๐Ÿ“– Read-only preview โ€” lessons, diagrams, and quizzes only. The hands-on labs, live grading, and progress tracking require running the real course locally against a Kubernetes cluster.Run it locally โ†’

Module 15 ยท Lesson 15.3

Load Balancers, Storage & Cost

Two more pieces complete the picture of what's actually different about a real EKS cluster versus the one on your laptop: how traffic gets in, how data survives a pod, and roughly what all of it costs.

Load balancers: from Traefik-on-ClusterIP to a real NLB/ALB

On your cluster, Traefik's own Service is a ClusterIP โ€” there's no real external address, which is why every lab so far verified routing from inside the cluster. On EKS, the AWS Load Balancer Controller watches Services (type: LoadBalancer) and Ingress objects and provisions a real AWS Network Load Balancer or Application Load Balancer to match, driven entirely by annotations:

metadata:
  annotations:
    service.beta.kubernetes.io/aws-load-balancer-type: "external"
    service.beta.kubernetes.io/aws-load-balancer-nlb-target-type: "ip"

aws-load-balancer-type: external is the current, correct value โ€” not the older nlb-ip, which still works for backward compatibility but shouldn't be used in new manifests. nlb-target-type: ip routes directly to pod IPs (only possible because of VPC CNI's real routable addresses from the last lesson) instead of through a node's kube-proxy.

Storage: from a laptop directory to a real EBS volume

Your standard StorageClass uses rancher.io/local-path-provisioner โ€” dynamic provisioning is real, but the "disk" is a directory on whichever node's filesystem the pod landed on; lose that node, lose the data. EKS's default dynamic provisioning is the EBS CSI driver, backing PVCs with real, network-attached EBS volumes (and the EFS CSI driver when you need a volume multiple pods can mount at once โ€” EBS is single-writer).

Cost: the parts that are easy to forget

  • Control plane: a flat $0.10/hour per cluster (~$73/month), regardless of workload size โ€” this is the one line item your local cluster has no equivalent for at all.
  • Nodes: standard EC2 pricing; Spot can cut this 60-90% for interruption-tolerant workloads, a decision Karpenter (Module 14) can automate.
  • EBS volumes: billed by provisioned size and IOPS/throughput tier, whether or not the volume is full โ€” an over-provisioned PVC quietly costs real money every month.
  • Data transfer: cross-AZ traffic between pods is billed per GB; a topology-naive Service (Module 10) can scatter pods across AZs and rack up transfer costs that an equally-correct, AZ-aware deployment wouldn't.

The infrastructure analogy

None of this is new if you've priced out ALBs, EBS volumes, or cross-AZ transfer for EC2 before โ€” the line items are identical. What's new is that Kubernetes objects (a Service, a PVC, a topology spread constraint) are now the thing deciding which of those line items you hit, which means a review of "is this manifest correct" and "is this manifest cheap" are often the same review.

๐Ÿงช Lab: lab-32-eks-lb-storage-cost

Preview only

Goal

Fix two realistic manifest mistakes from this lesson: a StorageClass with a typo'd provisioner name, and a Service using an outdated Load Balancer Controller annotation value.

Nothing here provisions a real AWS Load Balancer or EBS volume โ€” there's no AWS account behind this cluster โ€” but the objects themselves are real and gradeable, exactly like a manifest review before it ever reaches a real EKS cluster.

Tasks

  1. Apply the starting manifests: kubectl apply -f manifests/
  2. Check the StorageClass: kubectl get storageclass eks-ebs-gp3 -o yaml โ€” compare the provisioner field character-by-character against the real EBS CSI driver's provisioner name, ebs.csi.aws.com.
  3. Fix the typo in manifests/storage-and-lb.yaml. provisioner is an immutable field on an existing StorageClass โ€” same category of restriction you already hit on a Pod's command in Module 2 โ€” so kubectl apply alone will be rejected. Delete it first: kubectl delete storageclass eks-ebs-gp3, then re-apply the file.
  4. Check the Service: kubectl get service frontend -n lab-32-eks-lb-storage-cost -o yaml โ€” look at service.beta.kubernetes.io/aws-load-balancer-type. nlb-ip is the old, backward-compatibility-only value; current guidance is external.
  5. Fix that annotation in the same file and re-apply.

Check

Run the check once both the StorageClass provisioner and the Service annotation are corrected.

This lab runs against a real local Kubernetes cluster with an automated grader โ€” clone the repo and run make start to do it for real.

๐Ÿ“ Quiz

1. What provisions a real NLB/ALB on EKS when you create a Service of type LoadBalancer or an Ingress?

2. Which service annotation value is current/correct for aws-load-balancer-type on a new manifest?

3. Your local kind cluster's default StorageClass dies along with the one node whose disk backed a PVC. What's different about EKS's default (EBS CSI) storage?scenario

4. Which EKS cost is a flat, workload-independent charge you'd have no equivalent for on a local kind cluster?

5. A Deployment has no topology spread constraint, so its replicas end up unevenly distributed across AZs, and a lot of inter-pod traffic now crosses AZ boundaries. What's the cost impact?scenario

Progress isn't saved in this preview โ€” run the course locally to track completion and grade labs for real.