Kubernetes Services
Kubernetes Services
Beginner
Q1: What is a Kubernetes Service?
A Kubernetes Service is an abstraction that defines a stable network identity and routing policy for a set of Pods.
Q2: Why do we need Services in Kubernetes?
Pods are ephemeral and often have dynamic IPs. Services provide a stable endpoint for clients to connect to.
Q3: What is a Pod IP?
A Pod IP is the IP address assigned to a pod, which can change when the pod is recreated.
Q4: Why are Pod IPs not stable?
Pods may be rescheduled, restarted, scaled, or replaced, which can change their IP addresses.
Q5: What is service discovery?
Service discovery is the process of finding the network endpoint for a service without hardcoding pod IPs.
Q6: What is a Service selector?
A Service selector matches Pods by labels, selecting which pods receive traffic.
Q7: What is a label in Kubernetes?
A label is a key-value pair used to organize and select objects like Pods.
Q8: What is a selector match?
A selector match identifies Pods whose labels satisfy the Service’s label query.
Q9: What is the default Service type?
The default Service type is ClusterIP.
Q10: What is a ClusterIP Service?
A ClusterIP Service exposes the service internally within the cluster.
Q11: What is a NodePort Service?
A NodePort Service exposes the service on a static port on each node.
Q12: What is a LoadBalancer Service?
A LoadBalancer Service provisions an external load balancer to expose the service outside the cluster.
Q13: What is an ExternalName Service?
An ExternalName Service maps a service name to an external hostname, such as an external DNS name.
Q14: What is an Ingress?
An Ingress is an HTTP or HTTPS entry point that routes traffic to Services based on rules.
Q15: Why use an Ingress instead of NodePort?
Ingress provides HTTP routing, TLS termination, path routing, and a cleaner external entry point.
Q16: What does a Service do at a high level?
A Service provides a stable IP and port, and load balances traffic to matching Pods.
Q17: What is a Service endpoint?
A Service endpoint is the Pod address and port selected by the Service.
Q18: What are endpoints in Kubernetes?
Endpoints are the actual IPs and ports of the Pods behind a Service.
Q19: What is endpoint slicing?
Endpoint slicing is the newer API for tracking sets of Pod endpoints behind a Service efficiently.
Q20: Why are Services needed in a cluster?
Because clients should not need to know all Pod IPs or handle churn.
Q21: What is a stable DNS name for a Service?
A Service gets a DNS name in the cluster namespace, such as my-service.my-namespace.svc.cluster.local.
Q22: What is a Service in a Namespace?
A Service is scoped to a namespace and typically discovered via that namespace’s DNS.
Q23: What is cluster DNS?
Cluster DNS provides name resolution for Services and Pods within the Kubernetes cluster.
Q24: What is a selectorless Service?
A selectorless Service does not match Pods by labels and is often used to point to an external service or manually managed endpoints.
Q25: What is a headless Service?
A headless Service has no ClusterIP and exposes each Pod directly through DNS entries.
Q26: Why use a headless Service?
It is useful for stateful applications and direct Pod access, like a database cluster.
Q27: What is a session affinity?
Session affinity keeps requests from the same client bound to the same backend Pod.
Q28: Why would you use session affinity?
Some applications are stateful and require stickiness to a specific Pod.
Q29: What is a Service port?
A Service port is the port exposed by the Service to clients.
Q30: What is a target port?
A target port is the port on the Pod that receives the traffic.
Q31: Why use a target port value different from a service port?
Because the Service may expose a stable public port while the app listens on another internal port.
Q32: What is a Service manifest?
A Service manifest is a Kubernetes YAML resource that defines the Service’s selector, ports, and type.
Q33: What is a selector label example?
For example:
app: api
or
tier: backend
Q34: What does a Service select by default?
A Service selects Pods by labels based on the selector field.
Q35: How does traffic reach Pods behind a Service?
The kube-proxy or network plugin routes packets to one of the selected Pods.
Q36: What is kube-proxy?
kube-proxy is the Kubernetes component that implements Service routing rules in the cluster.
Q37: What is iptables mode?
iptables mode is a kube-proxy mode that uses iptables rules for routing and load balancing.
Q38: What is IPVS mode?
IPVS mode uses IPVS load balancing for service traffic and can be more performant in some large clusters.
Q39: What is load balancing in a Service?
Load balancing means distributing requests across multiple matching Pods.
Q40: What is round-robin load balancing?
Round-robin is a common load-balancing strategy where traffic is sent to Pods in turn.
Q41: What is service health?
A healthy Service endpoint is a Pod that is ready and able to accept traffic.
Q42: What is a readiness probe?
A readiness probe indicates when a container is ready to receive traffic.
Q43: Why are readiness probes important to Services?
Because Services route only to ready Pods unless explicitly configured otherwise.
Q44: What is a liveness probe?
A liveness probe indicates whether the container is alive and should be restarted if not.
Q45: What is a Pod readiness gate?
It is a more advanced readiness mechanism used by workloads to gate traffic acceptance.
Q46: What is service backlog?
A backlog is the queue of connections or requests waiting to be handled by backend Pods.
Q47: What is a network policy?
A network policy allows or denies traffic to and from pods and services based on labels and ports.
Q48: Why do Services and network policies matter together?
Because Services route traffic while network policies enforce who may talk to whom.
Q49: What is a ClusterIP assignment?
Kubernetes assigns a virtual IP address to the Service for intra-cluster access.
Q50: What is a Service type change?
A Service can be changed from ClusterIP to NodePort or LoadBalancer depending on exposure requirements.
Q51: What is a Kubernetes Deployment?
A Deployment manages ReplicaSets and maintains a desired number of Pods.
Q52: How does a Service relate to a Deployment?
A Service selects Pods created by a Deployment by labels.
Q53: What is a ReplicaSet?
A ReplicaSet ensures a defined number of Pod replicas are running.
Q54: What is a DaemonSet?
A DaemonSet ensures a Pod runs on every or selected nodes, often relevant for node-level networking services.
Q55: What is a StatefulSet?
A StatefulSet manages stateful Pods that often need stable identities and stable network identities.
Q56: Why do StatefulSets often use headless Services?
Because they need direct Pod-level identities and stable DNS names.
Q57: What is a Service name?
A Service name is the DNS name used by clients to connect to it.
Q58: What is DNS A record resolution for Services?
Kubernetes DNS resolves Service names to cluster IP addresses.
Q59: What is a Service port mapping?
A Service port maps external name and port to target port(s) on the Pods.
Q60: What is a Kubernetes namespace?
A namespace isolates Kubernetes objects, including Services, within a logical boundary.
Q61: Why is namespace isolation important?
It separates teams, apps, and environments while reducing accidental cross-communication.
Q62: What is an internal service?
An internal service is only reachable within the cluster.
Q63: What is an external service?
An external service is reachable from outside the cluster, usually via NodePort, LoadBalancer, or Ingress.
Q64: What is service exposure?
Service exposure is the act of making a Service reachable from outside or within the cluster.
Q65: What is port forwarding?
Port forwarding is a debugging technique where local traffic is forwarded into a pod or service.
Q66: What is kubectl port-forward?
It allows local clients to access a Service or pod as if it were local.
Q67: What is a network endpoint?
An endpoint is the destination that a Service forwards traffic to, nominally a Pod IP and port.
Q68: What is a Service mesh?
A Service mesh adds advanced routing, policy, and observability on top of Service networking.
Q69: Why is a Service mesh complementary to Kubernetes Services?
Because Services handle basic routing, while a mesh adds policy, observability, and advanced traffic control.
Q70: What is a Service to Pod mapping?
A Service maps a stable identity to one or more backend Pods.
Q71: Why are labels important for Services?
Because Services target Pods by labels, which makes selection dynamic and resilient.
Q72: What is a label selector mismatch?
It happens when the Service selector does not match any Pods or when labels change unexpectedly.
Q73: What is a Service not selecting Pods?
This often causes connection failures because no backends exist for the Service.
Q74: Why should Services be placed in the same namespace as Pods?
Usually yes, because DNS names and service discovery are namespaced.
Q75: What is DNS name resolution across namespaces?
Pods in different namespaces can resolve a Service with the namespace-qualified DNS name.
Q76: What is a service account and how is it related?
A service account is separate from a Service object, though both are K8s objects.
Q77: What is a service port number?
A port number identifies where a Service listens, such as 80 or 443.
Q78: What is a target port number?
A target port may be different from the service port, often 8080 inside a container.
Q79: What is a named port?
A named port lets you reference a service or container port by a name instead of a number in some APIs.
Q80: What is a Service IP family?
The IP family indicates IPv4 and/or IPv6 support for the Service.
Q81: Why is IPv6 support relevant?
Some clusters support dual-stack networking, and Services may be assigned IPv4, IPv6, or both.
Q82: What is a dual-stack Service?
A dual-stack Service has both IPv4 and IPv6 addresses in a dual-stack cluster.
Q83: What is a NodePort range?
NodePort ports are allocated from a configurable range, usually 30000-32767.
Q84: Why does NodePort expose to all nodes?
A NodePort Service opens the port on each cluster node, allowing access through any node IP.
Q85: What is a LoadBalancer external IP?
A LoadBalancer Service obtains an external IP assigned by a cloud or external load balancer.
Q86: What is a cloud provider integration?
CDNs or cloud load balancers integrate with Kubernetes Services to expose workloads externally.
Q87: Why do cluster internal Services not need external IPs?
Because traffic stays inside the cluster and uses the Service’s ClusterIP.
Q88: What is an internal load balancer?
An internal load balancer exposes a Service only inside the private network or VPC.
Q89: What is a Service health check?
A health check ensures a Service is reachable and backend Pods are ready.
Q90: Why is readiness critical to SLOs?
Because a Service should not send traffic to unhealthy endpoints.
Q91: What is a Service event?
A Service event can indicate changes to endpoints, type, or load balancer configuration.
Q92: What is a Kubernetes endpoint controller?
The endpoint controller maintains the list of backend Pods for Services.
Q93: Why do Services need endpoints?
Because otherwise no backend addresses exist and traffic cannot reach the app.
Q94: What is the difference between a Service and a Deployment?
A Deployment defines what Pods should run. A Service defines how to reach them.
Q95: What is a Pod label selector?
It is a query used to identify Pods based on labels.
Q96: What is a multi-port Service?
A Service can expose multiple ports, such as HTTP on 80 and metrics on 9090.
Q97: What is a named port in a Pod?
A Pod port may be assigned a name so a Service or app can reference it by name.
Q98: What is a service port protocol?
The protocol is often TCP or UDP, and for some services it may be SCTP as well.
Q99: What is a Service protocol mismatch?
It occurs when the Service or Pod is configured for one protocol but the application expects another.
Q100: What is a service routing policy?
A service routing policy governs traffic rules such as load balancing, affinity, and session behavior.
Intermediate
Q101: What is kube-proxy in userspace mode?
It is an older kube-proxy mode where traffic is proxied by user-space processes.
Q102: What is IPVS mode?
IPVS is a kernel-space load balancer used by kube-proxy for high-performance L4 service routing.
Q103: Why use IPVS?
It can scale better and provide more efficient load balancing for large clusters.
Q104: What is a ClusterIP service in practice?
It is virtual IP and port that routes to one or more selected Pods.
Q105: What is a kube-proxy iptables rule?
It is a low-level rule that sends packets from the Service IP to Pod endpoints.
Q106: Why is Service routing more complex than simple DNS?
Because the Service needs to balance traffic among multiple Pods and track readiness.
Q107: What is an endpoint slice?
EndpointSlice is the API object that stores addresses and metadata for Service backends.
Q108: Why was EndpointSlice introduced?
To scale better for large numbers of endpoints and Services.
Q109: What is endpoint controller behavior?
It watches Pods and updates the appropriate Service endpoints as Pods appear, disappear, or become ready.
Q110: What is a Pod ready condition?
The Pod ready condition indicates whether Pod containers are ready for service traffic.
Q111: Why is readiness important for zero-downtime deployments?
Because traffic should not go to Pods still starting up or failing readiness checks.
Q112: What is a startup probe?
A startup probe detects whether an app has finished starting up and can delay liveness checks during initialization.
Q113: Why use a startup probe with Services?
It helps avoid premature restarts when the app starts slowly.
Q114: What is an externalTrafficPolicy?
ExternalTrafficPolicy controls whether traffic from outside the cluster is routed through the node or directly to Pods.
Q115: What is local traffic policy?
Local traffic policy sends external traffic only to local Pods on the same node when possible.
Q116: What is Cluster external traffic policy?
Cluster external traffic policy may route traffic to Pods on other nodes.
Q117: What is a LoadBalancer health check?
A cloud or external LB often performs health checks against the Service’s backend to decide routing.
Q118: What is a NodePort health check?
A NodePort may need health checks at the node or LB layer to know when the endpoints are healthy.
Q119: Why do external load balancers need readiness?
Because they should not route to unhealthy Pods or nodes.
Q120: What is an ingress controller?
An ingress controller watches Ingress resources and configures an HTTP routing layer.
Q121: How does an Ingress relate to Services?
Ingress routes HTTP traffic to one or more Services, which then route to Pods.
Q122: What is a Service multi-port scenario?
A Service may expose multiple ports, each mapping to a different target port or protocol.
Q123: What is a host-based Ingress rule?
Host-based routing sends traffic for different domains to different Services.
Q124: What is a path-based Ingress rule?
Path-based routing sends /api to one Service and /web to another.
Q125: What is a TLS Ingress?
An Ingress can terminate TLS and route incoming HTTPS traffic to a backend Service.
Q126: What is a Service in a multi-tenant cluster?
It may be namespaced and connected to a particular team or app.
Q127: What is stable service identity?
A stable Service identity means clients can rely on a consistent name and IP without managing Pod churn.
Q128: What is a DNS A record for a Service?
Cluster DNS resolves Service names to an A record or cluster IP.
Q129: What is a DNS SRV record for a Service?
SRV records can identify named ports for a Service, useful for some protocols.
Q130: What is a headless Service DNS behavior?
A headless Service returns individual Pod IPs instead of the ClusterIP.
Q131: Why do StatefulSets need headless Services?
To give each Pod a stable identity and DNS name independent of the Service IP.
Q132: What is a StatefulSet network identity?
Each StatefulSet Pod gets a stable ordinal-based name and DNS record.
Q133: What is a Service mesh for advanced traffic control?
A service mesh adds retries, mTLS, canary releases, and traffic shifting on top of standard Services.
Q134: What is a Service topology?
Service topology defines how a Service routes traffic, such as local-only or zone-aware routing.
Q135: What is topology-aware routing?
It routes traffic to nearby backends based on topology, such as the same zone or node.
Q136: What is a cluster IP leak?
A cluster IP leak happens when internal Service addresses are exposed unintentionally.
Q137: What is a Service exposure risk?
External exposure can create attack surfaces if the Service is not controlled by firewall or ingress policy.
Q138: What is the role of firewalling with Services?
Firewall rules help restrict access to cluster or external entry points.
Q139: What is a Kubernetes NetworkPolicy?
A NetworkPolicy restricts traffic to and from Pods, which helps control Service accessibility.
Q140: What is a default deny policy?
A default deny policy blocks most traffic until specific allowed paths are defined.
Q141: Why do Services rely on NetworkPolicies?
Because a Service should not be reachable by every pod by default in secure environments.
Q142: What is a zero-trust service model?
It assumes workloads are isolated unless explicitly allowed to talk to each other.
Q143: What is a private cluster service?
It is a Service only reachable within the cluster or VPC.
Q144: What is a public service?
A public service is reachable by external clients via LoadBalancer, NodePort, or Ingress.
Q145: What is a gateway service?
A gateway service handles external traffic and routes it to the correct internal Service.
Q146: What is a cluster ingress?
An ingress sits at the edge and routes HTTP/HTTPS traffic into the cluster.
Q147: Why is Ingress often preferred for HTTP services?
Because it supports URL routing and TLS termination without exposing many node ports.
Q148: What is an Ingress rule path?
A path routes particular URL requests to specific backend Services.
Q149: What is an Ingress host rule?
It routes based on hostname, such as api.example.com vs app.example.com.
Q150: What is a host and path combination?
Ingress can match on both, allowing multiple apps and routes behind one external entry point.
Q151: What is a service admission control?
Policies can restrict which Services can be exposed or which types are allowed.
Q152: Why is Services naming important?
Because names become DNS names and are used by apps and operators to discover them.
Q153: What is a Service selector bug?
It happens when the selector labels do not match Pods, leaving the Service with no endpoints.
Q154: What is a stale endpoint?
A stale endpoint refers to a Pod that was removed but still appears in the endpoint list temporarily.
Q155: What is a Pod termination lifecycle?
When a Pod is terminating, it may remain temporarily ready or not, affecting Service routing.
Q156: What is a readiness grace period?
A readiness grace period allows a Pod to start receiving traffic only after it is fully ready.
Q157: What is a Service timeout?
A timeout occurs when a client waits too long for a response from a backend.
Q158: What is a circuit breaker?
A circuit breaker prevents repeated calls to an unhealthy or overloaded Service.
Q159: What is a retry policy?
A retry policy determines whether failed requests are retried and with what backoff.
Q160: What is service-level observability?
It includes metrics, logs, traces, and health signals for Service traffic patterns and latency.
Q161: Why is tracing important for Services?
Because each request may traverse multiple Services, and tracing helps identify bottlenecks and failures.
Q162: What is a Service topology spread?
It distributes backend Pods across zones or nodes to improve resilience.
Q163: What is high availability for Services?
High availability means the Service remains reachable even when some Pods or nodes fail.
Q164: What is the relationship between Deployment replicas and Services?
A Service routes to all ready Pods behind its selector, regardless of deployment scale.
Q165: Why do Services abstract pod churn?
Because clients see a stable per-service endpoint rather than unstable pod IPs.
Q166: What is a Service port conflict?
It happens when multiple Services on the same cluster or nodes try to bind the same port unexpectedly.
Q167: What is an external IP assignment race?
It happens when multiple Services try to claim or update the same cloud external IP.
Q168: What is a NodePort conflict?
A NodePort conflict occurs when two Services try to use the same node port.
Q169: What is Service object metadata?
Metadata includes labels, annotations, name, namespace, and other identifying fields.
Q170: What is a Service annotation?
Annotations are arbitrary metadata used by controllers, ingress, or cloud vendors.
Q171: What is an annotation-based cloud LB integration?
Cloud controllers may use annotations to create or modify load balancers for a Service.
Q172: What is a Service type conversion?
You can convert a Service between ClusterIP, NodePort, and LoadBalancer when you need to change exposure.
Q173: What is a service account token and network policy interaction?
Service account token exposure may be affected by policies, but Services themselves are network objects not identity objects.
Q174: Why do Service types matter?
Because they define the external exposure model and how the Service is accessed by clients.
Q175: What is a stable service endpoint model?
It is the idea that clients can reach a service without tracking individual pods or their movements.
Q176: What is a service-level DNS entry?
It is the DNS name that resolves to the Service’s stable cluster IP or other address.
Q177: Why use a Service without a selector?
To manually define endpoints that are not Kubernetes Pods, or to integrate with external resources.
Q178: What is a Service generated by an external controller?
Some controllers create Services automatically for external or internal integrations.
Q179: What is k8s service traffic flow?
Client -> Service IP -> kube-proxy -> selected backend Pod -> app response.
Q180: Why is kube-proxy central to service routing?
Because it turns the Service abstraction into actual iptables or IPVS rules on the node.
Advanced / Expert
Q181: What is Service topology in large clusters?
It includes topology-aware routing, zone balancing, and node locality to optimize performance and resilience.
Q182: What is kube-proxy iptables performance under load?
iptables rules are efficient but can scale poorly under extreme endpoint churn or large clusters compared with IPVS.
Q183: What is IPVS load balancing semantics?
IPVS supports weighted scheduling and more advanced L4 balancing than simple iptables rules.
Q184: What is kube-proxy per-node behavior?
kube-proxy runs on each node and maintains the local Service routing rules.
Q185: What is Service headless mode in StatefulSets?
It eliminates the ClusterIP and exposes each pod as a unique DNS endpoint.
Q186: Why is headless Service important in StatefulSets?
Because stateful workloads often need stable Pod DNS names and direct peer discovery.
Q187: What is DNS A record for a headless Service?
It resolves to one or more Pod IPs rather than a single Service ClusterIP.
Q188: What is a Service with multiple ports and protocols?
It can expose e.g. TCP and UDP port combinations to match different application protocols.
Q189: What is a Service for gRPC?
It is commonly a ClusterIP or LoadBalancer Service exposing the gRPC port to clients.
Q190: What is a Service for WebSocket?
A Service can route WebSocket traffic just like HTTP traffic, as long as backend Pods are ready and the protocol is supported.
Q191: What is a Service mesh traffic policy?
It may enforce mTLS, retries, circuit breakers, and routing rules independent of raw K8s Services.
Q192: What is a Service endpoint anti-affinity?
It means preferring backends in different failure domains to reduce correlated failures.
Q193: What is a multi-zone Service deployment?
It spreads Pods across availability zones and uses routing patterns to improve resilience and latency.
Q194: What is ingress sharding?
It is the partitioning of inbound traffic across ingress controllers or ingress nodes.
Q195: What is L4 vs L7 routing?
L4 routing operates at the transport layer, such as TCP/UDP. L7 routing operates at the application layer, such as HTTP path and host.
Q196: What is Kubernetes Service at L4?
The Service mostly functions at the transport layer, balancing connections to backend Pods.
Q197: What is Ingress at L7?
Ingress goes above Service routing and inspects HTTP headers, hosts, and paths.
Q198: What is external DNS integration?
ExternalDNS syncs DNS records to cloud or external DNS providers based on Kubernetes Services and Ingresses.
Q199: What is a Service object as the primitive of service discovery?
It is one of the core building blocks of K8s networking and inter-service communication.
Q200: What is the main lesson of Kubernetes Services?
Kubernetes Services turn a dynamic set of Pods into a stable, discoverable, load-balanced endpoint, which is the foundation of resilient and scalable application traffic management.