Green pods, empty Service INC-2380

Open2 versionsKubernetes · Easy · Fix · about 25 min ·Linux + Kubernetes

Lab machine

A private machine with its own Kubernetes cluster. Starting takes about 30 seconds. Sessions last up to 60 minutes.
Sasha Lind opened INC-2380 at 09:40SEV-2

This morning every workload moved to the recommended app.kubernetes.io labels. Waybill's pods are Running and Ready. Its Service has no endpoints.

A Service finds its pods by label. Nothing connects them except that match, and changing pod labels does not change the selector.

"Pods are green, so it must be the network. Want me to restart CoreDNS?" (on-call)

Labelling running pods by hand would work until the next pod is created.

Your task

Make the Service select every Ready Waybill pod, including pods created later, by fixing manifests/ and applying it.

On the machine

  • kubectl get svc waybill -o yaml, kubectl get pods --show-labels
  • kubectl get endpointslices
  • manifests/

Timeline

09:00Platform relabels every workload to app.kubernetes.io/*.
09:02Tracking API: 503, no endpoints available for service "waybill".
09:40"Pods are green, so it must be the network. Restart CoreDNS?"

Done when

  1. The Service's ready endpoints equal the Ready Waybill pods.
  2. A replacement pod is selected automatically.
  3. manifests/ matches the cluster.

Hints

Hint 1

Pods being Ready says nothing about who selects them, or on which port.

Hint 2

Compare the Service selector with the pod template labels, and its targetPort with the container's port names.

Hint 3

A selector must match every key-value pair it lists. A named targetPort must exist on the pod.

Hint 4

Fix the Service in manifests/service.yaml; labels added to running pods vanish on replacement.

Show the solution

`kubectl get endpointslices` shows no endpoints. Compare the Service with the pods: either its selector still lists the old `app`/`tier` labels (change it to `app.kubernetes.io/name: waybill`), or the selector matches but its `targetPort` names a port the pods no longer have (`web`, now `http`). Fix `manifests/service.yaml`, apply it, and confirm with `kubectl get endpointslices` and a request through the service proxy.