Memory hook: The API receives, etcd remembers, controllers reconcile, the scheduler places, the kubelet runs.
Must remember
- Kubernetes orchestrates containerised applications. You declare the desired state; control loops repeatedly compare it with the observed state and act on the difference. This supports recovery without a person restarting every failed application.
- A cluster combines a control plane with worker nodes. A node can be a virtual or physical machine. Highly available control planes avoid making one machine the only route to cluster management.
- kube-apiserver exposes the Kubernetes API and is the entry point for clients and components. etcd stores cluster configuration and state. Backing up etcd protects Kubernetes object data; it does not automatically back up files inside application volumes.
- kube-controller-manager runs reconciliation controllers, such as the controller that maintains a requested replica count. kube-scheduler selects a suitable node for an unscheduled Pod. It does not start that Pod's containers itself.
- kubelet runs on each node and works with a container runtime to keep assigned Pods running. kube-proxy, or a networking implementation that replaces its role, supplies Service traffic forwarding. A cloud controller integrates supported cloud infrastructure.
- A Pod is the smallest deployable Kubernetes unit: one or more closely coupled containers with a shared network identity and declared volumes. Containers in one Pod reach each other through
localhost; separate Pods have separate identities. - An object manifest normally has apiVersion, kind, metadata and spec.
specexpresses intent;statusreports observed conditions. YAML is a representation of API objects, not a different control plane. - Labels identify and group objects; selectors find matching groups. Annotations carry extra descriptive metadata. Namespaces organise namespaced objects; nodes and PersistentVolumes are examples of cluster-scoped objects.
Read the story behind a Deployment: submit its manifest → controllers create the required child objects → scheduler assigns Pods → kubelets start containers → readiness determines whether application endpoints should receive traffic. A controller may replace a failed Pod with a new identity rather than repair the old Pod in place.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Maintain three application replicas after one Pod disappears | A workload controller, such as a Deployment; a standalone Pod does not provide that replica-management loop |
| Identify where cluster object state is persisted | etcd; an image registry stores images instead |
| Place a Pod on an eligible node | Scheduler; kubelet performs execution after assignment |
| Group all frontend objects for selection | A label such as app=frontend; an annotation is not the normal grouping mechanism |
| Add a new API resource with its own reconciliation logic | A CustomResourceDefinition plus a controller; an operator packages application-specific operational knowledge |
Traps
- Kubernetes does not provide a complete application database, source repository or build pipeline just because it runs containers.
- A namespace is a scope for organisation and policy, not an automatic network isolation boundary.
- Pod IPs and container writable layers are poor places to keep an application's durable identity or only copy of data.
- Losing API availability affects management and reconciliation; it does not mean every already running container instantly stops.
Active recall
1. A Deployment requests four replicas, but only three exist. Which component family notices and acts?
The workload controllers reconcile observed and desired state and create the missing workload objects. The scheduler later chooses placement, and the kubelet starts the assigned containers.
2. A Pod is assigned to a node. Does the scheduler now pull its image?
No. The node's kubelet coordinates with its container runtime to pull images and run containers. Scheduling and execution are separate responsibilities.
3. Two containers need the same network identity and must share a local workspace. What is the natural unit?
A single Pod containing both containers, with a declared volume mounted into each container that needs it. Containers in a Pod share networking, but their root filesystems do not automatically become one filesystem.
4. Does restoring an etcd backup also restore a database's PersistentVolume contents?
No. etcd stores Kubernetes object state. Application data needs its own volume or database backup and an appropriate recovery procedure.
5. A tool needs to find every component belonging to one application. Labels or annotations?
Labels and selectors provide grouping and selection. Annotations are better for additional metadata that is not used to identify a selected set of objects.