Concept and mechanism
A selector-based Service depends on matching labels and eligible backends. EndpointSlices help observe destinations. port is the exposed port and targetPort is the backend port; declaring containerPort does not fix an incorrect numeric targetPort. DNS should identify the correct namespace, and the cluster domain must be confirmed. Ingress declares rules applied by a compatible implementation. API acceptance of an Ingress proves neither a controller exists, a certificate is correct, nor a backend works. Check each stage using suitable evidence.
Guided application
NetworkPolicies are additive and depend on network-plugin enforcement. If source and destination are isolated, source egress and destination ingress must allow the connection. When introducing default deny, list dependencies such as DNS, metrics, and databases with the scope actually needed. The resolver may be node-local or use another topology; copying another cluster’s labels can fail. For TLS, compare the expected hostname, configuration, and served certificate. Do not confuse working HTTP routing with successful identity validation.
For a process on 9090 and clients on 80, use port 80 and targetPort 9090. Then confirm Pod selection, DNS, and policies along the actual path.
Common pitfalls
Changing Service type to fix labels; forgetting DNS in egress; disabling TLS validation to hide a wrong certificate.
Related topics: Reproducible images and finite work · Init containers, sharing, and persistence
Validate resolution, selection, ports, policies, and identity as parts of one path.
Reference: Services · CKAD Kubernetes v1.35