Q: What is the difference between a Kubernetes Service and an Ingress? When would you use each one?
Clear, senior-level distinction between Kubernetes Services (ClusterIP, NodePort, LoadBalancer) and Ingress controllers with real-world architecture examples.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Kubernetes Service Types & Layer 4 Mechanics
A Service creates a static virtual IP (ClusterIP) managed by kube-proxy iptables or IPVS rules: - **ClusterIP**: Exposes the service internally inside the cluster (default). - **NodePort**: Opens a dedicated static port (30000-32767) on all node IP addresses. - **LoadBalancer**: Provisions a cloud provider Layer 4 load balancer (AWS NLB / Azure Basic LB). Creating 50 LoadBalancer Services provisions 50 expensive cloud load balancers.
apiVersion: v1
kind: Service
metadata:
name: payment-service
spec:
type: ClusterIP
selector:
app: payment
ports:
- port: 80
targetPort: 8080
Kubernetes Ingress & Layer 7 Routing Mechanics
Ingress is a set of routing rules evaluated by an Ingress Controller (NGINX, Traefik, AWS ALB Controller). It consolidates routing for multiple microservices behind a single public cloud Load Balancer and single public IP address.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: main-ingress
spec:
rules:
- host: api.example.com
http:
paths:
- path: /payments
pathType: Prefix
backend:
service:
name: payment-service
port:
number: 80
- path: /users
pathType: Prefix
backend:
service:
name: user-service
port:
number: 80
Key Capabilities Comparison Table
Feature trade-offs: - **Protocols**: Service handles TCP, UDP, SCTP. Ingress handles HTTP, HTTPS, WebSockets, gRPC. - **SSL Termination**: Ingress terminates SSL/TLS and manages certs (cert-manager). Services do not terminate SSL. - **Path Routing**: Ingress routes by domain and URI path (`/payments` vs `/users`). Service knows nothing about HTTP paths.
When to Use Each
- Use **ClusterIP Service** for internal pod-to-pod communication. - Use **Ingress** for external web/API traffic needing domain routing, SSL termination, and rate limiting. - Use **LoadBalancer Service** when exposing non-HTTP Layer 4 traffic (database proxies, gaming UDP servers, MQTT brokers).
- A Service operates at Layer 4, providing stable cluster-internal virtual IPs for dynamic pods.
- An Ingress operates at Layer 7, providing HTTP/HTTPS routing, SSL termination, and path-based routing.
- Use Ingress to route traffic to multiple internal ClusterIP services behind a single cloud load balancer.
- Use Type LoadBalancer directly only for non-HTTP Layer 4 workloads like TCP gaming or MQTT.