1. Service Types
Pods có IP tạm thời, bị xóa khi restart. Service cung cấp stable Virtual IP (ClusterIP) và load-balancing đến một nhóm Pods qua label selector.
| Type | Reachable From | Use Case | Real-world Example |
|---|---|---|---|
| ClusterIP | Cluster internal only | Backend microservices | Payment service → DB |
| NodePort | External via NodeIP:Port (30000-32767) | Dev/test access | Demo app on bare metal |
| LoadBalancer | External via cloud LB | Production apps on cloud | AWS/GCP internet traffic |
| ExternalName | CNAME alias for external service | Integrate external DNS | legacy-db.company.com |
External Traffic
│
▼
[LoadBalancer] ← cloud provider LB (AWS ELB, GCP)
│
[NodePort :30080] ← all nodes expose port 30080
│
[ClusterIP 10.96.5.3] ← virtual IP, iptables/IPVS routing
│
┌────┴────┐
[Pod A] [Pod B] ← matched by label selector
Exam tip: NodePort tự động tạo thêm ClusterIP. LoadBalancer tự động tạo thêm NodePort + ClusterIP. Mỗi type kế thừa type nhỏ hơn.
2. CoreDNS & Service Discovery
CoreDNS là DNS server mặc định trong Kubernetes cluster. Mỗi Service được đăng ký DNS record tự động.
DNS format: {service}.{namespace}.svc.cluster.local
Ví dụ:
Service "api" trong namespace "production":
→ api.production.svc.cluster.local
→ api.production.svc
→ api.production
→ api (chỉ trong cùng namespace)
| DNS Query | Resolves To | Works From |
|---|---|---|
api | Service ClusterIP | Same namespace only |
api.production | Service ClusterIP | Any namespace |
api.production.svc.cluster.local | Service ClusterIP | Any namespace (FQDN) |
3. Storage: PV, PVC, StorageClass
Storage lifecycle:
STATIC DYNAMIC
───── ───────
Admin creates → PersistentVolume StorageClass (provision template)
App requests → PersistentVolumeClaim → SC auto-provisions PV
Pod mounts → PVC as volume
| Concept | Vai trò | Ai tạo |
|---|---|---|
| PersistentVolume (PV) | Tài nguyên storage thực tế (NFS, EBS, GCE Disk) | Admin hoặc dynamic provisioner |
| PersistentVolumeClaim (PVC) | Request storage với size + access mode | Developer / App |
| StorageClass | Template tự động tạo PV khi có PVC | Admin |
Access Modes
| Mode | Abbrev | Ý nghĩa | Ví dụ |
|---|---|---|---|
| ReadWriteOnce | RWO | 1 node đọc+ghi | EBS volume, local disk |
| ReadOnlyMany | ROX | Nhiều nodes đọc | Static files on NFS |
| ReadWriteMany | RWX | Nhiều nodes đọc+ghi | NFS, EFS, GlusterFS |
| ReadWriteOncePod | RWOP | Chỉ 1 Pod (v1.22+) | Exclusive access needed |
Exam tip: AWS EBS chỉ hỗ trợ RWO. Nếu câu hỏi yêu cầu nhiều Pods ghi đồng thời, cần dùng NFS (RWX). StatefulSet thường dùng RWO với mỗi Pod có PVC riêng.
4. ConfigMap & Secret
| Resource | Dùng cho | Encoding | Inject vào Pod |
|---|---|---|---|
| ConfigMap | Config không nhạy cảm (URLs, flags, env files) | Plain text | Env var, volume file, CLI args |
| Secret | Data nhạy cảm (passwords, API keys, TLS certs) | Base64 (NOT encrypted by default) | Env var (không khuyến khích), volume mount |
Exam tip: Secret chỉ là base64 encoded, KHÔNG phải encrypted. Để encrypt Secret at rest, cần bật Encryption Configuration ở API Server. Câu hỏi hay dùng "encrypted" như distractor sai.
5. Cheat Sheet
| Câu hỏi exam | Đáp án |
|---|---|
| Expose app ra ngoài cluster trên cloud? | LoadBalancer (hoặc Ingress) |
| DNS name cho Service "db" trong ns "backend"? | db.backend.svc.cluster.local |
| Cần storage shared giữa nhiều Pods? | PV với access mode RWX |
| Tự động provision storage khi deploy? | StorageClass + PVC |
| Secret có bị encrypt by default? | Không, chỉ base64 |
6. Practice Questions
Q1: A developer wants to access a backend database Service named "orders-db" from a different namespace called "frontend". Which DNS name should they use?
- A) orders-db
- B) orders-db.default.svc.cluster.local
- C) orders-db.backend.svc.cluster.local ✓
- D) backend.orders-db.cluster.local
Explanation: Cross-namespace DNS requires the full format: {service}.{namespace}.svc.cluster.local. Short name "orders-db" only works within the same namespace.
Q2: Which Service type automatically creates a ClusterIP AND a NodePort?
- A) ClusterIP
- B) NodePort
- C) LoadBalancer ✓
- D) ExternalName
Explanation: LoadBalancer is a superset — it creates ClusterIP + NodePort + cloud load balancer. NodePort includes ClusterIP, but ClusterIP is standalone with no external access.
Q3: A Secret contains a database password. A developer claims the password is "encrypted". Is this claim accurate?
- A) Yes, Kubernetes Secrets are encrypted with AES
- B) No, Secrets are only base64 encoded unless Encryption Configuration is enabled ✓
- C) Yes, Secrets are encrypted using etcd's built-in encryption
- D) No, Secrets are stored in plain text
Explanation: By default, Secrets are stored as base64-encoded strings in etcd — which is NOT encryption. Administrators must configure EncryptionConfiguration on the API server to enable encryption at rest.