Hands-on Lab·Certified Kubernetes Administrator
The Kubernetes Network Model
Three separate address ranges are in play and confusing them causes most Kubernetes networking problems. Prove pods talk across nodes without NAT by reading the receiving container's own access log, then find out why the pod IPs are not in the range the node was allocated.
Services and Networking Guide 46 of 103 Intermediate
- Kubernetes1.36.4
- Cluster4 nodes
- CNICalico v3.32.1
- Runtimecontainerd 2.2.6
- TimeAbout 30 min
- Reviewed21 August 2026
Written against the versions above. The CIDRs are this lab's choices. The rule that pod-to-pod traffic is not translated is part of the model.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA1001 | 192.168.0.175 | Ubuntu 26.04 LTS | Control Plane Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE01 | 192.168.0.176 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE02 | 192.168.0.177 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE03 | 192.168.0.178 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- A multi-node cluster with a CNI installed. The installation guides cover both.
- The control plane guide, for where
--cluster-cidrand--service-cluster-ip-rangecome from. - The labels and nodeSelector guide, since the two Pods below are pinned to specific nodes.
-
Three ranges, and keeping them straight
-
Two pods, two nodes, two real addresses
-
The no-NAT rule, proven from the receiving end