Question 1
Q1A global retail enterprise is designing a cloud-native e-commerce platform on Oracle Cloud Infrastructure (OCI). The application utilizes microservices deployed on Oracle Container Engine for Kubernetes (OKE). The architecture requires that pods have direct visibility of the client source IP addresses for geo-fencing and audit logging purposes without using X-Forwarded-For headers. The solution must also support mixed-protocol traffic (TCP and UDP) on the same load balancer IP. Which OCI Load Balancer configuration meets these strict networking requirements?
Show answer & explanation
Correct answer: A
The OCI Network Load Balancer (NLB) operates at Layer 4 and is non-proxying by design, which inherently preserves the client source IP address when traffic is forwarded to the backend. It also supports both TCP and UDP protocols. Setting externalTrafficPolicy: Local on the Kubernetes Service ensures that traffic is only routed to nodes running the specific pod, preventing SNAT (Source Network Address Translation) that would obscure the source IP.