Kubernetes Networking->
Services, Ingress, Network Policies, DNS, CNI Plugin

Services:
Services used to make the set of pods available on network to interact with client. If we use deployment to run the app, it will create and destroy pods dynamically and we don't know how many pods are created and destroyed and what are the names of the pods. Each pod has it's own IP Address.
Assume we have an application, where a backend and frontend is running on different pods and we need to keep track of which IP address to connect to the frontend with backend.
Services in Kubernetes:
It help to expose groups of pods over a network. The service is to group the set of pod endpoints into a single resource. There are various ways to access grouping. By default it is stable cluster IP address. Which is used by client inside the cluster to contact with pod in the service.
creating a service-> suppose we have 8080 port for our application running on Pods and labelled as app.kubernetes.io/name=MyApp
apiVersion: v1
kind: Service
metadata:
name: my-service
spec:
selector:
app.kubernetes.io/name: MyApp
ports:
- protocol: TCP
port: 80
targetPort: 8080
The service targets TCP port 8080 on any Pod with the app.kubernetes.io/name: MyApp
Ingress:
It is an API object that manages external access to the service in cluster. Ingress provides load-balancing, name-based virtual hosting.
Ingress expose HTTP and HTTPS routes from outside the cluster to service in the cluster. Traffic routing is controlled by rules that are defined on ingress resource.
Ingress is also configured to give externally reachable URLs, load balancer, name-based virtual hosting.
Network Policies:
Network Policies are an application-centric construct which allow you to specify how a pod is allowed to communicate with various networks entity over the network.
While defining a pod- or namespace-based Network Policy, we use a selector to specify what traffic is allowed to and from the Pod(s) that match the selector.
Meanwhile when IP-based Network Policy is created, we define policies based on IP Blocks.
spec: Network policy spec has all the information needed to define a particular network policy in the given namespace.
podSelector: Each network policy includes podSelector. It selects a grouping of pods on which policies are applied.
policyType: Each Network Policy includes policyType, that has ingress or egress or both. By default the Ingress policyType will be set and if pod has any egress rule set then egress will be by default.
DNS:
Kubernetes publish the information about Pods & Services which is used to program DNS. Kubelet configures the Pods' DNS so the running containers can look up Service by name instead of IP address.
Service in cluster are assigned DNS names. By default the client Pods' DNS search list includes the Pods' own namespace and the cluster's default domain.
CNI Plugin:
Container Network Interface: A CNI plug in is necessary to implement the Kubernetes network model. It is a framework for dynamically configuring network resource. It uses groups of library and written in Go.




