Does the work. Runs the Pods and moves the packets. Every node in the cluster runs the same agents.
kubelet + CNI pluginnode agent
kubelet starts this node's Pods through the container runtime and reports their status. The CNI plugin gives each Pod an IP.
kube-proxynode agent
Watches Services and EndpointSlices, and turns them into kernel NAT rules. It writes rules; it never touches packets.
frontend Poda client of the Service
An application Pod that calls backend-svc.
Linux kernelnetfilter + conntrack
Where packets are actually rewritten, using the rules kube-proxy loaded (iptables or nftables).