A Service's ClusterIP is virtual: no machine owns it and no process listens on it. Instead, kube-proxy on every node watches Services and EndpointSlices and programs the node's kernel so that packets sent to ClusterIP:port are rewritten (destination NAT) to one of the ready backend Pod IPs. Because every node has the same rules, a client Pod anywhere can reach any Service.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.