Q: A pod is `Running` but your app is not reachable via the Service. What do you check?
1. Check pod labels vs service selector — kubectl describe service <name> shows the selector. kubectl get pod --show-labels shows pod lab...
#Kubernetes #Troubleshooting & Debugging #L2 #Container Orchestration #K8s
🎙️ Candidate Opening & Architectural Context
""In our production Kubernetes clusters running microservices on EKS/AKS, this was a classic operational challenge. The interviewer is testing: Service-to-pod connectivity debugging.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
- Check pod labels vs service selector —
kubectl describe serviceshows the selector.kubectl get pod --show-labelsshows pod labels. They must match exactly. - Check endpoints —
kubectl get endpoints. If it shows, the selector doesn't match any pod. - Check if the pod is Ready — even if Running, if the readiness probe fails, the pod is removed from endpoints.
2️⃣
Remediation & Permanent Safeguards
Execute the resolution runbook and verify workload health:
- Check the port mapping — service
targetPortmust match the container's listening port. - Test from inside the cluster —
kubectl exec -itto isolate if it's a network policy or external routing issue.-- curl :
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Check pod labels vs service selector — kubectl describe service shows the selector. kubectl get pod --show-labels shows pod label."
⚡ 60-Second Elevator Pitch Talking Points
- Check pod labels vs service selector — kubectl describe service shows the selector. kubectl get ...
- Check endpoints — kubectl get endpoints . If it shows , the selector doesn't match any pod.
- Check if the pod is Ready — even if Running, if the readiness probe fails, the pod is removed fro...
Advertisement