← CKAD: Kubernetes applications in production
07 / 7 · 28 MIN

Services, DNS, and isolation

Follow the path from client to backend and its dependencies.

Concept and mechanism

A selector-based Service depends on matching labels and eligible backends. EndpointSlices help observe destinations. port is the exposed port and targetPort is the backend port; declaring containerPort does not fix an incorrect numeric targetPort. DNS should identify the correct namespace, and the cluster domain must be confirmed. Ingress declares rules applied by a compatible implementation. API acceptance of an Ingress proves neither a controller exists, a certificate is correct, nor a backend works. Check each stage using suitable evidence.

Guided application

NetworkPolicies are additive and depend on network-plugin enforcement. If source and destination are isolated, source egress and destination ingress must allow the connection. When introducing default deny, list dependencies such as DNS, metrics, and databases with the scope actually needed. The resolver may be node-local or use another topology; copying another cluster’s labels can fail. For TLS, compare the expected hostname, configuration, and served certificate. Do not confuse working HTTP routing with successful identity validation.

IN PRACTICE

For a process on 9090 and clients on 80, use port 80 and targetPort 9090. Then confirm Pod selection, DNS, and policies along the actual path.

Common pitfalls

Changing Service type to fix labels; forgetting DNS in egress; disabling TLS validation to hide a wrong certificate.

Related topics: Reproducible images and finite work · Init containers, sharing, and persistence

Take this idea with you

Validate resolution, selection, ports, policies, and identity as parts of one path.

Create account

Reference: Services · CKAD Kubernetes v1.35