DevOps Bootcamp · Lesson

Service Types: ClusterIP, NodePort, LoadBalancer

Learn the different ways to expose services within and outside your Kubernetes cluster.

Lesson 2 of 412 steps

Service Types: ClusterIP, NodePort, LoadBalancer is a free DevOps Bootcamp lesson on CoddyKit. This is lesson 2 of 4. Any 3 lessons of this learning path are free to read in full — after that, CoddyKit PRO unlocks every lesson, plus hands-on practice with a built-in code editor and a 24/7 AI tutor. It is part of the DevOps Bootcamp learning path, and your progress syncs across the web and the CoddyKit app. The DevOps Bootcamp course includes 4 lessons in total.

Service Exposure Needs

In Kubernetes, Pods are ephemeral and have dynamic IP addresses. Services provide stable network access to your applications. But how do you expose them?

Depending on whether your application needs to be accessed from inside or outside your cluster, and how, Kubernetes offers different Service types. Let's explore the three main ones!

ClusterIP: Internal Access

The ClusterIP is the default Service type. It gives your Service a stable internal IP address, accessible only from within the Kubernetes cluster.

  • Pods can reach other Pods using these ClusterIPs and the Service's name.
  • It's perfect for backend services that don't need direct external exposure.
  • Think of it as an internal load balancer for your Pods.

ClusterIP Service YAML

Here's how you define a Service of type ClusterIP. Notice the type: ClusterIP field, though it's optional as it's the default.

apiVersion: v1
kind: Service
metadata:
  name: my-internal-service
spec:
  selector:
    app: my-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 8080
  type: ClusterIP

Accessing ClusterIP Services

Once deployed, Kubernetes automatically assigns a unique internal IP address (the ClusterIP) to this service. Other Pods can then use the service name (e.g., my-internal-service) or its IP to connect.

Kubernetes' DNS service resolves the service name to its ClusterIP, making internal communication easy and reliable.

NodePort: External Access

What if you need to access your application from outside the cluster? That's where NodePort comes in.

A NodePort Service exposes your application on a static port on every node's IP address in the cluster. Any traffic sent to NodeIP:NodePort is routed to your Service.

  • Useful for development and small deployments.
  • The NodePort is usually in the range 30000-32767.

NodePort Service YAML

To create a NodePort Service, you explicitly set type: NodePort. Kubernetes will automatically pick an available port in the NodePort range if you don't specify one.

apiVersion: v1
kind: Service
metadata:
  name: my-nodeport-service
spec:
  selector:
    app: my-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 8080
      nodePort: 30080 # Optional: K8s picks if omitted
  type: NodePort

Connect via NodePort

After deploying a NodePort Service, you can access your application from outside the cluster using <AnyNodeIP>:<NodePort>.

For example, if a node's IP is 192.168.1.100 and the assigned NodePort is 30080, you can reach your app at http://192.168.1.100:30080.

LoadBalancer: Cloud Integration

For production environments on cloud providers (AWS, GCP, Azure), the LoadBalancer Service type is often preferred. It automatically provisions an external cloud load balancer.

This load balancer gets a public IP address and distributes external traffic to your Service's Pods. It handles all the complex routing for you.

LoadBalancer Service YAML

Defining a LoadBalancer Service is straightforward. Your cloud provider does the heavy lifting to provision the external load balancer.

apiVersion: v1
kind: Service
metadata:
  name: my-loadbalancer-service
spec:
  selector:
    app: my-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 8080
  type: LoadBalancer

External Access with LoadBalancer

Once deployed, your cloud provider will create a dedicated load balancer and assign it an external IP address or hostname. You can then use this public endpoint to access your application.

This provides a robust, scalable, and highly available way to expose your services to the internet.

Quick Check: Service Types

Which Kubernetes Service types allow direct external access to your application from outside the cluster?

Recap: Choosing Your Service

You've learned about the three main Kubernetes Service types:

  • ClusterIP: For internal-only access within the cluster.
  • NodePort: Exposes services on a static port on each node's IP, allowing external access.
  • LoadBalancer: Integrates with cloud providers to provision an external load balancer with a public IP.

Choose the right type based on your application's exposure needs and your deployment environment!

Free to start

Learn DevOps Bootcamp with an AI tutor — free

Write and run real code in your browser, get instant help from a 24/7 AI tutor, and pick up where you left off on the web or in the app.

Courses
142
Lessons
568

Frequently Asked Questions

Is the “Service Types: ClusterIP, NodePort, LoadBalancer” lesson free?

Yes — any 3 lessons of the DevOps Bootcamp learning path, including “Service Types: ClusterIP, NodePort, LoadBalancer”, are free to read in full here on the web. After that, CoddyKit PRO unlocks every lesson, plus interactive practice with a built-in code editor and a 24/7 AI tutor. The DevOps Bootcamp course includes 4 lessons in total.

What will I learn in “Service Types: ClusterIP, NodePort, LoadBalancer”?

Learn the different ways to expose services within and outside your Kubernetes cluster. You practise DevOps Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start DevOps Bootcamp?

No prior experience is required. DevOps Bootcamp on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 2 of 4.

How long does the “Service Types: ClusterIP, NodePort, LoadBalancer” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this DevOps Bootcamp lesson?

Yes. Every DevOps Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Exposing Apps with Services
  2. Service Types: ClusterIP, NodePort, LoadBalancer
  3. Ingress for External Access
  4. DNS and Service Discovery
← Back to DevOps Bootcamp