1. Kubernetes Service Types
A Service provides a stable network endpoint (IP + DNS name) for a group of Pods. It uses label selectors to find target Pods.
Service Traffic Flow:
Client ──► Service (ClusterIP: 10.96.1.100) ──► Pod 1
──► Pod 2
──► Pod 3
kube-proxy manages iptables/IPVS rules for load balancing
| Service Type | Scope | Use case | Access |
|---|---|---|---|
| ClusterIP | Internal only | Default, service-to-service communication | Only within the cluster |
| NodePort | External via node IP | Dev/test, direct access via node | NodeIP:30000-32767 |
| LoadBalancer | External via cloud LB | Production on AWS/GCP/Azure | External IP from cloud provider |
| ExternalName | CNAME redirect | Connect to external services by DNS | Returns CNAME record |
Exam tip: ClusterIP is the default — if the question says "service accessible within the cluster," that's ClusterIP. If the question asks "expose to the internet," it's LoadBalancer.
2. CoreDNS & Service Discovery
DNS Resolution in Kubernetes:
my-service.my-namespace.svc.cluster.local
───────── ──────────── ─── ─────────────
Service Namespace Type Cluster domain
Pod in same namespace: curl http://my-service:8080
Pod in different namespace: curl http://my-service.other-ns:8080
CoreDNS is a CNCF graduated project, the default DNS server in Kubernetes. It automatically creates DNS records for Services and Pods.
3. Ingress & Ingress Controller
Ingress manages external HTTP/HTTPS access to services via host/path rules. Requires an Ingress Controller (nginx, traefik, HAProxy).
Ingress Routing:
Client request: https://app.example.com/api
│
┌──────▼──────┐
│ Ingress │
│ Controller │
│ (nginx) │
└──────┬──────┘
┌────────────┼────────────┐
/api → Service A /web → Service B /docs → Service C
4. Storage — PV, PVC, StorageClass
Storage Architecture:
Pod
│ volumeMounts: /data
▼
PVC (PersistentVolumeClaim) ← "I want 10Gi ReadWriteOnce"
│ bound
▼
PV (PersistentVolume) ← "Here is 10Gi from AWS EBS"
│ provisioned by
▼
StorageClass ← "auto-provision EBS gp3"
| Concept | Role | Created by |
|---|---|---|
| PV (PersistentVolume) | Actual storage resource | Admin or dynamic (StorageClass) |
| PVC (PersistentVolumeClaim) | Pod requests storage | Developer |
| StorageClass | Auto-provision PVs based on demand | Admin |
Access Modes
| Mode | Abbreviation | Meaning |
|---|---|---|
| ReadWriteOnce | RWO | 1 node can mount read-write |
| ReadOnlyMany | ROX | Many nodes mount read-only |
| ReadWriteMany | RWX | Many nodes mount read-write |
5. ConfigMap & Secret
| Resource | Used for | Encoding | Mounting options |
|---|---|---|---|
| ConfigMap | Non-sensitive config (DB_HOST, LOG_LEVEL) | Plain text | env var, volume file |
| Secret | Sensitive data (password, API key, TLS cert) | Base64 (not encrypted by default!) | env var, volume file |
Exam tip: Secrets are base64-encoded, not encrypted by default. To actually encrypt, you need to enable Encryption at Rest. KCNA may ask about the distinction between encoding and encryption.
6. Cheat Sheet
| Exam question | Answer |
|---|---|
| Default Service type? | ClusterIP |
| Service accessed from the internet? | LoadBalancer |
| L7 HTTP routing? | Ingress |
| K8s DNS server? | CoreDNS |
| Multiple nodes mounting same volume read-write? | ReadWriteMany (RWX) |
| Auto-provision PVs? | StorageClass |
| Secrets are encrypted? | No — base64 encoded only, encryption at rest is separate |
7. Practice Questions
Q1: A development team needs to expose their Kubernetes Service to external traffic on a cloud provider. Which Service type should they use?
- A) ClusterIP
- B) NodePort
- C) LoadBalancer ✓
- D) ExternalName
Explanation: LoadBalancer type creates an external load balancer via the cloud provider (AWS ELB, GCP LB, Azure LB), automatically assigning a public IP for external access.
Q2: What is the full DNS name of a Service called 'payment' in the 'production' namespace?
- A) payment.production
- B) payment.production.svc.cluster.local ✓
- C) payment.svc.production.local
- D) production.payment.cluster.svc
Explanation: Kubernetes DNS format: <service>.<namespace>.svc.cluster.local. This is an auto-created A record by CoreDNS.
Q3: An application requires shared storage that multiple Pods on different nodes can read and write. Which access mode is needed?
- A) ReadWriteOnce (RWO)
- B) ReadOnlyMany (ROX)
- C) ReadWriteMany (RWX) ✓
- D) ReadWriteOncePod
Explanation: RWX (ReadWriteMany) allows multiple nodes to mount the volume for both reading and writing. Typically requires network storage like NFS, EFS, or CephFS. Block storage (EBS, GCP PD) usually only supports RWO.