Kubernetes Service Examples: ClusterIP and NodePort

In Kubernetes, a Service is an abstract way to expose an application running on a set of Pods as a network service. Services enable communication between different parts of your application (e.g., frontend to backend) and allow external access to your applications. This document provides examples of two fundamental Service types: ClusterIP and NodePort.

1. ClusterIP Service

A ClusterIP Service exposes the Service on an internal IP address within the cluster. It makes the Service reachable only from within the cluster. This is the default Service type and is suitable for backend services that only need to be accessed by other applications inside the Kubernetes cluster (e.g., a database, an internal API).

Use Case: Internal communication between microservices, database access.

Example: ClusterIP Service for phpMyAdmin (pma)

This example shows a ClusterIP Service named pma that exposes port 80 of pods labeled app: pma.

apiVersion: v1
kind: Service
metadata:
  name: pma
spec:
  # 'selector' identifies the pods that this Service will route traffic to.
  # Traffic sent to the 'pma' Service will be directed to pods with the label 'app: pma'.
  selector:
    app: pma
  # 'type: ClusterIP' means the Service is only reachable from within the cluster.
  type: ClusterIP
  ports:
    # 'name: http' provides a descriptive name for the port.
    # 'port: 80' is the port on the Service itself. Other pods in the cluster will
    # connect to this port.
    # 'targetPort: 80' is the port on the pods that the Service will forward traffic to.
    # 'protocol: TCP' specifies the network protocol.
    - name: http
      port: 80
      targetPort: 80
      protocol: TCP

Explanation: The pma Service gets an internal cluster IP. Other pods within the cluster can access phpMyAdmin using the pma service name and port 80. External access would typically be handled by an Ingress Controller (like Traefik) which proxies requests to this internal ClusterIP service.

2. NodePort Service

A NodePort Service exposes the Service on a static port on each Node’s IP address. This makes the Service accessible from outside the cluster using <NodeIP>:<NodePort>. Kubernetes will automatically allocate a port from a configurable range (default: 30000-32767).

Use Case: Exposing a service directly to external clients for testing, development, or when an Ingress Controller is not desired/available.

Example: NodePort Service for MySQL Database

This example shows a NodePort Service named db that exposes port 3306 of pods labeled app: db. It also specifies a nodePort of 32000 for external access.

apiVersion: v1
kind: Service
metadata:
  name: db
spec:
  # 'selector' identifies the pods that this Service will route traffic to.
  # Traffic sent to the 'db' Service will be directed to pods with the label 'app: db'.
  selector:
    app: db
  # 'type: NodePort' exposes the Service on a static port on each Node's IP.
  type: NodePort
  ports:
    # 'name: mysql' provides a descriptive name for the port.
    # 'port: 3306' is the port on the Service itself. Other pods in the cluster will
    # connect to this port.
    # 'targetPort: 3306' is the port on the MySQL container within the pods.
    # 'nodePort: 32000' is the port allocated on EACH node's IP address for external access.
    # Connections to <NodeIP>:32000 will be routed to the 'db' Service.
    - name: mysql
      port: 3306        # The port inside the cluster for the Service
      targetPort: 3306  # The port the MySQL container listens on
      nodePort: 32000   # A port in the 30000-32767 range, choose one free on your nodes

Explanation: The db Service is accessible from outside the cluster on any node’s IP address at port 32000. For example, if a node has IP 192.168.1.10, you can connect to the MySQL database from an external machine using 192.168.1.10:32000. The Service then forwards this traffic to port 3306 on a selected db pod.