⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE Kubernetes Kubernetes Networking & Core Architecture Core Architecture

Q: What is kube-proxy, how does it handle Service routing, and what are the differences between iptables, IPVS, and eBPF mode?

Deep architectural explanation of how kube-proxy programs node-level networking to route ClusterIP service traffic to backend Pods using iptables, IPVS, and modern eBPF.

#Kubernetes #kube-proxy #iptables #IPVS #eBPF #Networking
🎙️ Candidate Opening & Architectural Context
"kube-proxy is a network proxy that runs on each worker node in a Kubernetes cluster. It does not actually proxy traffic in user-space anymore; instead, it watches the Kubernetes API server for Service and EndpointSlice changes and programs kernel packet forwarding rules."
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1

iptables Mode Mechanics & O(n) Scaling Limits

In iptables mode, kube-proxy creates chains in the NAT table. For every Service, it adds sequential rules using the statistic module for random load balancing. However, iptables evaluates rules sequentially—in clusters with 5,000+ services, packet evaluation overhead causes severe CPU spikes and latency.

iptables -t nat -L KUBE-SERVICES -n -v
iptables -t nat -L KUBE-SVC-XYZ -n -v
2

IPVS Mode & O(1) Hash Table Routing

IPVS (IP Virtual Server) is a transport-layer load balancer built into the Linux kernel. It uses hash tables (O(1) lookup complexity) that maintain consistent throughput regardless of whether the cluster has 10 services or 50,000 services.

3

eBPF (Cilium / Kube-Proxy Replacement)

Modern CNI solutions like Cilium completely replace kube-proxy using eBPF programs attached to Linux socket layers (sockops) and tc (traffic control), bypassing the entire netfilter/iptables subsystem for near-native wire speeds.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"kube-proxy translates virtual ClusterIPs to pod IPs. iptables is standard but O(n); IPVS is O(1) for large clusters; eBPF bypasses netfilter entirely."
⚡ 60-Second Elevator Pitch Talking Points
  • kube-proxy watches Services and EndpointSlices to program Linux kernel forwarding tables.
  • iptables mode: uses sequential rule evaluation; fine for small clusters but suffers O(n) latency at scale.
  • IPVS mode: uses in-kernel hash tables with O(1) lookup performance for enterprise-scale clusters.
  • eBPF mode (Cilium): bypasses iptables/netfilter completely at the socket layer for maximum throughput.
Advertisement
Want more Kubernetes scenarios?
Explore our complete collection of scenario-based Kubernetes interview runbooks.
Browse All Kubernetes Questions →

📚 Related Production Scenarios in Kubernetes