---
tags:
- k8s
- l1
- flashcard-deck
- k8s-networking
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Networking](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
k8s-networking/a1b2c3d4e5f6	k8s-networking	easy	k8s, networking, pods	What is the fundamental rule of the Kubernetes pod networking model?	Every pod gets its own IP address, and all pods can communicate with all other pods without NAT (flat network model).\n\nRemember: K8s networking rule: every pod gets a unique IP. Pod-to-pod across nodes without NAT.	training/library/topics/k8s-networking/primer.md
k8s-networking/b2c3d4e5f6a7	k8s-networking	easy	k8s, networking, services	What are the four Kubernetes Service types?	ClusterIP (internal only, default), NodePort (static port on every node 30000-32767), LoadBalancer (provisions external LB), and ExternalName (DNS CNAME redirect, no proxying).\n\nRemember: K8s networking rule: every pod gets a unique IP. Pod-to-pod across nodes without NAT.	training/library/topics/k8s-networking/primer.md
k8s-networking/c3d4e5f6a7b8	k8s-networking	easy	k8s, networking, dns	What DNS record format does Kubernetes create for a ClusterIP Service?	<service-name>.<namespace>.svc.cluster.local — for example, backend-api.production.svc.cluster.local.\n\nRemember: K8s DNS: `<svc>.<ns>.svc.cluster.local`. CoreDNS runs in kube-system.\n\nUnder the hood: CoreDNS auto-discovers Services. Pod /etc/resolv.conf points to it.\n\nFun fact: CoreDNS replaced kube-dns in K8s 1.13 (2018). It is written in Go and uses a plugin architecture.\n\nRemember: K8s DNS format: <svc>.<ns>.svc.cluster.local. Within the same namespace, just <svc> works thanks to search domains.	training/library/topics/k8s-networking/primer.md
k8s-networking/d4e5f6a7b8c9	k8s-networking	easy	k8s, networking, cni	What is the role of a CNI plugin in Kubernetes?	The CNI (Container Network Interface) plugin is called by the kubelet to set up and tear down pod network namespaces, assigning IPs and configuring routes so pods can communicate across nodes.\n\nRemember: CNI plugins: Calico (policy), Cilium (eBPF), Flannel (simple). "CCF."\n\nGotcha: No CNI = pods on different nodes can't talk. First install after cluster init.	training/library/topics/k8s-networking/primer.md
k8s-networking/e5f6a7b8c9d0	k8s-networking	medium	k8s, networking, kube-proxy	What is the key difference between kube-proxy iptables mode and IPVS mode?	iptables mode rewrites the full rule chain on every Service change (O(n) updates, slow at scale), while IPVS uses kernel-level hash tables for O(1) lookup performance and better scalability beyond ~5,000 Services.\n\nRemember: K8s networking rule: every pod gets a unique IP. Pod-to-pod across nodes without NAT.	training/library/topics/k8s-networking/primer.md
k8s-networking/f6a7b8c9d0e1	k8s-networking	medium	k8s, networking, dns, statefulsets	What is a headless Service and when is it used?	A headless Service has clusterIP: None and returns individual pod IPs directly via DNS instead of a single virtual IP. It is essential for StatefulSets where clients need to address specific pods (e.g., cassandra-0.cassandra.default.svc.cluster.local).\n\nRemember: K8s networking rule: every pod gets a unique IP. Pod-to-pod across nodes without NAT.	training/library/topics/k8s-networking/primer.md
k8s-networking/a7b8c9d0e1f2	k8s-networking	medium	k8s, networking, network-policy	What happens when you apply a NetworkPolicy with an empty podSelector and policyTypes: [Ingress] but no ingress rules?	It creates a default-deny-ingress policy that blocks ALL inbound traffic to every pod in the namespace, since the empty podSelector matches all pods and no ingress rules means nothing is allowed.\n\nRemember: Ingress routes HTTP/HTTPS by hostname/path. L7 only. Use NodePort/LB for L4.\n\nGotcha: Without an Ingress Controller deployed, Ingress resources have no effect.	training/library/topics/k8s-networking/primer.md
k8s-networking/b8c9d0e1f2a3	k8s-networking	medium	k8s, networking, network-policy	When writing a NetworkPolicy that restricts egress, why must you explicitly allow DNS traffic?	Without an explicit egress rule allowing UDP/TCP port 53, pods cannot resolve Service names via CoreDNS. This is the most common NetworkPolicy mistake — blocking egress silently breaks DNS-based service discovery.\n\nRemember: K8s DNS: `<svc>.<ns>.svc.cluster.local`. CoreDNS runs in kube-system.\n\nUnder the hood: CoreDNS auto-discovers Services. Pod /etc/resolv.conf points to it.	training/library/topics/k8s-networking/primer.md
k8s-networking/d0e1f2a3b4c5	k8s-networking	hard	k8s, networking, debugging	A pod can reach a Service by ClusterIP but not by DNS name. What is the most likely cause and how do you diagnose it?	Most likely a DNS search domain issue in /etc/resolv.conf. Diagnose: kubectl exec -it pod -- cat /etc/resolv.conf to check nameserver and search domains, kubectl exec -it pod -- nslookup kubernetes.default to test basic DNS, then check CoreDNS pods with kubectl get pods -n kube-system -l k8s-app=kube-dns.\n\nRemember: K8s DNS: `<svc>.<ns>.svc.cluster.local`. CoreDNS runs in kube-system.\n\nUnder the hood: CoreDNS auto-discovers Services. Pod /etc/resolv.conf points to it.	training/library/topics/k8s-networking/primer.md
k8s-networking/e1f2a3b4c5d6	k8s-networking	hard	k8s, networking, debugging, tcpdump	How do you capture network traffic inside a running pod without modifying its image?	Use an ephemeral debug container (K8s 1.23+): kubectl debug -it problem-pod --image=nicolaka/netshoot --target=app-container -- tcpdump -i eth0 -nn port 8080. This attaches a debug container to the pod's network namespace without restarting the pod.\n\nRemember: K8s networking rule: every pod gets a unique IP. Pod-to-pod across nodes without NAT.	training/library/topics/k8s-networking/primer.md
k8s-networking/f2a3b4c5d6e7	k8s-networking	hard	k8s, networking, ingress	An Ingress resource shows correct rules but external traffic returns 404. What are the three most likely causes?	1) Ingress controller not installed or not running. 2) ingressClassName does not match the controller's IngressClass. 3) Backend Service has no ready endpoints — check kubectl get endpoints to verify pods are running and selected.\n\nRemember: Ingress routes HTTP/HTTPS by hostname/path. L7 only. Use NodePort/LB for L4.\n\nGotcha: Without an Ingress Controller deployed, Ingress resources have no effect.	training/library/topics/k8s-networking/primer.md
k8s-networking/a3b4c5d6e7f8	k8s-networking	hard	k8s, networking, cni, cilium	How does Cilium differ from traditional CNI plugins like Flannel?	Cilium uses eBPF programs in the Linux kernel for networking, load balancing, and security. It can replace kube-proxy entirely and provides deep network flow visibility, while Flannel only provides basic VXLAN overlay with no network policy support.\n\nRemember: CNI plugins: Calico (policy), Cilium (eBPF), Flannel (simple). "CCF."\n\nGotcha: No CNI = pods on different nodes can't talk. First install after cluster init.	training/library/topics/k8s-networking/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [API Gateways & Ingress](../../../../library/topics/api-gateways/index.md) (Topic Pack, L2) — Kubernetes Networking
- [Case Study: CNI Broken After Restart](../../../../library/case-studies/kubernetes_ops/cni-broken-after-restart/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Canary Deploy Routing to Wrong Backend — Ingress Misconfigured](../../../../library/case-studies/cross-domain/canary-deploy-wrong-backend-ingress/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: CoreDNS Timeout Pod DNS](../../../../library/case-studies/kubernetes_ops/coredns-timeout-pod-dns/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Grafana Dashboard Empty — Prometheus Blocked by NetworkPolicy](../../../../library/case-studies/cross-domain/grafana-empty-prometheus-networkpolicy/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Service Mesh 503s — Envoy Misconfigured, RBAC Policy](../../../../library/case-studies/cross-domain/service-mesh-503-envoy-rbac/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Service No Endpoints](../../../../library/case-studies/kubernetes_ops/service-no-endpoints/README.md) (Case Study, L1) — Kubernetes Networking
- [Cilium & eBPF Networking](../../../../library/topics/cilium/index.md) (Topic Pack, L2) — Kubernetes Networking
- [Deep Dive: Kubernetes Networking](../../../../library/deep-dives/kubernetes.networking.md) (deep_dive, L2) — Kubernetes Networking
- Docker Networking Flashcards *(CLI)* (flashcard_deck, L1) — Kubernetes Networking

<!-- wiki:related:end -->
