Chuyển đến nội dung chính

Bài 3: Services, Networking & Storage

Service types (ClusterIP, NodePort, LoadBalancer, ExternalName). CoreDNS và service discovery. PersistentVolume, PVC, ConfigMap, Secret.

Kubernetes Services và Networking — ClusterIP, NodePort, LoadBalancer

1. Service Types

Pods có IP tạm thời, bị xóa khi restart. Service cung cấp stable Virtual IP (ClusterIP) và load-balancing đến một nhóm Pods qua label selector.

TypeReachable FromUse CaseReal-world Example
ClusterIPCluster internal onlyBackend microservicesPayment service → DB
NodePortExternal via NodeIP:Port (30000-32767)Dev/test accessDemo app on bare metal
LoadBalancerExternal via cloud LBProduction apps on cloudAWS/GCP internet traffic
ExternalNameCNAME alias for external serviceIntegrate external DNSlegacy-db.company.com
External Traffic
      │
      ▼
[LoadBalancer]          ← cloud provider LB (AWS ELB, GCP)
      │
[NodePort :30080]       ← all nodes expose port 30080
      │
[ClusterIP 10.96.5.3]  ← virtual IP, iptables/IPVS routing
      │
 ┌────┴────┐
[Pod A] [Pod B]        ← matched by label selector

Exam tip: NodePort tự động tạo thêm ClusterIP. LoadBalancer tự động tạo thêm NodePort + ClusterIP. Mỗi type kế thừa type nhỏ hơn.

2. CoreDNS & Service Discovery

CoreDNS là DNS server mặc định trong Kubernetes cluster. Mỗi Service được đăng ký DNS record tự động.

DNS format: {service}.{namespace}.svc.cluster.local

Ví dụ:
  Service "api" trong namespace "production":
  → api.production.svc.cluster.local
  → api.production.svc
  → api.production
  → api  (chỉ trong cùng namespace)
DNS QueryResolves ToWorks From
apiService ClusterIPSame namespace only
api.productionService ClusterIPAny namespace
api.production.svc.cluster.localService ClusterIPAny namespace (FQDN)

3. Storage: PV, PVC, StorageClass

Storage lifecycle:
                    STATIC                     DYNAMIC
                    ─────                      ───────
  Admin creates  → PersistentVolume     StorageClass (provision template)
  App requests   → PersistentVolumeClaim → SC auto-provisions PV
  Pod mounts     → PVC as volume
ConceptVai tròAi tạo
PersistentVolume (PV)Tài nguyên storage thực tế (NFS, EBS, GCE Disk)Admin hoặc dynamic provisioner
PersistentVolumeClaim (PVC)Request storage với size + access modeDeveloper / App
StorageClassTemplate tự động tạo PV khi có PVCAdmin

Access Modes

ModeAbbrevÝ nghĩaVí dụ
ReadWriteOnceRWO1 node đọc+ghiEBS volume, local disk
ReadOnlyManyROXNhiều nodes đọcStatic files on NFS
ReadWriteManyRWXNhiều nodes đọc+ghiNFS, EFS, GlusterFS
ReadWriteOncePodRWOPChỉ 1 Pod (v1.22+)Exclusive access needed

Exam tip: AWS EBS chỉ hỗ trợ RWO. Nếu câu hỏi yêu cầu nhiều Pods ghi đồng thời, cần dùng NFS (RWX). StatefulSet thường dùng RWO với mỗi Pod có PVC riêng.

4. ConfigMap & Secret

ResourceDùng choEncodingInject vào Pod
ConfigMapConfig không nhạy cảm (URLs, flags, env files)Plain textEnv var, volume file, CLI args
SecretData nhạy cảm (passwords, API keys, TLS certs)Base64 (NOT encrypted by default)Env var (không khuyến khích), volume mount

Exam tip: Secret chỉ là base64 encoded, KHÔNG phải encrypted. Để encrypt Secret at rest, cần bật Encryption Configuration ở API Server. Câu hỏi hay dùng "encrypted" như distractor sai.

5. Cheat Sheet

Câu hỏi examĐáp án
Expose app ra ngoài cluster trên cloud?LoadBalancer (hoặc Ingress)
DNS name cho Service "db" trong ns "backend"?db.backend.svc.cluster.local
Cần storage shared giữa nhiều Pods?PV với access mode RWX
Tự động provision storage khi deploy?StorageClass + PVC
Secret có bị encrypt by default?Không, chỉ base64

6. Practice Questions

Q1: A developer wants to access a backend database Service named "orders-db" from a different namespace called "frontend". Which DNS name should they use?

  • A) orders-db
  • B) orders-db.default.svc.cluster.local
  • C) orders-db.backend.svc.cluster.local ✓
  • D) backend.orders-db.cluster.local

Explanation: Cross-namespace DNS requires the full format: {service}.{namespace}.svc.cluster.local. Short name "orders-db" only works within the same namespace.

Q2: Which Service type automatically creates a ClusterIP AND a NodePort?

  • A) ClusterIP
  • B) NodePort
  • C) LoadBalancer ✓
  • D) ExternalName

Explanation: LoadBalancer is a superset — it creates ClusterIP + NodePort + cloud load balancer. NodePort includes ClusterIP, but ClusterIP is standalone with no external access.

Q3: A Secret contains a database password. A developer claims the password is "encrypted". Is this claim accurate?

  • A) Yes, Kubernetes Secrets are encrypted with AES
  • B) No, Secrets are only base64 encoded unless Encryption Configuration is enabled ✓
  • C) Yes, Secrets are encrypted using etcd's built-in encryption
  • D) No, Secrets are stored in plain text

Explanation: By default, Secrets are stored as base64-encoded strings in etcd — which is NOT encryption. Administrators must configure EncryptionConfiguration on the API server to enable encryption at rest.