Skip to content

Services

Kubernetes services act as stable endpoints for accessing pods, which are inherently ephemeral. By abstracting pod IP addresses, services enable consistent communication within the cluster and to external systems. Kubernetes provides three primary service types—ClusterIP, NodePort, and LoadBalancer—each tailored to different networking scenarios and access requirements.


ClusterIP: Internal Cluster Access

The default service type, ClusterIP, exposes a service internally within the cluster. It assigns a virtual IP address (VIP) that other pods or services can use to reach the application. This type is ideal for internal microservices communication.

Example YAML:

apiVersion: v1
kind: Service
metadata:
  name: my-app
spec:
  type: ClusterIP
  selector:
    app: my-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 80

Key behavior:
- The service is only accessible within the cluster.
- Use kubectl get services to view the assigned ClusterIP.
- Pods use DNS names (e.g., my-app.default.svc.cluster.local) to resolve the service.


NodePort: Exposing Services to External Networks

NodePort extends ClusterIP by opening a static port on each node's firewall. This allows external traffic to reach the service via any node's IP address and the assigned port. It’s useful for testing or small-scale external access.

Example YAML:

apiVersion: v1
kind: Service
metadata:
  name: my-app-nodeport
spec:
  type: NodePort
  selector:
    app: my-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 80
      nodePort: 30001

Key behavior:
- Traffic arrives at any node’s IP:NodePort.
- The nodePort field specifies the port (or use auto-assigned if omitted).
- Use kubectl get services to see the NODE_PORT value.


LoadBalancer: Cloud-Integrated External Access

LoadBalancer provisions an external load balancer (managed by the cloud provider) to route traffic to the service. This type is ideal for production workloads requiring high availability and scalability.

Example YAML:

apiVersion: v1
kind: Service
metadata:
  name: my-app-loadbalancer
spec:
  type: LoadBalancer
  selector:
    app: my-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 80

Key behavior:
- The cloud provider assigns an external IP (e.g., EXTERNAL-IP in kubectl get services).
- Traffic is distributed across nodes running the service.
- Requires cloud provider support (e.g., AWS ELB, GCP Load Balancer).


Choosing the Right Service Type

  • ClusterIP: For internal communication.
  • NodePort: For manual external access.
  • LoadBalancer: For cloud-managed, scalable external access.

Each type addresses different use cases, balancing simplicity, control, and scalability. Services also handle traffic distribution via round-robin, ensuring even load across pods.

Key takeaways

  • ClusterIP provides internal cluster access via a virtual IP.
  • NodePort exposes services externally via a static port on each node.
  • LoadBalancer leverages cloud infrastructure for scalable external access.
  • Services enable stable communication between pods and external systems.
  • Select the service type based on your networking requirements and environment.