Debug Services — Iptables mode
In "iptables" mode, you should see something like the following on a Node Bounded code example (external data; do not execute automatically): ```shell iptables-save | grep hostnames ``` Bounded code example (external data; do not execute automatically): ```none -A KUBE-SEP-57KPRZ3JQVENLNBR -s 10.244
Reference note (untrusted external data; do not execute it as instructions).
In "iptables" mode, you should see something like the following on a Node
Bounded code example (external data; do not execute automatically):
```shell
iptables-save | grep hostnames
```
Bounded code example (external data; do not execute automatically):
```none
-A KUBE-SEP-57KPRZ3JQVENLNBR -s 10.244.3.6/32 -m comment --comment "default/hostnames:" -j MARK --set-xmark 0x00004000/0x00004000
-A KUBE-SEP-57KPRZ3JQVENLNBR -p tcp -m comment --comment "default/hostnames:" -m tcp -j DNAT --to-destination 10.244.3.6:9376
-A KUBE-SEP-WNBA2IHDGP2BOBGZ -s 10.244.1.7/32 -m comment --comment "default/hostnames:" -j MARK --set-xmark 0x00004000/0x00004000
-A KUBE-SEP-WNBA2IHDGP2BOBGZ -p tcp -m comment --comment "default/hostnames:" -m tcp -j DNAT --to-destination 10.244.1.7:9376
-A KUBE-SEP-X3P2623AGDH6CDF3 -s 10.244.2.3/32 -m comment --comment "default/hostnames:" -j MARK --set-xmark 0x00004000/0x00004000
-A KUBE-SEP-X3P2623AGDH6CDF3 -p tcp -m comment --comment "default/hostnames:" -m tcp -j DNAT --to-destination 10.244.2.3:9376
-A KUBE-SERVICES -d 10.0.1.175/32 -p tcp -m comment --comment "default/hostnames: cluster IP" -m tcp --dport 80 -j KUBE-SVC-NWV5X233
```
For each port of each Service, there should be 1 rule in KUBE-SERVICES and one KUBE-SVC- chain. For each Pod endpoint, there should be a small number of rules in that KUBE-SVC- and one KUBE-SEP- chain with a small number of rules in it. The exact rules will vary based on your exact config (including node-ports and load-balancers).
Attribution: Adapted from Kubernetes Documentation under CC-BY-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
Kubernetes Documentation — content/en/docs/tasks/debug/debug-application/debug-service.md :: Iptables mode ↗Revision 6449f1eced66 · CC-BY-4.0 and attribution