Kubernetes Internals
Studies in this cluster, in series order. Each one keeps its own URL.
DevOps
Kubernetes workloads, CI/CD pipelines, artifact digests, supply-chain controls, Git rebase, merge, and recovery, and Terraform state, modules, and safe change you can defend in interviews.
Kubernetes Internals
6 studies- 1.Kubernetes Internals - Declarative Reconciliation from kubectl apply to Running PodHub: Kubernetes as a database of intentions plus independent watch-driven loops; imperative vs declarative reconciliation; the full kubectl apply -> running pod path (authn/authz, admission, etcd, Deployment/ReplicaSet controllers, scheduler, kubelet, CRI/CNI/CSI); component contracts, bottlenecks and a layer-picking decision chart. Goes one layer below the existing Workloads series.
- 2.Kubernetes Control Plane - API Server Request Path, etcd, Watches, Informers, Optimistic Concurrency & CRDsControl plane: API server request pipeline (authn, API Priority and Fairness, RBAC, mutating/validating admission, schema validation), etcd limits and compaction, resourceVersion, watches, 410 Gone and relist, 409 optimistic concurrency, shared informers and workqueues, CRDs and operators vs aggregated APIs.
- 3.Scheduler, Controllers & the Kubelet - Filter and Score, Taints, Preemption, Reconcile Loops, Garbage Collection & Pod SyncScheduler, controllers and kubelet: scheduling framework (PreFilter, Filter, Score, Reserve, Permit, Bind), taints/tolerations, affinity and topology spread, priority and preemption; level-triggered reconcile loops, owner references, finalizers and garbage collection; kubelet pod sync, node-pressure eviction and a Pending/ContainerCreating triage chart.
- 4.Kubernetes Storage - Volumes, PV, PVC, StorageClass, CSI, StatefulSets & Failure ModesStorage: volume types, PV/PVC/StorageClass, static vs dynamic provisioning, Immediate vs WaitForFirstConsumer, provision -> bind -> attach -> mount via CSI, access modes (RWO/RWOP/RWX), reclaim policies, StatefulSets with volumeClaimTemplates, expansion and snapshots, zone pinning, Multi-Attach and node-loss failure timelines.
- 5.Helm & Kubernetes Packaging - Charts, Values, Releases, Rollback, Hooks vs Kustomize, Operators & GitOpsPackaging: Helm charts, values precedence, rendering, releases stored as Secrets, upgrade/rollback, 3-way merge vs server-side apply (Helm 4), hooks, dependencies, library charts, CRD handling; compared with Kustomize, raw manifests, operators and GitOps (Argo CD, Flux) with a decision chart.
- 6.Node-Level Scaling - Node Groups, Cluster Autoscaler vs Karpenter, Over-Provisioning, PDBs & DrainsNode scaling: node groups/ASGs/managed node pools, Cluster Autoscaler simulation and expanders, Karpenter NodePools, consolidation and disruption budgets, CA vs Karpenter, scale-up latency budget, over-provisioning with pause pods and CapacityBuffer, PDBs and drains, cost levers. HPA/VPA linked, not re-taught.