Services
Kubernetes services act as stable endpoints for accessing pods, which are inherently ephemeral. By abstracting pod IP addresses, services enable consistent communication within the cluster and to external systems. Kubernetes provides three primary service types—ClusterIP, NodePort, and LoadBalancer—each tailored to different networking scenarios and access requirements.
ClusterIP: Internal Cluster Access¶
The default service type, ClusterIP, exposes a service internally within the cluster. It assigns a virtual IP address (VIP) that other pods or services can use to reach the application. This type is ideal for internal microservices communication.
Example YAML:
apiVersion: v1
kind: Service
metadata:
name: my-app
spec:
type: ClusterIP
selector:
app: my-app
ports:
- protocol: TCP
port: 80
targetPort: 80
Key behavior:
- The service is only accessible within the cluster.
- Use kubectl get services to view the assigned ClusterIP.
- Pods use DNS names (e.g., my-app.default.svc.cluster.local) to resolve the service.
NodePort: Exposing Services to External Networks¶
NodePort extends ClusterIP by opening a static port on each node's firewall. This allows external traffic to reach the service via any node's IP address and the assigned port. It’s useful for testing or small-scale external access.
Example YAML:
apiVersion: v1
kind: Service
metadata:
name: my-app-nodeport
spec:
type: NodePort
selector:
app: my-app
ports:
- protocol: TCP
port: 80
targetPort: 80
nodePort: 30001
Key behavior:
- Traffic arrives at any node’s IP:NodePort.
- The nodePort field specifies the port (or use auto-assigned if omitted).
- Use kubectl get services to see the NODE_PORT value.
LoadBalancer: Cloud-Integrated External Access¶
LoadBalancer provisions an external load balancer (managed by the cloud provider) to route traffic to the service. This type is ideal for production workloads requiring high availability and scalability.
Example YAML:
apiVersion: v1
kind: Service
metadata:
name: my-app-loadbalancer
spec:
type: LoadBalancer
selector:
app: my-app
ports:
- protocol: TCP
port: 80
targetPort: 80
Key behavior:
- The cloud provider assigns an external IP (e.g., EXTERNAL-IP in kubectl get services).
- Traffic is distributed across nodes running the service.
- Requires cloud provider support (e.g., AWS ELB, GCP Load Balancer).
Choosing the Right Service Type¶
- ClusterIP: For internal communication.
- NodePort: For manual external access.
- LoadBalancer: For cloud-managed, scalable external access.
Each type addresses different use cases, balancing simplicity, control, and scalability. Services also handle traffic distribution via round-robin, ensuring even load across pods.
Key takeaways¶
- ClusterIP provides internal cluster access via a virtual IP.
- NodePort exposes services externally via a static port on each node.
- LoadBalancer leverages cloud infrastructure for scalable external access.
- Services enable stable communication between pods and external systems.
- Select the service type based on your networking requirements and environment.