Part 3 · Fundamentals

Networking: DNS, Services, routing and VPC IPs

Prerequisites: 01-control-loops, 02-objects

03 / Internal service discovery

Cluster DNS resolves a Service name, and the client sends to a stable Service address which forwards to one of two ready endpoints.

Scroll the diagram sideways for readable labels.

DNS resolution precedes the illustrated request. Service forwarding depends on the cluster dataplane implementation; EndpointSlices describe the backing endpoints. [S05]

ALB control path ≠ request path

A dashed control path leads from routing objects through the AWS controller to ALB configuration. A solid request path runs client to ALB to Pod IP.

Scroll the diagram sideways for readable labels.

Logical routing example with IP targets. In instance-target mode traffic instead reaches a node’s NodePort. Auto Mode manages its load balancing integration separately. [S20] [S30] [S15]

Learning objective and mental model verified

A Service selects backend Pods and offers stable access while Pod endpoints change. EndpointSlices describe the backend endpoints. Cluster DNS provides service discovery. The forwarding implementation may use kube-proxy or another dataplane; a Service object is not itself a running proxy process.

[S05]

AWS integration verified

On standard EKS, the AWS Load Balancer Controller can create an ALB for Ingress and an NLB for a LoadBalancer Service. The diagram uses ALB IP targets, where request traffic reaches Pod IPs. Instance targets take a different path through node ports. Auto Mode has managed load-balancing integration with its own configuration contract.

[S20] [S30] [S15]

VPC mechanics verified

The Amazon VPC CNI assigns VPC addresses to Pods on AWS infrastructure. Plan workload and cluster subnet capacity, including temporary upgrade and scale-out needs. A private API endpoint requires an administration path from the VPC or a connected network; it does not automatically provide internet egress for workloads.

[S34] [S19]

Worked example, decision and pitfall synthesis

For the illustrative quote API, expose only the application route through an ALB and keep worker nodes in private subnets. Check DNS, ready endpoints, ALB target health, security groups, enforced policy and outbound dependencies independently. An empty Service selector or IP shortage can break traffic even while EC2 instances appear healthy.

[S05] [S19] [S20]

Further improvement synthesis

Track available subnet addresses and target-registration delay alongside CPU and memory. Test the complete request path rather than treating “Ingress exists” as proof of reachability.

[S19] [S20]
Keep this: Separate the configuration path from the request path, and treat IP space as a capacity constraint.
Check yourself: Does a client HTTP request pass through the Kubernetes API server?

Normally no. The API configures desired routing; application requests travel through the selected network and load-balancer dataplane.

Sources & further reading

  1. [S05] Service

    Kubernetes · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Service selection, stable access and EndpointSlices

    Read the linked primary source for implementation details and current constraints.

  2. [S15] EKS Auto Mode

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Managed compute, networking, load balancing and block storage

    Read the linked primary source for implementation details and current constraints.

  3. [S19] VPC and subnet considerations

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Cluster subnets, private endpoint access, upgrade IP headroom

    Read the linked primary source for implementation details and current constraints.

  4. [S20] AWS Load Balancer Controller

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Ingress to ALB and Service LoadBalancer to NLB integration

    Read the linked primary source for implementation details and current constraints.

  5. [S30] AWS Fargate for EKS

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: No DaemonSets, privileged containers or GPUs; private subnets and IP targets

    Read the linked primary source for implementation details and current constraints.

  6. [S34] Amazon VPC CNI

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: VPC private addresses per Pod and Auto Mode networking ownership

    Read the linked primary source for implementation details and current constraints.