DevOps Practitioner · Module 2: Kubernetes networking and storage · Lab
Diagnose Selector and targetPort Access Failures
45 min hands-on · Core
A local KinD or k3d cluster on a machine you own, with a demo API deployment and Service.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Separate selector breaks from targetPort breaks by EndpointSlice state
- Fix both from the manifest and show traffic restored
- Write the three-link check order: selector, endpoints, ports
Step 1
Break the selector
Introduce a one-character selector typo on the demo Service. Resolve the name (it works), dial the ClusterIP (it fails), and show the empty EndpointSlice. Record symptom plus slice state.
Step 2
Break the targetPort
Restore the selector, then point targetPort at a port nothing listens on. Show the populated slice with refused connections, then correct the port and show traffic flowing.
Step 3
Write the check order
Record the diagnostic order used for both breaks: resolve the name, read the EndpointSlice, then compare port against targetPort. State which evidence separates the two causes.
How to confirm it worked
- Empty slice with refused traffic quoted for the selector break
- Populated slice with refused traffic quoted for the port break
- Both fixes applied from the manifest, traffic shown restored
- Three-link check order written down