Breaking A Kubernetes Service in Three Ways And Examining The Raw Packets
A Kubernetes service is simple conceptually. You get a stable endpoint which load balances traffic across a pool of backend pods. Under the hood it’s implemented by standard Linux kernel features – DNAT iptables rules, virtual bridges, and veth pairs. There’s no separate proxy process implementing the logic for a Kubernetes service, so when it breaks, the errors are just going to be standard Linux…