Question 1
Q1A network engineer needs to configure a secondary network attachment for high-throughput container workloads on OpenShift Container Platform 4.20. The pods require direct Layer 2 connectivity to an external physical subnet connected to worker node interface eth2. Communication between pods scheduled on the same worker node over this secondary network must be switched internally within the node kernel without requiring frames to traverse an external physical switch, while each pod retains an independent MAC address. Which CNI plugin type and operating mode must be specified in the NetworkAttachmentDefinition?
Show answer & explanation
Correct answer: A
The macvlan CNI plugin in bridge mode creates sub-interfaces on the parent physical device (eth2), each with a unique MAC address. In bridge mode, traffic between endpoints on the same host interface is switched directly within the Linux kernel, preventing packets from looping out to an external physical switch. In contrast, private mode drops inter-endpoint traffic on the same host, vepa requires an external switch supporting IEEE 802.1Qbg Hairpin mode, and passthru dedicates the physical interface entirely to a single container.