The mechanism
Pods are replaceable, so clients should not depend on one Pod IP. A Service supplies a stable discovery and access abstraction. For selector-based Services, control-plane components track matching Pods through EndpointSlices. The data plane uses the relevant endpoint information to route traffic.
A selector is a set of label conditions, not a reference to a Deployment name. A Service can exist with no matching ready endpoints. In that case DNS may resolve and the Service object may look healthy while requests still fail.
Separate service discovery, endpoint selection and packet delivery when debugging. Each can fail independently. The exact data-plane implementation depends on the cluster; do not assume every distribution uses the same proxy mode.
Worked example
This offline Service manifest matches the Deployment labels from chapter 6. Port 80 is the Service port; 8080 is the target application port. The application must actually listen there. The handbook does not apply this object.
apiVersion: v1
kind: Service
metadata:
name: parcelops
namespace: handbook-lab
spec:
selector:
app: parcelops
ports:
- name: http
port: 80
targetPort: 8080
type: ClusterIP
Practice: predict, inspect, explain
Offline exercise. Create three synthetic Pods: a ready Pod labelled parcelops, an unready matching Pod and a ready Pod labelled another app. Predict which addresses should normally serve the Service. Change the selector to a misspelling and explain the resulting empty endpoint set.
Expected observation: successful name resolution is insufficient to prove a working backend. For an optional approved lab, inspect the Service and its EndpointSlices before testing packets. Keep observations and expected behavior separate, particularly for terminating endpoints and specialized traffic policies.
Troubleshooting and trade-offs
If a Service has no useful endpoints, check labels, namespace and readiness first. If endpoints are correct but connections fail, verify target port, process binding and network policy. A containerPort declaration documents a port; it does not make a process listen. Avoid changing the Service type to expose the application externally as a debugging shortcut.
Interview practice
Does a Service selector select a Deployment?
It selects Pods by labels. The Deployment may create those Pods, but the Service does not target the Deployment object itself.
Why inspect EndpointSlices?
They show the backend addresses and conditions associated with the Service, helping separate discovery and selector problems from packet-routing or application failures.
Completion check
Explain a resolvable Service with zero ready backends and locate the first useful diagnostic evidence.
Sources and version notes
Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.
- Official documentation: Service
- Official documentation: Endpoint slices
- Official documentation: Liveness readiness startup probes
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.