted?

No. The backend hop needs its own transport protection if encryption on that segment is required.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.