From what I understand, when a POD talks to a Service the IP tables have been updated by a CNI provider (this may be specific to some but not all CNI providers). The iptables have basically provided a virtual IP that then round robins or distributes (somehow) to backend ephemeral pods. Those pods may live on the same host or another host in the cluster. At this point (again based on the CNI) conntrack is used to keep src and dst straight as it remaps the svc-ip to the dest-ip of the POD. What I'm wondering though, is if the dest pod is on the same host, I'm not certain how it is routed on the return path. I would suspect via the service still and then possibly using conntrack for the return path.
Does kubernetes use conntrack twice when a pod talks to a pod through a service where the destination pod is on the same host?