⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 1 — Fundamentals Module 03 of 24 Free & Open Access

Services & Cluster Networking Basics

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

03 - Services & Cluster Networking Basics

Why this matters

Pods are ephemeral and get new IPs constantly. Services give you a stable way to reach a set of pods. This is the #1 source of "why can't my app talk to X" debugging.

Read this first — Definitions & Explanations

Why Services exist

Pods are mortal — they die, get rescheduled, change IPs. A Service gives a stable virtual IP (ClusterIP) and DNS name that fronts a set of Pods selected by labels.

ClusterIP

Default Service type. Reachable inside the cluster only. Other Pods call my-svc.my-ns.svc.cluster.local.

NodePort

Exposes the Service on a static port on each node’s IP. Useful for labs/demos; less common as a public production entry by itself.

LoadBalancer

Cloud providers allocate an external load balancer that fronts the Service. On bare minikube this may be emulated (e.g. tunnel/metallb patterns depending on setup).

ExternalName

Maps a Service name to an external DNS name (CNAME-style). No proxying of Pods — just DNS aliasing.

Headless Service (clusterIP: None)

No virtual ClusterIP. DNS returns Pod IPs directly. Common with StatefulSets when clients need to address individual Pods.

Endpoints / EndpointSlices

Track which Pod IPs/ports are currently valid backends for a Service. Ready Pods appear here; not-ready Pods usually do not receive traffic.

kube-proxy’s role

Implements Service routing on nodes so packets to a Service IP get forwarded to an endpoint Pod. Modes: iptables (common) or IPVS (better at huge Service scale).

Label selectors

Services find Pods with matching labels (app=web). If labels don’t match, the Service has no endpoints — traffic goes nowhere.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

kubectl create deployment web --image=nginx --replicas=3
kubectl expose deployment web --port=80 --type=ClusterIP
kubectl get svc web
kubectl get endpointslices -l kubernetes.io/service-name=web

# Prove DNS resolution works cluster-internally
kubectl run tmp --rm -it --image=busybox --restart=Never -- \
  sh -c "nslookup web.default.svc.cluster.local; wget -qO- web"

# Watch iptables rules kube-proxy generated for this Service (on any node)
minikube ssh -p prod-sim
  sudo iptables -t nat -L | grep -A5 web
  exit

# NodePort — reach the service from outside the cluster network via node IP
kubectl expose deployment web --port=80 --type=NodePort --name=web-nodeport
kubectl get svc web-nodeport   # note the NodePort e.g. 30xxx
minikube ip -p prod-sim
curl http://$(minikube ip -p prod-sim):<nodeport>

# Break the selector on purpose and watch endpoints go empty
kubectl patch svc web -p '{"spec":{"selector":{"app":"doesnotexist"}}}'
kubectl get endpointslices -l kubernetes.io/service-name=web   # empty now
kubectl patch svc web -p '{"spec":{"selector":{"app":"web"}}}'  # fix it back

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 03 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: A ClusterIP Service provides:
  • A. Public internet access by default
  • B. Stable virtual IP reachable inside the cluster
  • C. Node filesystem mounts
  • D. TLS certificates
✓ Correct Answer: B (Stable virtual IP reachable inside the cluster)
Option B ('Stable virtual IP reachable inside the cluster') is the standard production architectural best practice.
Question 2: Which Service type exposes the Service on each Node's IP at a static port?
  • A. ClusterIP
  • B. NodePort
  • C. ExternalName
  • D. Headless only
✓ Correct Answer: B (NodePort)
Option B ('NodePort') is the standard production architectural best practice.
Question 3: kube-proxy's role in Services is to:
  • A. Store Service objects in etcd
  • B. Program packet forwarding to endpoints
  • C. Schedule Pods
  • D. Issue API tokens
✓ Correct Answer: B (Program packet forwarding to endpoints)
Option B ('Program packet forwarding to endpoints') is the standard production architectural best practice.
Question 4: A Headless Service (clusterIP: None) is often used for:
  • A. DNS-based discovery of Pod IPs
  • B. Replacing Ingress
  • C. Node upgrades
  • D. etcd encryption
✓ Correct Answer: A (DNS-based discovery of Pod IPs)
Option A ('DNS-based discovery of Pod IPs') is the standard production architectural best practice.
Question 5: Endpoints / EndpointSlices track:
  • A. Nodes only
  • B. Ready backend Pods for a Service
  • C. ConfigMap keys
  • D. PVC claims
✓ Correct Answer: B (Ready backend Pods for a Service)
Option B ('Ready backend Pods for a Service') is the standard production architectural best practice.
← Previous Module (02) Pods & Workload Controllers Next Module (04) → ConfigMaps & Secrets