Memory hook: Requests place; limits constrain; probes decide.
Must remember
Deployments manage ReplicaSets and rolling changes. StatefulSets supply stable ordinal identity and per-Pod storage patterns; DaemonSets place node-local workloads; Jobs run to completion and CronJobs schedule Jobs. Pick the controller that expresses the workload instead of creating unmanaged Pods.
Use kubectl rollout status, history and undo for Deployment progress and recovery. maxSurge permits extra Pods; maxUnavailable controls how many desired replicas can be unavailable during a rolling update. A rollback restores an earlier Pod template, not external database state.
Readiness determines eligibility for normal Service traffic; liveness can restart a failing container; startup delays the other probes while an application initializes. An overly aggressive liveness probe can turn a dependency outage into a restart storm. Resource requests influence scheduling; limits constrain use, with CPU throttling and possible memory termination.
Node selectors and required affinity constrain placement; preferred affinity expresses preference. Taints repel Pods without matching tolerations; a toleration permits placement but does not select a particular node. Topology spread and anti-affinity reduce correlated failures. Admission controls, namespace quotas and LimitRanges can reject or default Pod configuration before scheduling.
HPA scales replica counts from configured metrics; utilisation-based CPU scaling requires appropriate requests and metrics availability. Node autoscaling supplies node capacity rather than changing desired application replicas. A PodDisruptionBudget limits voluntary disruption; it cannot prevent every involuntary failure.
ConfigMaps store nonsecret settings; Secrets hold sensitive values but base64 encoding is not encryption. Protect API access and at-rest storage. Environment variables are captured at container start; mounted projected data can update with qualifications, including subPath limitations. Restart or reload the application when its consumption method requires it.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Slow startup but healthy later | Use a startup probe and suitable thresholds. |
| Spread replicas across failure domains | Topology constraints/anti-affinity plus sufficient capacity. |
| Scale on measured load | HPA with correct requests and metrics. |
Traps
- A toleration is permission, not a placement guarantee.
- A readiness failure does not itself restart the container.
Active recall
1. Which probe removes an unready Pod from normal traffic?
Readiness; liveness controls restart behavior.
2. What does maxSurge allow?
Extra Pods above desired replicas during a rolling update.
3. Why might a Pod remain Pending despite a toleration?
Other scheduling requirements or capacity can still be unsatisfied.
4. Does a ConfigMap environment-variable change update a running process?
No. Recreate/restart the container or use a suitable reloadable consumption mechanism.
5. Does a PDB guarantee survival of a node crash?
No. It constrains voluntary disruptions, not all infrastructure failures.