Chuyển đến nội dung chính

Lesson 3: Services, Networking & Storage

ClusterIP, NodePort, LoadBalancer, ExternalName. CoreDNS, Service discovery. Ingress & Ingress Controller. PV, PVC, StorageClass. ConfigMaps & Secrets.

Kubernetes Services & Networking — ClusterIP, NodePort, LoadBalancer, Ingress

1. Kubernetes Service Types

A Service provides a stable network endpoint (IP + DNS name) for a group of Pods. It uses label selectors to find target Pods.

Service Traffic Flow:
  Client ──► Service (ClusterIP: 10.96.1.100) ──► Pod 1
                                                ──► Pod 2
                                                ──► Pod 3
  kube-proxy manages iptables/IPVS rules for load balancing
Service TypeScopeUse caseAccess
ClusterIPInternal onlyDefault, service-to-service communicationOnly within the cluster
NodePortExternal via node IPDev/test, direct access via nodeNodeIP:30000-32767
LoadBalancerExternal via cloud LBProduction on AWS/GCP/AzureExternal IP from cloud provider
ExternalNameCNAME redirectConnect to external services by DNSReturns CNAME record

Exam tip: ClusterIP is the default — if the question says "service accessible within the cluster," that's ClusterIP. If the question asks "expose to the internet," it's LoadBalancer.

2. CoreDNS & Service Discovery

DNS Resolution in Kubernetes:
  my-service.my-namespace.svc.cluster.local
  ─────────  ────────────  ───  ─────────────
  Service     Namespace    Type  Cluster domain

  Pod in same namespace: curl http://my-service:8080
  Pod in different namespace: curl http://my-service.other-ns:8080

CoreDNS is a CNCF graduated project, the default DNS server in Kubernetes. It automatically creates DNS records for Services and Pods.

3. Ingress & Ingress Controller

Ingress manages external HTTP/HTTPS access to services via host/path rules. Requires an Ingress Controller (nginx, traefik, HAProxy).

Ingress Routing:
  Client request: https://app.example.com/api
                        │
                 ┌──────▼──────┐
                 │   Ingress   │
                 │  Controller │
                 │   (nginx)   │
                 └──────┬──────┘
           ┌────────────┼────────────┐
     /api → Service A   /web → Service B   /docs → Service C

4. Storage — PV, PVC, StorageClass

Storage Architecture:
  Pod
   │ volumeMounts: /data
   ▼
  PVC (PersistentVolumeClaim)  ← "I want 10Gi ReadWriteOnce"
   │ bound
   ▼
  PV  (PersistentVolume)       ← "Here is 10Gi from AWS EBS"
   │ provisioned by
   ▼
  StorageClass                 ← "auto-provision EBS gp3"
ConceptRoleCreated by
PV (PersistentVolume)Actual storage resourceAdmin or dynamic (StorageClass)
PVC (PersistentVolumeClaim)Pod requests storageDeveloper
StorageClassAuto-provision PVs based on demandAdmin

Access Modes

ModeAbbreviationMeaning
ReadWriteOnceRWO1 node can mount read-write
ReadOnlyManyROXMany nodes mount read-only
ReadWriteManyRWXMany nodes mount read-write

5. ConfigMap & Secret

ResourceUsed forEncodingMounting options
ConfigMapNon-sensitive config (DB_HOST, LOG_LEVEL)Plain textenv var, volume file
SecretSensitive data (password, API key, TLS cert)Base64 (not encrypted by default!)env var, volume file

Exam tip: Secrets are base64-encoded, not encrypted by default. To actually encrypt, you need to enable Encryption at Rest. KCNA may ask about the distinction between encoding and encryption.

6. Cheat Sheet

Exam questionAnswer
Default Service type?ClusterIP
Service accessed from the internet?LoadBalancer
L7 HTTP routing?Ingress
K8s DNS server?CoreDNS
Multiple nodes mounting same volume read-write?ReadWriteMany (RWX)
Auto-provision PVs?StorageClass
Secrets are encrypted?No — base64 encoded only, encryption at rest is separate

7. Practice Questions

Q1: A development team needs to expose their Kubernetes Service to external traffic on a cloud provider. Which Service type should they use?

  • A) ClusterIP
  • B) NodePort
  • C) LoadBalancer ✓
  • D) ExternalName

Explanation: LoadBalancer type creates an external load balancer via the cloud provider (AWS ELB, GCP LB, Azure LB), automatically assigning a public IP for external access.

Q2: What is the full DNS name of a Service called 'payment' in the 'production' namespace?

  • A) payment.production
  • B) payment.production.svc.cluster.local ✓
  • C) payment.svc.production.local
  • D) production.payment.cluster.svc

Explanation: Kubernetes DNS format: <service>.<namespace>.svc.cluster.local. This is an auto-created A record by CoreDNS.

Q3: An application requires shared storage that multiple Pods on different nodes can read and write. Which access mode is needed?

  • A) ReadWriteOnce (RWO)
  • B) ReadOnlyMany (ROX)
  • C) ReadWriteMany (RWX) ✓
  • D) ReadWriteOncePod

Explanation: RWX (ReadWriteMany) allows multiple nodes to mount the volume for both reading and writing. Typically requires network storage like NFS, EFS, or CephFS. Block storage (EBS, GCP PD) usually only supports RWO.