Kubernetes Services

Kubernetes Services


Beginner

Q1: What is a Kubernetes Service?

A Kubernetes Service is an abstraction that defines a stable network identity and routing policy for a set of Pods.

Q2: Why do we need Services in Kubernetes?

Pods are ephemeral and often have dynamic IPs. Services provide a stable endpoint for clients to connect to.

Q3: What is a Pod IP?

A Pod IP is the IP address assigned to a pod, which can change when the pod is recreated.

Q4: Why are Pod IPs not stable?

Pods may be rescheduled, restarted, scaled, or replaced, which can change their IP addresses.

Q5: What is service discovery?

Service discovery is the process of finding the network endpoint for a service without hardcoding pod IPs.

Q6: What is a Service selector?

A Service selector matches Pods by labels, selecting which pods receive traffic.

Q7: What is a label in Kubernetes?

A label is a key-value pair used to organize and select objects like Pods.

Q8: What is a selector match?

A selector match identifies Pods whose labels satisfy the Service’s label query.

Q9: What is the default Service type?

The default Service type is ClusterIP.

Q10: What is a ClusterIP Service?

A ClusterIP Service exposes the service internally within the cluster.

Q11: What is a NodePort Service?

A NodePort Service exposes the service on a static port on each node.

Q12: What is a LoadBalancer Service?

A LoadBalancer Service provisions an external load balancer to expose the service outside the cluster.

Q13: What is an ExternalName Service?

An ExternalName Service maps a service name to an external hostname, such as an external DNS name.

Q14: What is an Ingress?

An Ingress is an HTTP or HTTPS entry point that routes traffic to Services based on rules.

Q15: Why use an Ingress instead of NodePort?

Ingress provides HTTP routing, TLS termination, path routing, and a cleaner external entry point.

Q16: What does a Service do at a high level?

A Service provides a stable IP and port, and load balances traffic to matching Pods.

Q17: What is a Service endpoint?

A Service endpoint is the Pod address and port selected by the Service.

Q18: What are endpoints in Kubernetes?

Endpoints are the actual IPs and ports of the Pods behind a Service.

Q19: What is endpoint slicing?

Endpoint slicing is the newer API for tracking sets of Pod endpoints behind a Service efficiently.

Q20: Why are Services needed in a cluster?

Because clients should not need to know all Pod IPs or handle churn.

Q21: What is a stable DNS name for a Service?

A Service gets a DNS name in the cluster namespace, such as my-service.my-namespace.svc.cluster.local.

Q22: What is a Service in a Namespace?

A Service is scoped to a namespace and typically discovered via that namespace’s DNS.

Q23: What is cluster DNS?

Cluster DNS provides name resolution for Services and Pods within the Kubernetes cluster.

Q24: What is a selectorless Service?

A selectorless Service does not match Pods by labels and is often used to point to an external service or manually managed endpoints.

Q25: What is a headless Service?

A headless Service has no ClusterIP and exposes each Pod directly through DNS entries.

Q26: Why use a headless Service?

It is useful for stateful applications and direct Pod access, like a database cluster.

Q27: What is a session affinity?

Session affinity keeps requests from the same client bound to the same backend Pod.

Q28: Why would you use session affinity?

Some applications are stateful and require stickiness to a specific Pod.

Q29: What is a Service port?

A Service port is the port exposed by the Service to clients.

Q30: What is a target port?

A target port is the port on the Pod that receives the traffic.

Q31: Why use a target port value different from a service port?

Because the Service may expose a stable public port while the app listens on another internal port.

Q32: What is a Service manifest?

A Service manifest is a Kubernetes YAML resource that defines the Service’s selector, ports, and type.

Q33: What is a selector label example?

For example: app: api or tier: backend

Q34: What does a Service select by default?

A Service selects Pods by labels based on the selector field.

Q35: How does traffic reach Pods behind a Service?

The kube-proxy or network plugin routes packets to one of the selected Pods.

Q36: What is kube-proxy?

kube-proxy is the Kubernetes component that implements Service routing rules in the cluster.

Q37: What is iptables mode?

iptables mode is a kube-proxy mode that uses iptables rules for routing and load balancing.

Q38: What is IPVS mode?

IPVS mode uses IPVS load balancing for service traffic and can be more performant in some large clusters.

Q39: What is load balancing in a Service?

Load balancing means distributing requests across multiple matching Pods.

Q40: What is round-robin load balancing?

Round-robin is a common load-balancing strategy where traffic is sent to Pods in turn.

Q41: What is service health?

A healthy Service endpoint is a Pod that is ready and able to accept traffic.

Q42: What is a readiness probe?

A readiness probe indicates when a container is ready to receive traffic.

Q43: Why are readiness probes important to Services?

Because Services route only to ready Pods unless explicitly configured otherwise.

Q44: What is a liveness probe?

A liveness probe indicates whether the container is alive and should be restarted if not.

Q45: What is a Pod readiness gate?

It is a more advanced readiness mechanism used by workloads to gate traffic acceptance.

Q46: What is service backlog?

A backlog is the queue of connections or requests waiting to be handled by backend Pods.

Q47: What is a network policy?

A network policy allows or denies traffic to and from pods and services based on labels and ports.

Q48: Why do Services and network policies matter together?

Because Services route traffic while network policies enforce who may talk to whom.

Q49: What is a ClusterIP assignment?

Kubernetes assigns a virtual IP address to the Service for intra-cluster access.

Q50: What is a Service type change?

A Service can be changed from ClusterIP to NodePort or LoadBalancer depending on exposure requirements.

Q51: What is a Kubernetes Deployment?

A Deployment manages ReplicaSets and maintains a desired number of Pods.

Q52: How does a Service relate to a Deployment?

A Service selects Pods created by a Deployment by labels.

Q53: What is a ReplicaSet?

A ReplicaSet ensures a defined number of Pod replicas are running.

Q54: What is a DaemonSet?

A DaemonSet ensures a Pod runs on every or selected nodes, often relevant for node-level networking services.

Q55: What is a StatefulSet?

A StatefulSet manages stateful Pods that often need stable identities and stable network identities.

Q56: Why do StatefulSets often use headless Services?

Because they need direct Pod-level identities and stable DNS names.

Q57: What is a Service name?

A Service name is the DNS name used by clients to connect to it.

Q58: What is DNS A record resolution for Services?

Kubernetes DNS resolves Service names to cluster IP addresses.

Q59: What is a Service port mapping?

A Service port maps external name and port to target port(s) on the Pods.

Q60: What is a Kubernetes namespace?

A namespace isolates Kubernetes objects, including Services, within a logical boundary.

Q61: Why is namespace isolation important?

It separates teams, apps, and environments while reducing accidental cross-communication.

Q62: What is an internal service?

An internal service is only reachable within the cluster.

Q63: What is an external service?

An external service is reachable from outside the cluster, usually via NodePort, LoadBalancer, or Ingress.

Q64: What is service exposure?

Service exposure is the act of making a Service reachable from outside or within the cluster.

Q65: What is port forwarding?

Port forwarding is a debugging technique where local traffic is forwarded into a pod or service.

Q66: What is kubectl port-forward?

It allows local clients to access a Service or pod as if it were local.

Q67: What is a network endpoint?

An endpoint is the destination that a Service forwards traffic to, nominally a Pod IP and port.

Q68: What is a Service mesh?

A Service mesh adds advanced routing, policy, and observability on top of Service networking.

Q69: Why is a Service mesh complementary to Kubernetes Services?

Because Services handle basic routing, while a mesh adds policy, observability, and advanced traffic control.

Q70: What is a Service to Pod mapping?

A Service maps a stable identity to one or more backend Pods.

Q71: Why are labels important for Services?

Because Services target Pods by labels, which makes selection dynamic and resilient.

Q72: What is a label selector mismatch?

It happens when the Service selector does not match any Pods or when labels change unexpectedly.

Q73: What is a Service not selecting Pods?

This often causes connection failures because no backends exist for the Service.

Q74: Why should Services be placed in the same namespace as Pods?

Usually yes, because DNS names and service discovery are namespaced.

Q75: What is DNS name resolution across namespaces?

Pods in different namespaces can resolve a Service with the namespace-qualified DNS name.

Q76: What is a service account and how is it related?

A service account is separate from a Service object, though both are K8s objects.

Q77: What is a service port number?

A port number identifies where a Service listens, such as 80 or 443.

Q78: What is a target port number?

A target port may be different from the service port, often 8080 inside a container.

Q79: What is a named port?

A named port lets you reference a service or container port by a name instead of a number in some APIs.

Q80: What is a Service IP family?

The IP family indicates IPv4 and/or IPv6 support for the Service.

Q81: Why is IPv6 support relevant?

Some clusters support dual-stack networking, and Services may be assigned IPv4, IPv6, or both.

Q82: What is a dual-stack Service?

A dual-stack Service has both IPv4 and IPv6 addresses in a dual-stack cluster.

Q83: What is a NodePort range?

NodePort ports are allocated from a configurable range, usually 30000-32767.

Q84: Why does NodePort expose to all nodes?

A NodePort Service opens the port on each cluster node, allowing access through any node IP.

Q85: What is a LoadBalancer external IP?

A LoadBalancer Service obtains an external IP assigned by a cloud or external load balancer.

Q86: What is a cloud provider integration?

CDNs or cloud load balancers integrate with Kubernetes Services to expose workloads externally.

Q87: Why do cluster internal Services not need external IPs?

Because traffic stays inside the cluster and uses the Service’s ClusterIP.

Q88: What is an internal load balancer?

An internal load balancer exposes a Service only inside the private network or VPC.

Q89: What is a Service health check?

A health check ensures a Service is reachable and backend Pods are ready.

Q90: Why is readiness critical to SLOs?

Because a Service should not send traffic to unhealthy endpoints.

Q91: What is a Service event?

A Service event can indicate changes to endpoints, type, or load balancer configuration.

Q92: What is a Kubernetes endpoint controller?

The endpoint controller maintains the list of backend Pods for Services.

Q93: Why do Services need endpoints?

Because otherwise no backend addresses exist and traffic cannot reach the app.

Q94: What is the difference between a Service and a Deployment?

A Deployment defines what Pods should run. A Service defines how to reach them.

Q95: What is a Pod label selector?

It is a query used to identify Pods based on labels.

Q96: What is a multi-port Service?

A Service can expose multiple ports, such as HTTP on 80 and metrics on 9090.

Q97: What is a named port in a Pod?

A Pod port may be assigned a name so a Service or app can reference it by name.

Q98: What is a service port protocol?

The protocol is often TCP or UDP, and for some services it may be SCTP as well.

Q99: What is a Service protocol mismatch?

It occurs when the Service or Pod is configured for one protocol but the application expects another.

Q100: What is a service routing policy?

A service routing policy governs traffic rules such as load balancing, affinity, and session behavior.

Intermediate

Q101: What is kube-proxy in userspace mode?

It is an older kube-proxy mode where traffic is proxied by user-space processes.

Q102: What is IPVS mode?

IPVS is a kernel-space load balancer used by kube-proxy for high-performance L4 service routing.

Q103: Why use IPVS?

It can scale better and provide more efficient load balancing for large clusters.

Q104: What is a ClusterIP service in practice?

It is virtual IP and port that routes to one or more selected Pods.

Q105: What is a kube-proxy iptables rule?

It is a low-level rule that sends packets from the Service IP to Pod endpoints.

Q106: Why is Service routing more complex than simple DNS?

Because the Service needs to balance traffic among multiple Pods and track readiness.

Q107: What is an endpoint slice?

EndpointSlice is the API object that stores addresses and metadata for Service backends.

Q108: Why was EndpointSlice introduced?

To scale better for large numbers of endpoints and Services.

Q109: What is endpoint controller behavior?

It watches Pods and updates the appropriate Service endpoints as Pods appear, disappear, or become ready.

Q110: What is a Pod ready condition?

The Pod ready condition indicates whether Pod containers are ready for service traffic.

Q111: Why is readiness important for zero-downtime deployments?

Because traffic should not go to Pods still starting up or failing readiness checks.

Q112: What is a startup probe?

A startup probe detects whether an app has finished starting up and can delay liveness checks during initialization.

Q113: Why use a startup probe with Services?

It helps avoid premature restarts when the app starts slowly.

Q114: What is an externalTrafficPolicy?

ExternalTrafficPolicy controls whether traffic from outside the cluster is routed through the node or directly to Pods.

Q115: What is local traffic policy?

Local traffic policy sends external traffic only to local Pods on the same node when possible.

Q116: What is Cluster external traffic policy?

Cluster external traffic policy may route traffic to Pods on other nodes.

Q117: What is a LoadBalancer health check?

A cloud or external LB often performs health checks against the Service’s backend to decide routing.

Q118: What is a NodePort health check?

A NodePort may need health checks at the node or LB layer to know when the endpoints are healthy.

Q119: Why do external load balancers need readiness?

Because they should not route to unhealthy Pods or nodes.

Q120: What is an ingress controller?

An ingress controller watches Ingress resources and configures an HTTP routing layer.

Q121: How does an Ingress relate to Services?

Ingress routes HTTP traffic to one or more Services, which then route to Pods.

Q122: What is a Service multi-port scenario?

A Service may expose multiple ports, each mapping to a different target port or protocol.

Q123: What is a host-based Ingress rule?

Host-based routing sends traffic for different domains to different Services.

Q124: What is a path-based Ingress rule?

Path-based routing sends /api to one Service and /web to another.

Q125: What is a TLS Ingress?

An Ingress can terminate TLS and route incoming HTTPS traffic to a backend Service.

Q126: What is a Service in a multi-tenant cluster?

It may be namespaced and connected to a particular team or app.

Q127: What is stable service identity?

A stable Service identity means clients can rely on a consistent name and IP without managing Pod churn.

Q128: What is a DNS A record for a Service?

Cluster DNS resolves Service names to an A record or cluster IP.

Q129: What is a DNS SRV record for a Service?

SRV records can identify named ports for a Service, useful for some protocols.

Q130: What is a headless Service DNS behavior?

A headless Service returns individual Pod IPs instead of the ClusterIP.

Q131: Why do StatefulSets need headless Services?

To give each Pod a stable identity and DNS name independent of the Service IP.

Q132: What is a StatefulSet network identity?

Each StatefulSet Pod gets a stable ordinal-based name and DNS record.

Q133: What is a Service mesh for advanced traffic control?

A service mesh adds retries, mTLS, canary releases, and traffic shifting on top of standard Services.

Q134: What is a Service topology?

Service topology defines how a Service routes traffic, such as local-only or zone-aware routing.

Q135: What is topology-aware routing?

It routes traffic to nearby backends based on topology, such as the same zone or node.

Q136: What is a cluster IP leak?

A cluster IP leak happens when internal Service addresses are exposed unintentionally.

Q137: What is a Service exposure risk?

External exposure can create attack surfaces if the Service is not controlled by firewall or ingress policy.

Q138: What is the role of firewalling with Services?

Firewall rules help restrict access to cluster or external entry points.

Q139: What is a Kubernetes NetworkPolicy?

A NetworkPolicy restricts traffic to and from Pods, which helps control Service accessibility.

Q140: What is a default deny policy?

A default deny policy blocks most traffic until specific allowed paths are defined.

Q141: Why do Services rely on NetworkPolicies?

Because a Service should not be reachable by every pod by default in secure environments.

Q142: What is a zero-trust service model?

It assumes workloads are isolated unless explicitly allowed to talk to each other.

Q143: What is a private cluster service?

It is a Service only reachable within the cluster or VPC.

Q144: What is a public service?

A public service is reachable by external clients via LoadBalancer, NodePort, or Ingress.

Q145: What is a gateway service?

A gateway service handles external traffic and routes it to the correct internal Service.

Q146: What is a cluster ingress?

An ingress sits at the edge and routes HTTP/HTTPS traffic into the cluster.

Q147: Why is Ingress often preferred for HTTP services?

Because it supports URL routing and TLS termination without exposing many node ports.

Q148: What is an Ingress rule path?

A path routes particular URL requests to specific backend Services.

Q149: What is an Ingress host rule?

It routes based on hostname, such as api.example.com vs app.example.com.

Q150: What is a host and path combination?

Ingress can match on both, allowing multiple apps and routes behind one external entry point.

Q151: What is a service admission control?

Policies can restrict which Services can be exposed or which types are allowed.

Q152: Why is Services naming important?

Because names become DNS names and are used by apps and operators to discover them.

Q153: What is a Service selector bug?

It happens when the selector labels do not match Pods, leaving the Service with no endpoints.

Q154: What is a stale endpoint?

A stale endpoint refers to a Pod that was removed but still appears in the endpoint list temporarily.

Q155: What is a Pod termination lifecycle?

When a Pod is terminating, it may remain temporarily ready or not, affecting Service routing.

Q156: What is a readiness grace period?

A readiness grace period allows a Pod to start receiving traffic only after it is fully ready.

Q157: What is a Service timeout?

A timeout occurs when a client waits too long for a response from a backend.

Q158: What is a circuit breaker?

A circuit breaker prevents repeated calls to an unhealthy or overloaded Service.

Q159: What is a retry policy?

A retry policy determines whether failed requests are retried and with what backoff.

Q160: What is service-level observability?

It includes metrics, logs, traces, and health signals for Service traffic patterns and latency.

Q161: Why is tracing important for Services?

Because each request may traverse multiple Services, and tracing helps identify bottlenecks and failures.

Q162: What is a Service topology spread?

It distributes backend Pods across zones or nodes to improve resilience.

Q163: What is high availability for Services?

High availability means the Service remains reachable even when some Pods or nodes fail.

Q164: What is the relationship between Deployment replicas and Services?

A Service routes to all ready Pods behind its selector, regardless of deployment scale.

Q165: Why do Services abstract pod churn?

Because clients see a stable per-service endpoint rather than unstable pod IPs.

Q166: What is a Service port conflict?

It happens when multiple Services on the same cluster or nodes try to bind the same port unexpectedly.

Q167: What is an external IP assignment race?

It happens when multiple Services try to claim or update the same cloud external IP.

Q168: What is a NodePort conflict?

A NodePort conflict occurs when two Services try to use the same node port.

Q169: What is Service object metadata?

Metadata includes labels, annotations, name, namespace, and other identifying fields.

Q170: What is a Service annotation?

Annotations are arbitrary metadata used by controllers, ingress, or cloud vendors.

Q171: What is an annotation-based cloud LB integration?

Cloud controllers may use annotations to create or modify load balancers for a Service.

Q172: What is a Service type conversion?

You can convert a Service between ClusterIP, NodePort, and LoadBalancer when you need to change exposure.

Q173: What is a service account token and network policy interaction?

Service account token exposure may be affected by policies, but Services themselves are network objects not identity objects.

Q174: Why do Service types matter?

Because they define the external exposure model and how the Service is accessed by clients.

Q175: What is a stable service endpoint model?

It is the idea that clients can reach a service without tracking individual pods or their movements.

Q176: What is a service-level DNS entry?

It is the DNS name that resolves to the Service’s stable cluster IP or other address.

Q177: Why use a Service without a selector?

To manually define endpoints that are not Kubernetes Pods, or to integrate with external resources.

Q178: What is a Service generated by an external controller?

Some controllers create Services automatically for external or internal integrations.

Q179: What is k8s service traffic flow?

Client -> Service IP -> kube-proxy -> selected backend Pod -> app response.

Q180: Why is kube-proxy central to service routing?

Because it turns the Service abstraction into actual iptables or IPVS rules on the node.

Advanced / Expert

Q181: What is Service topology in large clusters?

It includes topology-aware routing, zone balancing, and node locality to optimize performance and resilience.

Q182: What is kube-proxy iptables performance under load?

iptables rules are efficient but can scale poorly under extreme endpoint churn or large clusters compared with IPVS.

Q183: What is IPVS load balancing semantics?

IPVS supports weighted scheduling and more advanced L4 balancing than simple iptables rules.

Q184: What is kube-proxy per-node behavior?

kube-proxy runs on each node and maintains the local Service routing rules.

Q185: What is Service headless mode in StatefulSets?

It eliminates the ClusterIP and exposes each pod as a unique DNS endpoint.

Q186: Why is headless Service important in StatefulSets?

Because stateful workloads often need stable Pod DNS names and direct peer discovery.

Q187: What is DNS A record for a headless Service?

It resolves to one or more Pod IPs rather than a single Service ClusterIP.

Q188: What is a Service with multiple ports and protocols?

It can expose e.g. TCP and UDP port combinations to match different application protocols.

Q189: What is a Service for gRPC?

It is commonly a ClusterIP or LoadBalancer Service exposing the gRPC port to clients.

Q190: What is a Service for WebSocket?

A Service can route WebSocket traffic just like HTTP traffic, as long as backend Pods are ready and the protocol is supported.

Q191: What is a Service mesh traffic policy?

It may enforce mTLS, retries, circuit breakers, and routing rules independent of raw K8s Services.

Q192: What is a Service endpoint anti-affinity?

It means preferring backends in different failure domains to reduce correlated failures.

Q193: What is a multi-zone Service deployment?

It spreads Pods across availability zones and uses routing patterns to improve resilience and latency.

Q194: What is ingress sharding?

It is the partitioning of inbound traffic across ingress controllers or ingress nodes.

Q195: What is L4 vs L7 routing?

L4 routing operates at the transport layer, such as TCP/UDP. L7 routing operates at the application layer, such as HTTP path and host.

Q196: What is Kubernetes Service at L4?

The Service mostly functions at the transport layer, balancing connections to backend Pods.

Q197: What is Ingress at L7?

Ingress goes above Service routing and inspects HTTP headers, hosts, and paths.

Q198: What is external DNS integration?

ExternalDNS syncs DNS records to cloud or external DNS providers based on Kubernetes Services and Ingresses.

Q199: What is a Service object as the primitive of service discovery?

It is one of the core building blocks of K8s networking and inter-service communication.

Q200: What is the main lesson of Kubernetes Services?

Kubernetes Services turn a dynamic set of Pods into a stable, discoverable, load-balanced endpoint, which is the foundation of resilient and scalable application traffic management.