Kubernetes Workloads — Deployments, Probes, Resources & Progressive Delivery
Controllers reconcile desired vs actual. Deployments own ReplicaSets that own Pods. Probes gate traffic and restarts. Requests/limits set QoS and scheduling. Rollouts need PDBs and a progressive strategy. This hub maps the cluster; Ingress/Gateway stays in the Private Networking pages.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Stateless API, interchangeable Pods
Prefer
Deployment
The controller owns rollout history, surge, and rollback. Pods are cattle. You declare replicas and a template.
- RollingUpdate, pause, resume, and undo are built in.
- A new template becomes a new ReplicaSet revision.
- Right for most web APIs and workers without sticky identity.
Alternative
StatefulSet
Stable network names and a volume per ordinal. Rollouts are slower because identity and disk stick to pod-0, pod-1.
- Right for brokers and databases that need ordered peers.
- Wrong as the default for a stateless HTTP service.
- Drain and replace are harder because the name is the identity.
Control plane loop
Desired state is written once. Controllers keep comparing it to the cluster until they match or they surface why they cannot.
- 1
Write desired state
You or CI updates a Deployment. The API server stores it. - 2
Deployment controller
It ensures a ReplicaSet exists for the current template revision. - 3
ReplicaSet controller
It creates or deletes Pods until the count matches replicas. - 4
Scheduler
It binds each Pod to a Node that can fit the Pod requests. - 5
Kubelet and probes
Containers start. Readiness decides Service membership. Liveness may restart a wedged process.
Overview
"We just use Deployments" is not an interview answer. The interviewer wants the loop: something writes desired state, a controller notices the gap, and it changes the cluster. If it cannot, status tells you why (image pull, quota, unschedulable, a probe that never passes).
This cluster is the workload layer. Controllers, Pod lifecycle, capacity, progressive delivery, and autoscaling. It is not the traffic-edge layer. How a request enters the cluster from outside is Ingress Controllers & North-South in the Private Networking series. Readiness still matters here, because a Ready Pod is what a Service's EndpointSlice is allowed to use. The object that routes host and path from the internet is a different lesson.
What this cluster covers
- Pods, ReplicaSets & Deployments — Desired State & Controllers — labels, owner references, maxUnavailable, maxSurge, revision history.
- Probes & Pod Lifecycle — Liveness, Readiness, Startup & PreStop — three probes, SIGTERM, drain.
- Requests, Limits & QoS — CPU Throttling, Memory OOM & Scheduling — Guaranteed, Burstable, BestEffort.
- Rolling, Blue-Green & Canary — Strategies, PDBs & Blast Radius — how many users see the new build, and what a PDB will refuse.
- HPA, VPA & Autoscaling Gotchas — Metrics, Stabilization & Thrash — replica math, windows, and the fight when both touch CPU.
Decisions
- 1
1. Write desired state
- next2. Deployment watches
- 2
2. Deployment watches
- next3. Ensure a ReplicaSet
- 3
3. Ensure a ReplicaSet
- next4. Match the Pod count
- 4
4. Match the Pod count
- next5. Bind using requests
- 5
5. Bind using requests
- next6. Kubelet runs probes
- 6
6. Kubelet runs probes
- next7. Ready?
- ?
7. Ready?
- yes8. Add to EndpointSlice
- no9. No traffic yet
- 8
8. Add to EndpointSlice
- next10. Loop until matched
- 9
9. No traffic yet
- next10. Loop until matched
- 10
10. Loop until matched
Lesson map
Kubernetes Workloads — Deployments, Probes, Resources & Progressive Delivery
Controllers reconcile desired vs actual. Deployments own ReplicaSets that own Pods. Probes gate traffic and restarts. Requests/limits set QoS and scheduling. Rollouts need PDBs and a progressive strategy. This hub maps the cluster; Ingress/Gateway stays in the Private Networking pages.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB a["1. Write desired state"] b["2. Deployment watches"] c["3. Ensure a ReplicaSet"] d["4. Match the Pod count"] a -->|1. Write desired state| b b -->|2. Deployment watches| c c -->|3. Ensure a ReplicaSet| d
Interview soundbite: Kubernetes is continuous reconciliation. You declare what you want. Controllers fight reality until it matches, or they report why it cannot.
Which controller owns the workload
| Kind | Strength | Cost | Use when |
|---|---|---|---|
| Deployment | Rollouts, history, pause, surge | Pods have no sticky name or disk | APIs and interchangeable workers |
| StatefulSet | Stable name, ordered scale, PVC per ordinal | Slower replace | Brokers, databases, pod-0 and pod-1 |
| DaemonSet | One Pod per selected node | Replica count follows nodes | Log agents, node exporters |
| Job or CronJob | Run to completion, retries, schedule | Not a long-lived Service | Migrations, batch, periodic cleanup |
Rule: interchangeable Pods go on a Deployment. Identity, order, or a disk go on a StatefulSet. "Every node" is a DaemonSet. Finish-and-exit is a Job.
Decisions
- 1
1. What should run
- next2. Pods interchangeable
- ?
2. Pods interchangeable
- yes3. Use a Deployment
- no4. Need sticky identity
- 3
3. Use a Deployment
- ?
4. Need sticky identity
- yes5. Use a StatefulSet
- no6. One Pod per node
- 5
5. Use a StatefulSet
- ?
6. One Pod per node
- yes7. Use a DaemonSet
- no8. Finish and exit
- 7
7. Use a DaemonSet
- 8
8. Finish and exit
- next9. Use Job or CronJob
- 9
9. Use Job or CronJob
What this cluster leaves alone
- Ingress and Gateway API. Host, path, TLS at the edge, and L4 versus L7 entry live in Ingress Controllers & North-South. The map is Private Networking — VPC, NAT, SSM, Tunnels & Ingress. This hub only cares that a Ready Pod can be selected by a Service.
- Service mesh. mTLS, retries, and east-west policy live in Sidecar Pattern & Service Mesh. Do not fold that into a Deployment lecture.
- Secret stores and operators. Rotation and CRDs sit on top of this workload model. Learn the reconcile loop first.
A canary that shifts a percentage of edge traffic still needs the Ingress or mesh lesson for the weight. The workload lesson owns replica surge, analysis, and abort. That split is Rolling, Blue-Green & Canary.
Interview Q&A
What owns what in a Deployment?
Answer
The Deployment owns one or more ReplicaSets. Each ReplicaSet owns the Pods that match its selector and template. A rolling update creates a new ReplicaSet and moves replicas toward it. Details and the knobs are the next page.
Why are readiness and liveness different?
Answer
Readiness removes the Pod from Service traffic and leaves the process running. Liveness restarts a stuck process. Pointing liveness at a shared database turns one slow dependency into a restart storm. The probe page is the full comparison.
What do CPU requests do that limits do not?
Answer
Requests are what the scheduler packs onto a Node, and they set relative CPU weight under contention. A CPU limit throttles. A memory limit can OOMKill. Guaranteed QoS needs request equal to limit for both CPU and memory on every container. That is the QoS lesson.
What does a PDB protect?
Answer
A PodDisruptionBudget limits voluntary disruption (drain, rollout eviction) so you keep minAvailable or stay within maxUnavailable. It does not stop a node from crashing. Strategy math is the rollout lesson.
Why can HPA and VPA on the same resource fight?
Answer
HPA changes replica count from utilization. VPA changes the request size that utilization is divided by. Both chasing CPU can oscillate. Split them: HPA on a custom or external signal, VPA in recommendation or initial mode. The autoscaling lesson derives the formula.
When is a Deployment the wrong controller?
Answer
When Pods are not interchangeable. A database that needs pod-0 and a volume wants a StatefulSet. A node agent wants a DaemonSet. A migration that must exit wants a Job. Using a Deployment there gives you a rollout story and the wrong identity story.
What is the soundbite for a stuck rollout?
Answer
Desired and actual diverged and the controller cannot close the gap: image pull, quota, unschedulable requests, or a probe that never passes. progressDeadlineSeconds turns a long stall into ProgressDeadlineExceeded. You still read Pod status. You do not SSH in and hope.
Where does traffic enter the cluster?
Answer
Not on this page. North-south entry, Ingress, and Gateway API are Ingress Controllers & North-South in Private Networking. Here, "in service" means the Pod is Ready and therefore eligible for an EndpointSlice.
Why not hand-edit a live Pod?
Answer
The owning controller reconciles it away or replaces the Pod. Production policy is to change the template. Orphaning a Pod on purpose is a debug trick, not a deploy strategy. The next lesson shows the ownership chain.
What should you say in the first minute of a Kubernetes interview?
Answer
Controllers close desired versus actual. Deployment owns ReplicaSets owns Pods. Probes split traffic from restarts. Requests schedule, limits enforce. Rollouts need a strategy and a PDB. Autoscaling needs a metric that matches the bottleneck, plus a stabilization window. Ingress is a different cluster.
Pitfalls
- Treating every workload as a Deployment, including databases and node agents.
- One health URL used as both liveness and readiness.
- Requests copied from a tutorial, then Pending Pods because the sum does not fit allocatable CPU.
- A canary story that never mentions how many users are in the blast radius, or a PDB that blocks the node upgrade.
- Re-explaining edge routing when the question was about the reconcile loop.
A staff engineer asks how a Deployment actually updates. Answer with the ownership chain, one probe failure mode, one capacity failure mode, and where you would look if the rollout stalls. Do not draw an edge load balancer.