Cheat Sheets / Kubernetes & Platform

Networking Deep Dive cheat sheet

81 commands from every lesson of Networking Deep Dive, on one page.

01 · Ethernet, ARP & MTU

Link layer

ip -br linkInterfaces, state and MAC addresses
ip neighARP/neighbour table (IP → MAC)
sudo tcpdump -eni eth0 arpWatch ARP requests and replies, with MACs
cat /proc/net/bonding/bond0Bond mode and member link status
ip -d link show eth0.100VLAN details (id, parent)

MTU

ip link show eth0 | grep mtuInterface MTU
ping -M do -s 1472 10.0.0.20Test a full 1500-byte packet without fragmentation
tracepath 10.0.0.20Discover the path MTU

02 · IP routing, NAT & conntrack

Routing

ip routeMain routing table
ip route get 10.96.0.10Which route and source address a destination uses
ip rulePolicy routing rules (which table to consult)
ip route show table all | headRoutes in every table

NAT & conntrack

sudo iptables -t nat -S | head -40NAT rules (iptables-based kube-proxy)
sudo nft list ruleset | lessAll nftables rules
sudo conntrack -L | headTracked connections (conntrack-tools)
sudo conntrack -SPer-CPU stats, including drops and insert failures
sysctl net.netfilter.nf_conntrack_count net.netfilter.nf_conntrack_maxCurrent vs maximum tracked connections

03 · TCP: state, flags & congestion

See connections

ss -tan state established | wc -lHow many established connections
ss -tan | awk 'NR>1 {print $1}' | sort | uniq -cConnections per state
ss -ti dst 10.0.5.20Per-connection RTT, cwnd, retransmits
nstat -az | grep -E 'TcpRetransSegs|ListenOverflows|ListenDrops'Kernel TCP counters

Capture

sudo tcpdump -ni any 'tcp port 443 and (tcp[tcpflags] & (tcp-syn|tcp-rst) != 0)'Only SYNs and RSTs
sysctl net.ipv4.tcp_congestion_controlCongestion control algorithm (cubic, bbr…)

04 · Your host's network model

Build it by hand

sudo ip netns add pod1Create a network namespace (a 'pod')
sudo ip link add veth-pod1 type veth peer name veth-host1A virtual cable with two ends
sudo ip link set veth-pod1 netns pod1Plug one end into the namespace
sudo ip link add br0 type bridge && sudo ip link set veth-host1 master br0Plug the other end into a bridge
sudo ip netns exec pod1 ip addrRun a command inside the namespace

Inspect a real node

ip -br link | grep -E 'veth|cali|lxc|cni'Host-side ends of pod veth pairs (names depend on the CNI)
sudo nsenter -t <pid> -n ip routeA pod's routes, from the node
ls /etc/cni/net.d/ /opt/cni/bin/CNI config and plugin binaries

05 · CNI plugins compared

Identify the CNI

ls /etc/cni/net.d/Which CNI config is active on a node
kubectl get pods -n kube-system -o wide | grep -E 'calico|cilium|flannel|kindnet|aws-node'CNI agent pods
kubectl get nodes -o jsonpath='{.items[*].spec.podCIDR}'Per-node pod CIDRs (if the CNI uses them)

CNI-specific tools

cilium status / cilium connectivity testCilium health and an end-to-end test suite
hubble observe --namespace shopCilium: live flow logs
calicoctl node statusCalico: BGP peering status

06 · Services, kube-proxy & eBPF

Which mode am I in?

kubectl -n kube-system get cm kube-proxy -o yaml | grep modekube-proxy mode (empty = platform default)
curl -s localhost:10249/proxyModeAsk kube-proxy on a node
cilium status | grep KubeProxyReplacementCilium replacing kube-proxy?

Inspect the rules

sudo iptables -t nat -L KUBE-SERVICES -n | headiptables mode Service rules
sudo ipvsadm -LnIPVS mode virtual servers and backends
sudo nft list table ip kube-proxy | head -50nftables mode rules
cilium service listeBPF service table (Cilium)

07 · DNS end to end

Inspect

kubectl exec <pod> -- cat /etc/resolv.confThe pod's resolver config
kubectl -n kube-system get cm coredns -o yamlThe Corefile (CoreDNS configuration)
kubectl -n kube-system logs -l k8s-app=kube-dnsCoreDNS logs (enable the 'log' plugin to see queries)

Test

kubectl run dns --rm -it --image=busybox:1.36 --restart=Never -- nslookup web.shopResolve a Service
dig +search webResolve using search domains (where dig is available)
dig @10.96.0.10 web.shop.svc.cluster.localAsk CoreDNS directly by its Service IP

08 · Load balancing & proxies

MetalLB

kubectl get ipaddresspools,l2advertisements,bgpadvertisements -n metallb-systemMetalLB configuration
kubectl get svc -A --field-selector spec.type=LoadBalancerLoadBalancer Services and their external IPs
kubectl -n metallb-system logs -l component=speakerWhich node announces which IP

Client IP

externalTrafficPolicy: LocalKeep the source IP at L4 (no SNAT hop)
X-Forwarded-For / ForwardedClient IP carried in HTTP headers by L7 proxies
PROXY protocol v1/v2Client IP prepended to the TCP stream by L4 proxies

09 · TLS: handshake & trust

openssl s_client

openssl s_client -connect host:443 -servername host </dev/nullHandshake details and the served chain
… -showcertsPrint every certificate the server sends
… | openssl x509 -noout -subject -issuer -dates -ext subjectAltNameSummarise the leaf certificate
… -alpn h2,http/1.1Which application protocol the server picks
openssl verify -CAfile ca.crt server.crtDoes this chain validate against this CA?

curl

curl -v https://host/TLS version, cipher, certificate, then HTTP
curl --cacert ca.crt https://host/Trust a specific (private) CA
curl --cert client.crt --key client.key https://host/Present a client certificate (mTLS)

10 · HTTP/1.1 → 2 → 3

Test protocol versions

curl -sI --http1.1 https://host/ | head -1Force HTTP/1.1
curl -sI --http2 https://host/ | head -1Try HTTP/2 (via ALPN)
curl -sI --http3 https://host/ | head -1Try HTTP/3 (needs a curl built with HTTP/3 support)
curl -w '%{http_version} %{time_connect} %{time_starttransfer}\n' -o /dev/null -s https://host/Version and timing

11 · gRPC & Protobuf

grpcurl

grpcurl -plaintext localhost:50051 listServices exposed (needs server reflection)
grpcurl -plaintext localhost:50051 describe orders.v1.OrdersMethods and messages
grpcurl -plaintext -d '{"id": "42"}' localhost:50051 orders.v1.Orders/GetOrderCall a method with JSON input
grpcurl -plaintext localhost:50051 grpc.health.v1.Health/CheckStandard health check

Kubernetes

readinessProbe: grpc: {port: 50051}Native gRPC health probes
clusterIP: NoneHeadless Service so clients can see every pod (client-side balancing)

12 · Capstone: one request, every layer

One command per layer

dig +short shop.example.comDNS: does the name resolve to the right address?
nc -vz <ip> 443TCP: can I connect at all?
openssl s_client -connect <ip>:443 -servername shop.example.com </dev/nullTLS: which certificate, which chain?
curl -v --resolve shop.example.com:443:<ip> https://shop.example.com/HTTP: status, headers, timings
kubectl get endpointslices -n shopService: are there ready backends?
kubectl -n shop exec deploy/web -- wget -qO- -T 3 http://api:8080/healthPod-to-pod: does the internal hop work?
ping -M do -s 1422 <pod-ip>MTU: do full-size packets survive the overlay?