# Exhaustive Service reference (v1). # A Service is a stable virtual endpoint in front of pods: one DNS name and # one cluster IP that load-balances to the currently Ready pods behind it. # Pods come and go; the Service name (app-service.example.svc.cluster.local) # never changes. apiVersion: v1 kind: Service metadata: name: app-service namespace: example labels: app: app annotations: description: "exhaustive service example" spec: # selector: pods carrying these labels receive traffic. Empty selector = # no automatic endpoints (pair with a hand-written EndpointSlice to aim at # an external address - see endpointslice.yaml). selector: app: app ports: - name: http # protocol: TCP (default), UDP, or SCTP. Each port entry needs one. protocol: TCP # port: the port clients connect to on the Service IP. port: 80 # targetPort: the port on the pod. Number or container port NAME # (names decouple the Service from container port renumbering). # Omit when it equals `port`. targetPort: http # nodePort: fixed node port for type NodePort/LoadBalancer (range # 30000-32767). Omit for auto-assignment. # nodePort: 30080 # appProtocol: protocol hint for the payload (http, https, grpc, h2c, # ws...). Used by meshes and LBs, ignored by plain kube-proxy routing. appProtocol: http - name: metrics protocol: TCP port: 9090 targetPort: 9090 # type: ClusterIP (default, internal VIP), NodePort (also open a fixed port # on every node), LoadBalancer (NodePort + cloud LB in front), # ExternalName (DNS alias, no proxying - see below). type: ClusterIP # clusterIP: pin the virtual IP. "None" makes the Service headless: no VIP, # DNS returns pod IPs directly (required base for StatefulSets). # clusterIP: None # clusterIPs / ipFamilies / ipFamilyPolicy: dual-stack control. # ipFamilies: [IPv4] (default), [IPv6], or [IPv4, IPv6]. # ipFamilyPolicy: SingleStack (default), PreferDualStack, RequireDualStack. # ipFamilies: # - IPv4 # ipFamilyPolicy: SingleStack # sessionAffinity: None (default, spread every connection) or ClientIP # (same client IP sticks to one pod). sessionAffinity: None # sessionAffinityConfig: stickiness TTL for ClientIP affinity. # sessionAffinityConfig: # clientIP: # timeoutSeconds: 10800 # publishNotReadyAddresses: send traffic to not-Ready pods too. Needed for # peer discovery where members must find each other before anyone is Ready. publishNotReadyAddresses: false # internalTrafficPolicy: Cluster (default, route to pods on any node) or # Local (only pods on the receiving node - preserves source IP, drops # traffic on nodes without local pods). internalTrafficPolicy: Cluster # --- NodePort / LoadBalancer extras (ignored by pure ClusterIP) --- # externalTrafficPolicy: Cluster (default) or Local. Local preserves the # client source IP but drops traffic arriving on nodes with no local pod. # externalTrafficPolicy: Cluster # healthCheckNodePort: fixed node port for the LB health check (Local # policy). Omit for auto-assignment. # healthCheckNodePort: 32111 # allocateLoadBalancerNodePorts: set false to skip node-port allocation on # a LoadBalancer (when the LB routes straight to pods). Default true. # allocateLoadBalancerNodePorts: true # loadBalancerIP: request a specific IP from the cloud provider. Provider # support varies; most now prefer annotations or IP pools. # loadBalancerIP: 203.0.113.10 # loadBalancerSourceRanges: client CIDRs allowed through the cloud LB. # Unset = world-open. This is the cloud firewall in front of the Service. # loadBalancerSourceRanges: # - 203.0.113.0/24 # loadBalancerClass: use a custom LB implementation instead of the cloud # default (e.g. MetalLB speaker). The named controller must be installed. # loadBalancerClass: example.com/custom-lb # trafficDistribution: hint how to prefer endpoints (PreferClose = same # zone first). Best-effort, kube-proxy dependent. # trafficDistribution: PreferClose # --- other types --- # externalIPs: extra IPs (already routed to nodes) that also serve this # Service. Traffic arriving there is proxied like ClusterIP traffic. # externalIPs: # - 203.0.113.20 # ExternalName type: no proxying at all - DNS CNAME to the target. # Ports are informational. Used to reference outside names under a stable # in-cluster name. # type: ExternalName # externalName: db.example.com