Exposing a virtual machine by using a service
You can expose a virtual machine (VM) within or outside the cluster by exposing a VM as a Kubernetes service. You can leverage native load balancing and observability tools that provide unified traffic management, consistent SSL termination, and centralized security policies across hybrid workloads.
About services
A Kubernetes service exposes network access for clients to an application running on a set of pods. Services offer abstraction, load balancing, and, in the case of the NodePort and LoadBalancer types, exposure to the outside world.
ClusterIP- Exposes the service on an internal IP address and as a DNS name to other applications within the cluster. A single service can map to multiple virtual machines. When a client tries to connect to the service, the client’s request is load balanced among available backends.
ClusterIPis the default service type. NodePort- Exposes the service on the same port of each selected node in the cluster.
NodePortmakes a port accessible from outside the cluster, provided that the node itself is externally accessible to the client. LoadBalancer- Creates an external load balancer in the current cloud (if supported) and assigns a fixed, external IP address to the service.
For on-premise clusters, you can configure a load balancing service by deploying the MetalLB Operator.
Dual-stack support
If IPv4 and IPv6 dual-stack networking is enabled for your cluster, you can create a service that uses IPv4, IPv6, or both, by defining the spec.ipFamilyPolicy and the spec.ipFamilies fields in the Service object.
The spec.ipFamilyPolicy field can be set to one of the following values:
- SingleStack
- The control plane assigns a cluster IP address for the service based on the first configured service cluster IP range.
- PreferDualStack
- The control plane assigns both IPv4 and IPv6 cluster IP addresses for the service on clusters that have dual-stack configured.
- RequireDualStack
- This option fails for clusters that do not have dual-stack networking enabled. For clusters that have dual-stack configured, the behavior is the same as when the value is set to
PreferDualStack. The control plane allocates cluster IP addresses from both IPv4 and IPv6 address ranges.
You can define which IP family to use for single-stack or define the order of IP families for dual-stack by setting the spec.ipFamilies field to one of the following array values:
[IPv4][IPv6][IPv4, IPv6][IPv6, IPv4]
IPv6 single stack and the [IPv6, IPv4] array are not supported in IBM Z(R) and IBM(R) LinuxONE.
Creating a service by using the CLI
You can create a service and associate it with a virtual machine (VM) by using the command line.
Prerequisites
- You configured the cluster network to support the service.
- You have installed the OpenShift CLI (
oc).
Procedure
-
Edit the
VirtualMachinemanifest to add the label for service creation. Addspecial: keyto thespec.template.metadata.labelsstanza:apiVersion: kubevirt.io/v1kind: VirtualMachinemetadata:name: example-vmnamespace: example-namespacespec:runStrategy: Haltedtemplate:metadata:labels:special: key# ...noteLabels on a virtual machine pass through to the pod. The
special: keylabel must match the label in thespec.selectorattribute of theServicemanifest. -
Save the
VirtualMachinemanifest file to apply your changes. -
Create a
Servicemanifest to expose the VM:apiVersion: v1kind: Servicemetadata:name: example-servicenamespace: example-namespacespec:# ...selector:special: keytype: NodePortports:protocol: TCPport: 80targetPort: 9376nodePort: 30000spec.selectordefines the label that you added to thespec.template.metadata.labelsstanza of theVirtualMachinemanifest.spec.typedefines the type of service by the way it is exposed. Choose one ofClusterIP,NodePort, orLoadBalancer.spec.portsdefines a collection of network ports and protocols to expose from the virtual machine.
-
Save the
Servicemanifest file. -
Create the service by running the following command:
$ oc create -f example-service.yaml -
Restart the VM to apply the changes.
Verification
- Query the
Serviceobject to verify that it is available:$ oc get service -n example-namespace
Additional resources