Networking
DNS
59 / 82

Applications call checkout; CoreDNS and the search path do the rest.

CoreDNS runs inside the cluster as a Deployment and answers for cluster.local. Every Pod's resolver is pointed at it.

app in namespace shopcalls http://checkoutresolver search pathcheckout.shop.svc.cluster.localalso .svc.cluster.local and .cluster.localCoreDNSkube-systemClusterIP 10.96.0.15then kube-proxy picks a Pod

ndots: 5 latency

A name with fewer than 5 dots, such as api.stripe.com, is tried against every search domain first. Lower ndots or use trailing-dot names for chatty external calls.

dnsPolicy: Default trap

Despite the name it is not the default. It bypasses CoreDNS, so .svc.cluster.local names fail while the internet works.

Quick test

kubectl run -it --rm dbg --image=nicolaka/netshoot -- nslookup checkout.shop