The ClusterIP 10.96.1.190 is on no network interface. It exists only as rules that kube-proxy, a DaemonSet Pod on every node, writes into the kernel from Services and EndpointSlices, translating (DNAT) each new connection to one ready Pod:
kubectl -n kube-system get configmap kube-proxy -o jsonpath='{.data.config\.conf}' | grep '^mode'
docker exec l3-booknest-worker iptables-save -t nat | grep 'default/web' \
| sed 's/-m comment --comment "[^"]*" //'mode: iptables -A KUBE-SEP-DGO6B5KTFPJ5IL5G -s 10.244.1.26/32 -j KUBE-MARK-MASQ -A KUBE-SEP-DGO6B5KTFPJ5IL5G -p tcp -m tcp -j DNAT --to-destination 10.244.1.26:80 -A KUBE-SEP-KVQDEGTO7UXS2HHB -s 10.244.1.27/32 -j KUBE-MARK-MASQ -A KUBE-SEP-KVQDEGTO7UXS2HHB -p tcp -m tcp -j DNAT --to-destination 10.244.1.27:80 -A KUBE-SERVICES -d 10.96.1.190/32 -p tcp -m tcp --dport 80 -j KUBE-SVC-LOLE4ISW44XBNF3G -A KUBE-SVC-LOLE4ISW44XBNF3G ! -s 10.244.0.0/16 -d 10.96.1.190/32 -p tcp -m tcp --dport 80 -j KUBE-MARK-MASQ -A KUBE-SVC-LOLE4ISW44XBNF3G -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-DGO6B5KTFPJ5IL5G -A KUBE-SVC-LOLE4ISW44XBNF3G -j KUBE-SEP-KVQDEGTO7UXS2HHB
Start at the KUBE-SERVICES rule: traffic to 10.96.1.190:80 jumps to the Service chain KUBE-SVC-..., which picks the first endpoint with probability 0.5 and otherwise the second; each KUBE-SEP-... chain rewrites the destination to a Pod IP, and connection tracking keeps the connection there. KUBE-MARK-MASQ marks traffic from outside the Pod network for source NAT.
iptables 40,292 mode is still the default. nftables 40,292 , GA since 1.33, updates rules incrementally and scales better on new clusters; ipvs is deprecated, with removal planned for 1.43; Cilium 96,364 can replace kube-proxy with eBPF. A ClusterIP that does not answer usually has no ready endpoints: check kubectl 5,150 get endpointslices.