▸case-01 We are migrating our Kubernetes services to a zero-trust architecture and need to enforce strict mutual authentication across all pods managed by Istio. Please provide a clear implementation strategy detailing the necessary mesh resources, configuration steps, and validation methods to confirm all unencrypted traffic is successfully blocked. | pass→fail | 19,330 | 26,760 | +38% | 1 | 1 | 0% | 3,300 | 3,075 | -7% | 0 | 0 | — |
▸case-02 Our security team requires automated certificate lifecycle management for our microservices mesh to satisfy PCI-DSS compliance. Could you give us an actionable guide on integrating cert-manager with our service mesh, including resource setup and verification commands to test certificate rotation? | pass→fail | 23,089 | 17,822 | -23% | 1 | 1 | 0% | 4,267 | 3,652 | -14% | 0 | 0 | — |
▸case-03 We are encountering handshake errors when services attempt to communicate securely across our mesh after enabling mutual TLS. Can you outline a systematic debugging plan and verification checklist to help us identify trust anchor misconfigurations, expired certificates, or policy mismatches? | fail→pass | 20,583 | 19,120 | -7% | 1 | 1 | 0% | 3,470 | 3,596 | +4% | 0 | 0 | — |
▸case-04 We are configuring outbound client sidecars in Istio to talk to upstream internal microservices that require mutual TLS. A team member suggested setting the DestinationRule TLS mode to SIMPLE to handle the encryption. Should we follow this advice or use a different TLS mode for service-to-service mutual authentication? | pass→pass | 10,113 | 9,222 | -9% | 1 | 1 | 0% | 1,823 | 2,058 | +13% | 0 | 0 | — |
▸case-05 We deployed Linkerd service mesh in our Kubernetes cluster hoping for zero-trust security. We noticed that sidecar injection is enabled via annotations, but how can we verify that inter-service pod traffic is actually encrypted with mTLS rather than falling back to plaintext? | fail→fail | 16,271 | 17,910 | +10% | 1 | 1 | 0% | 2,834 | 3,098 | +9% | 0 | 0 | — |
▸case-06 We want to issue identity certificates to ephemeral microservices running across multi-cloud clusters using SPIFFE/SPIRE without storing long-lived static keys on disk. Please outline how SPIRE Agent injects SVIDs into running workload containers. | pass→pass | 19,505 | 20,239 | +4% | 1 | 1 | 0% | 3,123 | 3,774 | +21% | 0 | 0 | — |
▸case-07 We are connecting microservices across two distinct Kubernetes clusters in a multi-region mesh setup. Developers suggest issuing independent root Certificate Authorities in each cluster so they can operate autonomously. What is the recommended certificate hierarchy design for cross-cluster trust? | pass→pass | 31,960 | 15,825 | -50% | 1 | 1 | 0% | 2,725 | 3,129 | +15% | 0 | 0 | — |
▸case-08 We have dozens of legacy services in production that currently send unencrypted HTTP traffic. Management wants zero downtime while moving to strict mTLS. Should we apply STRICT PeerAuthentication immediately across the whole mesh namespace? | pass→pass | 12,646 | 11,166 | -12% | 1 | 1 | 0% | 2,174 | 2,430 | +12% | 0 | 0 | — |
▸case-09 Our organization uses custom intermediate certificates issued by an internal PKI for Istio mesh CA. What automated operational practice should be adopted to prevent mesh-wide outages when certificates approach expiration? | pass→pass | 15,715 | 15,004 | -5% | 1 | 1 | 0% | 2,552 | 2,998 | +17% | 0 | 0 | — |
▸case-10 During an mTLS rollout, proxy sidecar logs show 'TLS error: 268435581:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED' when Service A calls Service B. What is the root cause and how do we verify trust anchor alignment? | pass→pass | 15,912 | 15,517 | -2% | 1 | 1 | 0% | 2,891 | 3,165 | +9% | 0 | 0 | — |
▸case-11 We need to ensure Service A can only communicate with Service B, but even with mTLS active, any service with a valid mesh certificate is currently able to call Service B. How do we restrict access at the authorization layer based on identity? | pass→pass | 13,883 | 11,900 | -14% | 1 | 1 | 0% | 2,451 | 2,654 | +8% | 0 | 0 | — |
▸case-12 We are integrating cert-manager-istio-csr to sign Istio workload certificates directly from our Vault backend. Can you explain how cert-manager replaces Istiod's internal CA role? | pass→pass | 15,711 | 15,465 | -2% | 1 | 1 | 0% | 2,689 | 3,048 | +13% | 0 | 0 | — |
▸case-13 Our Kubernetes liveness and readiness HTTP probes are failing on port 8080 because kubelet cannot perform mTLS handshakes with sidecars. Should we disable mTLS for the entire pod workload? | pass→pass | 11,832 | 9,862 | -17% | 1 | 1 | 0% | 2,056 | 2,157 | +5% | 0 | 0 | — |
▸case-14 We are pairing two service meshes in Cluster East and Cluster West. Cluster East uses trust domain 'east.internal' and Cluster West uses 'west.internal'. Cross-cluster mTLS calls are failing SAN validation. What configuration adjustment is required? | pass→pass | 11,803 | 11,610 | -2% | 1 | 1 | 0% | 2,082 | 2,397 | +15% | 0 | 0 | — |
▸case-15 To comply with HIPAA mandates, we must guarantee that no plaintext HTTP traffic is allowed between services under any circumstances, including fallback modes. Which Istio PeerAuthentication mode must be enforced? | pass→pass | 5,563 | 4,286 | -23% | 1 | 1 | 0% | 895 | 1,164 | +30% | 0 | 0 | — |
▸case-16 When cert-manager rotates a workload SVID certificate in Istio, developers are concerned that running Envoy proxy sidecar containers will need to be restarted, causing brief packet drops. How does Envoy handle renewed certificates? | pass→pass | 14,153 | 12,938 | -9% | 1 | 1 | 0% | 1,902 | 2,303 | +21% | 0 | 0 | — |
▸case-17 We are using Linkerd in production and want to enforce mandatory mTLS policy so unmanaged pods outside the mesh cannot reach our payment service pod. What Linkerd resource policy should be applied? | pass→pass | 13,709 | 9,421 | -31% | 1 | 1 | 0% | 2,466 | 2,164 | -12% | 0 | 0 | — |
▸case-18 All microservice traffic failed suddenly across our production mesh at midnight. Proxy logs show 'certificate has expired'. What verification step quickly pinpoints which CA or intermediate certificate in the chain expired? | pass→pass | 15,556 | 13,861 | -11% | 1 | 1 | 0% | 2,680 | 2,688 | +0% | 0 | 0 | — |
▸case-19 A security audit flagged that mTLS private keys might be written to persistent node disk storage in Kubernetes. What design practice ensures private keys remain strictly in ephemeral memory? | pass→pass | 14,670 | 13,784 | -6% | 1 | 1 | 0% | 2,515 | 2,577 | +2% | 0 | 0 | — |
▸case-20 We need to configure an NGINX Ingress Controller to terminate standard HTTPS traffic for our public website using a Let's Encrypt TLS certificate. Please provide the ingress manifest to handle public client HTTPS requests. | pass→pass | 10,110 | 12,336 | +22% | 1 | 1 | 0% | 2,033 | 2,925 | +44% | 0 | 0 | — |
▸case-21 We want to restrict pod-to-pod network traffic in our cluster at Layer 4 using standard Kubernetes NetworkPolicies, ensuring only backend pods on port 5432 accept connections from API pods without inspecting or encrypting application payloads. Please provide the NetworkPolicy YAML. | pass→pass | 6,941 | 5,981 | -14% | 1 | 1 | 0% | 1,301 | 1,721 | +32% | 0 | 0 | — |
▸case-22 Our sysadmin team needs to set up SSH public-key authentication for remote access to our Linux jump hosts, including key generation and authorized_keys deployment. Please outline the procedure for establishing SSH access. | pass→pass | 13,671 | 8,830 | -35% | 1 | 1 | 0% | 2,553 | 2,162 | -15% | 0 | 0 | — |