A curious engineer runs `ping` against a Service's ClusterIP from inside the cluster and gets no reply, but `curl`ing the same IP on the Service's port works fine. Is something broken?
Nothing is broken — a ClusterIP is not a real address that anything is listening on, so there's nothing to answer an ICMP echo request in the first place. A Service selects pods by label and keeps a list of the ones currently passing readiness; kube-proxy turns that list into kernel-level rules (an iptables DNAT rule, or an IPVS virtual server) that rewrite the destination of a packet addressed to the ClusterIP into a real pod's IP, before the kernel routes it onward. curl works because HTTP traffic on the Service's port matches those rules and gets rewritten to a pod that's actually listening; ping fails because ICMP isn't what the rule matches — the ClusterIP was never bound to any interface or process, it's purely a kernel-level redirect target for the protocols and ports the Service actually defines.