certslothcertsloth
CKAD/Topic 06

CNCF / Developer

Services, DNS and Network Policy

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Selector finds endpoints; policy permits the path.

Must remember

Pods communicate using cluster networking supplied by the CNI. A Service gives stable discovery for a changing set of endpoints. Check labels/selectors, target ports and EndpointSlices when traffic reaches the Service but no application responds.

Type Use
ClusterIP Internal stable virtual service address.
NodePort A port exposed on nodes, with the Service forwarding to backends.
LoadBalancer Requests an external load balancer from an available implementation.
Headless (clusterIP: None) DNS discovery of endpoints rather than a normal virtual IP.

Ingress describes HTTP/S routing, but needs an Ingress controller. TLS certificates normally come from referenced Secrets; matching host/path and backend port matters. Gateway API separates infrastructure ownership (GatewayClass/controller), listeners (Gateway) and application routing (HTTPRoute). Inspect parent references, allowed routes, listener hostnames and cross-namespace ReferenceGrants where needed. Gateway resources also require an implementation.

CoreDNS resolves service names such as api.team.svc.cluster.local, with the actual cluster domain configurable. Test name resolution separately from network reachability. Check namespace search suffixes, CoreDNS Pods/Service, resolv.conf and DNS egress policy before blaming application code.

Gateway routing drill: inspect kubectl get gateway,httproute -n team -o yaml, then trace parentRefs to the listener and backendRefs to the Service. An HTTPRoute backend port is the Service port, not an arbitrary container port. Check host/path matching and the controller's status conditions before testing a request with the intended Host header. A route that exists but never attaches to its Gateway cannot deliver the requested traffic.

NetworkPolicy is enforced only by supporting networking implementations. Policies are additive allow lists. Once a Pod is isolated for ingress or egress, applicable allowed traffic must be specified; when both ends are isolated, both source egress and destination ingress must permit the connection. An empty selector selects all Pods in that namespace. Namespace and Pod selectors in the same peer entry are AND; separate entries are alternatives.

Practical drill: draw client → DNS → Service → endpoint → container. For each arrow, identify one read-only command and one possible configuration fault.

Choose under exam pressure

Requirement Choice and reason
HTTP host/path routing Ingress or Gateway API with a working controller.
Service has no backends Inspect selectors, Pod readiness and EndpointSlices.
Restrict Pod communication NetworkPolicies plus a capable CNI implementation.

Traps

  • Creating a LoadBalancer Service does not guarantee a load-balancer implementation exists.
  • Default-deny egress can also block DNS.

Active recall

1. What implements an Ingress object?

An installed controller that watches and configures the required data plane.

2. Why inspect EndpointSlices?

They reveal which addresses and ports the Service can actually use.

3. Does NetworkPolicy work on every CNI automatically?

No. The networking implementation must enforce it.

4. Both ends are isolated: which policy must permit traffic?

The source’s egress and destination’s ingress.

5. What does GatewayClass represent?

The implementation/controller class responsible for Gateways using it.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.