learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Services & DNS (CKAD)

Pods die and change IP. A Service gives them one name that never moves.

An interactive Kubernetes lesson: 21 steps, about 30 minutes, on a live simulation in your browser.

Your shop has a frontend, web, and it needs product data from a backend. You start the backend as a single pod called api, listening on port 8080.

Every pod gets its own IP address from the cluster's pod network. So the simplest thing that could work: look up the api pod's IP and have web call it directly. Watch the requests flow. Every one comes back 200.

What you will learn

  1. Pods are moving targets

    • Call a pod by its IP: Every pod has its own IP, and any pod can reach any other pod's IP directly. No NAT, no port mapping.
    • The pod gets replaced: A pod IP lives exactly as long as that one pod. Replace the pod and the address is gone for good.
    • Three replicas, three IPs
  2. One stable name

    • A Service: one address for many pods: A Service is a stable virtual IP plus a rule on every node: rewrite traffic for this IP to one healthy pod.
    • The selector picks the pods: A Service owns no pods. It owns a label query, re-run continuously; the result is the Endpoints list.
    • Kill a pod behind the Service
    • port and targetPort: port is the Service's front door. targetPort is the container's door. Traffic walks in one and out the other.
  3. Finding it by name

    • DNS gives it a name: Name → ClusterIP is DNS's job. ClusterIP → pod is kube-proxy's job. Two hops, two things that can break.
    • Calling from another namespace: A short Service name only works inside its own namespace. Across namespaces, say which one: <service>.<namespace>.
    • Break it: CoreDNS goes down
  4. Who gets traffic

    • Running is not the same as Ready: Readiness is the pod raising or lowering its hand. The Service only calls on pods with a hand up.
    • Break it: a one-letter typo
  5. Reaching in from outside

    • NodePort: a door on every node: NodePort = ClusterIP plus the same port opened on every node. Each type wraps the one before it.
    • LoadBalancer: one public address
    • Two odd ones: headless and ExternalName: Headless: DNS hands you the pods. ExternalName: DNS hands you another name. Neither one proxies traffic.
    • Drill: expose a Deployment
  6. When it breaks

    • Break it: endpoints look fine
    • Four questions, in order: Walk the path the packet walks: name, Service, endpoints, pod, policy. The first hop that fails is your bug.
    • Drill: the first command
  7. Recap & playground

    • Cheat sheet
    • Playground