Kubernetes Core Concepts Lab (Interactive)
Crash a pod, watch ReplicaSet reconciliation reissue a new IP, and route traffic through the Service abstraction you pick. Explore control-plane components, ephemeral pod IPs, kube-proxy iptables versus IPVS, and ClusterIP through Ingress exposure.
Cluster Anatomy: Control Plane, Pods, Services & Ingress
Crash a pod, watch the ReplicaSet reconciliation diff, and route 120 QPS through the Service abstraction you choose.
route: 120 QPS → https://api.example.com/orders → ClusterIP VIP
Layer 7 host/path routing with TLS termination (cert-manager) on ONE NGINX/Envoy controller fan-out to many Services.
EndpointSlice: 3 ready backends · traffic even → 40 rps/pod
IPVS: kernel hash-table O(1) · per-packet lookup 0.004 ms · Constant latency at 10k+ Services
How It Works Under the Hood
Kubernetes reconciles a declarative desired state: kube-apiserver is the sole gatekeeper to the Raft-backed etcd store, the scheduler filters and scores nodes, and controller-manager loops drive actual toward declared. Pods are ephemeral, so when one dies the ReplicaSet controller recreates it with a brand new IP, which is exactly why Services exist. A Service pins a stable virtual IP and DNS name and load-balances to healthy endpoints tracked by EndpointSlices. NodePort, LoadBalancer and Ingress then decide how much of the cluster is exposed, and kube-proxy in IPVS mode uses kernel hash tables to route at scale.
Core Architectural Principles
- Only kube-apiserver reads/writes etcd; scheduler and controllers communicate exclusively through the API server.
- A crashed pod is replaced with a new IP; the Service VIP and EndpointSlice keep the network identity durable.
- IPVS gives O(1) kernel-hash routing while iptables rule chains degrade O(N) as service count explodes.
Frame Services as the answer to ephemeral pod IPs: a Deployment keeps replica count, but IPs churn on every restart, so clients hit a ClusterIP VIP backed by EndpointSlices. Walk the control plane top-down: apiserver as stateless hub, etcd as Raft consensus source of truth, scheduler filtering then scoring, controllers reconciling. Distinguish ClusterIP, NodePort, LoadBalancer and Layer-7 Ingress to show you can design traffic ingress, and cite IPVS for large clusters.
Declarative self-healing and unified scheduling erase ClickOps errors, at the price of real complexity across RBAC, CNI, and control-plane operations.