Networking: DNS, Services, routing and VPC IPs
Prerequisites: 01-control-loops, 02-objects
03 / Internal service discovery
Scroll the diagram sideways for readable labels.
ALB control path ≠ request path
Scroll the diagram sideways for readable labels.
Learning objective and mental model verified
A Service selects backend Pods and offers stable access while Pod endpoints change. EndpointSlices describe the backend endpoints. Cluster DNS provides service discovery. The forwarding implementation may use kube-proxy or another dataplane; a Service object is not itself a running proxy process.
[S05]AWS integration verified
On standard EKS, the AWS Load Balancer Controller can create an ALB for Ingress and an NLB for a LoadBalancer Service. The diagram uses ALB IP targets, where request traffic reaches Pod IPs. Instance targets take a different path through node ports. Auto Mode has managed load-balancing integration with its own configuration contract.
[S20] [S30] [S15]VPC mechanics verified
The Amazon VPC CNI assigns VPC addresses to Pods on AWS infrastructure. Plan workload and cluster subnet capacity, including temporary upgrade and scale-out needs. A private API endpoint requires an administration path from the VPC or a connected network; it does not automatically provide internet egress for workloads.
[S34] [S19]Worked example, decision and pitfall synthesis
For the illustrative quote API, expose only the application route through an ALB and keep worker nodes in private subnets. Check DNS, ready endpoints, ALB target health, security groups, enforced policy and outbound dependencies independently. An empty Service selector or IP shortage can break traffic even while EC2 instances appear healthy.
[S05] [S19] [S20]Further improvement synthesis
Track available subnet addresses and target-registration delay alongside CPU and memory. Test the complete request path rather than treating “Ingress exists” as proof of reachability.
[S19] [S20]Check yourself: Does a client HTTP request pass through the Kubernetes API server?
Normally no. The API configures desired routing; application requests travel through the selected network and load-balancer dataplane.