I am trying to understand Kubernetes networking and came across the following snippet...in GKE network documentation...GKE - Networking. This says...
Kubernetes manages connectivity among Pods and Services using the kube-proxy component, which runs on each node. kube-proxy, which is not an in-line proxy, but an egress-based load-balancing controller, watches the Kubernetes API server and continually maps the ClusterIP to healthy Pods by adding and removing destination NAT (DNAT) rules to the node's iptables subsystem. When a container running in a Pod sends traffic to a Service's ClusterIP, the node selects a Pod at random and routes the traffic to that Pod.
I have two questions on this...
- Assume there are 5 nodes out of which 3 nodes are part of service. Now one of the pod (from node that is not part of service) wants to communicate with service... It finds service by FQDN of service.. Does the kube-proxy with in this node send traffic to one of the pod that is part of service ?
- Also, it says kube-proxy load balances the traffic across the full set of pods... how is that done ? If there is one single node that takes of traffic routing, it understand which one is the next node/pod to get traffic.. but Service picks nodes(with in a service) randomly right ?
Can someone please clarify ?
Thanks in advance.