Full lesson
Explore the full explanation, examples, and visuals at your own pace.
Same Service address, different Pod IP
A Pod can disappear without changing the address clients use. The Client connects to the web Service, which routes to web-a. The puzzle is that web-a’s IP can change while the Service address stays the same.
The selector finds matching Pods
The web Service doesn’t target a fixed Pod name or IP address. Its selector looks for the app=web label, so web-a matches because it carries that label.
Matches become current endpoints
A Service keeps its address while an EndpointSlice tracks the current IPs of matching, ready Pods: here, web-a at 10.1.0.4.
Replacement changes the endpoint, not the Service
The web Service’s selector, app=web, still matches ready Pod web-b. The EndpointSlice replaces web-a’s old address, 10.1.0.4, with web-b’s current IP, 10.1.0.9; the Service address itself stays the same.
When ready web-b replaces web-a with a new IP, what needs to change for the Service to reach web-b?
Let's think this through. When ready web-b replaces web-a with a new IP, what needs to change for the Service to reach web-b? A: The client's Service address. B: The Service's recorded endpoint. C: The Service's selector label. Choose an answer, or just think it through. I'll explain in a moment.
- The client's Service address
- The Service's recorded endpoint
- The Service's selector label
When ready web-b replaces web-a with a new IP, what needs to change for the Service to reach web-b?
The answer is B: The Service's recorded endpoint. The EndpointSlice must reflect web-b's current IP so routing can reach it. The client keeps using the same Service address, and the selector still matches the app=web label.
- The client's Service address
- The Service's recorded endpoint
- The Service's selector label
A new connection reaches web-b
The Client still connects to the unchanged web Service address. Node routing uses the updated EndpointSlice, which now points to web-b at 10.1.0.9, and forwards this new connection there.
What to check when traffic misses Pods
First, does the Service selector match the Pod’s labels? Then confirm web-b is ready. Endpoint updates can take time, so routing may briefly lag.
- Does the selector match Pod labels?
- Is the replacement Pod ready?
- Have endpoints updated?
Stable address, current ready endpoint
A Service's stable address is separate from its changing endpoints. For web, that unchanged address routes new connections to ready web-b at its current IP, 10.1.0.9.




