Services & DNS (CKAD)
Pods die and change IP. A Service gives them one name that never moves.
An interactive Kubernetes lesson: 21 steps, about 30 minutes, on a live simulation in your browser.
Your shop has a frontend, web, and it needs product data from a backend. You start the backend as a single pod called api, listening on port 8080.
Every pod gets its own IP address from the cluster's pod network. So the simplest thing that could work: look up the api pod's IP and have web call it directly. Watch the requests flow. Every one comes back 200.
What you will learn
Pods are moving targets
- Call a pod by its IP: Every pod has its own IP, and any pod can reach any other pod's IP directly. No NAT, no port mapping.
- The pod gets replaced: A pod IP lives exactly as long as that one pod. Replace the pod and the address is gone for good.
- Three replicas, three IPs
One stable name
- A Service: one address for many pods: A Service is a stable virtual IP plus a rule on every node: rewrite traffic for this IP to one healthy pod.
- The selector picks the pods: A Service owns no pods. It owns a label query, re-run continuously; the result is the Endpoints list.
- Kill a pod behind the Service
- port and targetPort: port is the Service's front door. targetPort is the container's door. Traffic walks in one and out the other.
Finding it by name
- DNS gives it a name: Name → ClusterIP is DNS's job. ClusterIP → pod is kube-proxy's job. Two hops, two things that can break.
- Calling from another namespace: A short Service name only works inside its own namespace. Across namespaces, say which one: <service>.<namespace>.
- Break it: CoreDNS goes down
Who gets traffic
- Running is not the same as Ready: Readiness is the pod raising or lowering its hand. The Service only calls on pods with a hand up.
- Break it: a one-letter typo
Reaching in from outside
- NodePort: a door on every node: NodePort = ClusterIP plus the same port opened on every node. Each type wraps the one before it.
- LoadBalancer: one public address
- Two odd ones: headless and ExternalName: Headless: DNS hands you the pods. ExternalName: DNS hands you another name. Neither one proxies traffic.
- Drill: expose a Deployment
When it breaks
- Break it: endpoints look fine
- Four questions, in order: Walk the path the packet walks: name, Service, endpoints, pod, policy. The first hop that fails is your bug.
- Drill: the first command
Recap & playground
- Cheat sheet
- Playground