Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 07 / 30 · Connect the workload

Services and EndpointSlices

Follow stable service identity to the actual ready workload addresses.

4 min read + practiceWorked exerciseInterview practice

The mechanism

Pods are replaceable, so clients should not depend on one Pod IP. A Service supplies a stable discovery and access abstraction. For selector-based Services, control-plane components track matching Pods through EndpointSlices. The data plane uses the relevant endpoint information to route traffic.

A selector is a set of label conditions, not a reference to a Deployment name. A Service can exist with no matching ready endpoints. In that case DNS may resolve and the Service object may look healthy while requests still fail.

Separate service discovery, endpoint selection and packet delivery when debugging. Each can fail independently. The exact data-plane implementation depends on the cluster; do not assume every distribution uses the same proxy mode.

Service name
Selector
EndpointSlices
Ready Pod address

Worked example

This offline Service manifest matches the Deployment labels from chapter 6. Port 80 is the Service port; 8080 is the target application port. The application must actually listen there. The handbook does not apply this object.

apiVersion: v1
kind: Service
metadata:
  name: parcelops
  namespace: handbook-lab
spec:
  selector:
    app: parcelops
  ports:
    - name: http
      port: 80
      targetPort: 8080
  type: ClusterIP

Practice: predict, inspect, explain

Offline exercise. Create three synthetic Pods: a ready Pod labelled parcelops, an unready matching Pod and a ready Pod labelled another app. Predict which addresses should normally serve the Service. Change the selector to a misspelling and explain the resulting empty endpoint set.

Expected observation: successful name resolution is insufficient to prove a working backend. For an optional approved lab, inspect the Service and its EndpointSlices before testing packets. Keep observations and expected behavior separate, particularly for terminating endpoints and specialized traffic policies.

Troubleshooting and trade-offs

If a Service has no useful endpoints, check labels, namespace and readiness first. If endpoints are correct but connections fail, verify target port, process binding and network policy. A containerPort declaration documents a port; it does not make a process listen. Avoid changing the Service type to expose the application externally as a debugging shortcut.

Interview practice

Does a Service selector select a Deployment?

It selects Pods by labels. The Deployment may create those Pods, but the Service does not target the Deployment object itself.

Why inspect EndpointSlices?

They show the backend addresses and conditions associated with the Service, helping separate discovery and selector problems from packet-routing or application failures.

Completion check

Explain a resolvable Service with zero ready backends and locate the first useful diagnostic evidence.

Sources and version notes

Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.