Master Pod scheduling, CrashLoopBackOff resolution, Ingress routing, StatefulSets/DaemonSets, EKS setups, HPA, and NetworkPolicies.
SM
Written by Sachin Mehta • Founder & Principal Cloud ArchitectPrincipal cloud infrastructure specialist and systems architect. CKA & CKS certified.
Interactive Flashcards
# 1
Unreviewed
Explain the differences between a Pod, a ReplicaSet, and a Deployment.
Answer Guide
A Pod is the smallest deployable unit in Kubernetes, hosting one or more containers. A ReplicaSet ensures that a specified number of pod replicas are running at any given time. A Deployment is a higher-level controller that manages ReplicaSets, enabling declarative updates to Pods (rolling updates, rollbacks) without manual intervention.
Key Concepts Checklist
Evaluate difficulty:
# 2
Unreviewed
What is a CrashLoopBackOff error, and what are its common causes?
Answer Guide
CrashLoopBackOff means that a pod is repeatedly starting, failing, and restarting, with Kubernetes delaying restarts progressively. Common causes include application configuration errors (missing env vars/secrets), volume mount failures, port binding conflicts, out-of-memory (OOM) kills, or lack of connectivity to dependency services.
Key Concepts Checklist
Evaluate difficulty:
# 3
Unreviewed
What is the difference between ConfigMaps and Secrets in Kubernetes?
Answer Guide
ConfigMaps are used to store non-sensitive configuration data (like file paths, properties, env vars) in plain-text key-value pairs. Secrets are used to store sensitive data (like passwords, API keys, certificates) encoded in Base64 (though not encrypted by default; encryption at rest must be enabled separately in the cluster).
Key Concepts Checklist
Evaluate difficulty:
# 4
Unreviewed
What are Taints and Tolerations in Kubernetes?
Answer Guide
Taints are attributes applied to Nodes that prevent Pods from being scheduled on them unless the Pods have matching Tolerations. This allows a cluster administrator to dedicate nodes for specific workloads (e.g., GPU nodes, control-plane nodes, or system-critical nodes).
Key Concepts Checklist
Evaluate difficulty:
# 5
Unreviewed
What is the purpose of the Kubernetes Ingress resource?
Answer Guide
Ingress is an API object that manages external access to services within the cluster, typically via HTTP/HTTPS. It acts as an entry point/reverse proxy, providing routing rules (e.g., domain hostnames, paths), SSL/TLS termination, and load balancing, replacing individual LoadBalancer services.
Key Concepts Checklist
Evaluate difficulty:
# 6
Unreviewed
How do HPA and VPA differ in Kubernetes?
Answer Guide
HPA (Horizontal Pod Autoscaler) adjusts the number of Pod replicas based on CPU/memory usage or custom metrics. VPA (Vertical Pod Autoscaler) adjusts the CPU and memory resource requests/limits of the existing Pod containers. They generally cannot be used together on the same resource metrics.
Key Concepts Checklist
Evaluate difficulty:
# 7
Unreviewed
What are Kubernetes DaemonSets and StatefulSets?
Answer Guide
A DaemonSet ensures that all (or some) Nodes run a single copy of a Pod (typically used for log collectors like Fluentd or monitoring agents like Prometheus node-exporter). A StatefulSet manages stateful applications, providing unique, persistent network identifiers, and dedicated persistent volumes that stick with the pods.
Key Concepts Checklist
Evaluate difficulty:
# 8
Unreviewed
Explain IAM Roles for Service Accounts (IRSA) in EKS.
Answer Guide
IRSA allows you to associate an AWS IAM Role directly with a Kubernetes Service Account. Using OpenID Connect (OIDC) federation, pods configured with this service account receive short-lived AWS credentials, eliminating the need to assign IAM permissions to the EKS worker nodes themselves.
Key Concepts Checklist
Evaluate difficulty:
# 9
Unreviewed
What is the difference between Cluster Autoscaler and Karpenter?
Answer Guide
Cluster Autoscaler scales AWS EC2 Auto Scaling Groups up or down in response to pending pods. Karpenter is a modern, high-performance node provisioner that directly calls AWS EC2 APIs to provision right-sized nodes in seconds without using Auto Scaling Groups, optimizing compute costs.
Key Concepts Checklist
Evaluate difficulty:
# 10
Unreviewed
What are the different types of Services in Kubernetes?
Answer Guide
1. ClusterIP (default): Exposes the service on a cluster-internal IP. 2. NodePort: Exposes the service on each Node's IP at a static port (30000-32767). 3. LoadBalancer: Exposes the service externally using a cloud provider's load balancer. 4. ExternalName: Maps the service to a DNS name.
Key Concepts Checklist
Evaluate difficulty:
# 11
Unreviewed
How do two pods in different namespaces communicate?
Answer Guide
They communicate using CoreDNS. The syntax is "<service-name>.<namespace>.svc.cluster.local". If there are NetworkPolicies defined, the policy must explicitly permit ingress/egress traffic between the source and target namespaces.
Key Concepts Checklist
Evaluate difficulty:
# 12
Unreviewed
How do you troubleshoot a worker node in NotReady status?
Answer Guide
1. Run "kubectl describe node <node>" to inspect events and conditions (DiskPressure, MemoryPressure). 2. SSH into the worker node. 3. Check kubelet service status using "systemctl status kubelet". 4. Check container runtime logs (containerd) and check for resource exhaustion (disk/memory limits).
Key Concepts Checklist
Evaluate difficulty:
Scenario Challenges
Select a scenario below to test your troubleshooting workflow.
Topic: Pod CrashLoopBackOff
A critical backend pod keeps restarting with a CrashLoopBackOff error. Diagnose and fix the crash.
Run kubectl get pods followed by kubectl logs -p <pod-name> to inspect logs from the previous failed container instance.Click to select
Identify the crash reason (e.g. database credentials missing) from the log output.Click to select
Update the ConfigMap/Secret manifests, re-apply them, and run kubectl rollout restart deployment to fetch updates.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Ingress Controller Setup
Expose a microservice securely using HTTPS via an Ingress resource in an Amazon EKS cluster. Arrange the configuration steps.
Deploy the AWS Load Balancer Controller in the EKS cluster to process Ingress resources.Click to select
Create an Ingress manifest specifying paths, backend services, and ACM certificate annotations.Click to select
Apply the Ingress rule, allowing the controller to provision an AWS ALB and register target groups.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Implementing HPA
Configure Horizontal Pod Autoscaling (HPA) to scale replicas dynamically under load. Order the operations.
Deploy the Metrics Server in the cluster to expose node/pod resource metrics.Click to select
Add resources.requests.cpu and resources.limits.cpu specifications to your pod deployment template.Click to select
Deploy the HPA manifest targeting the deployment with min/max replicas and CPU usage percentage trigger.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Node Eviction Mitigation
A Kubernetes worker node is throwing DiskPressure alarms and evicting pods. Address the issue.
Run kubectl describe node <node-name> to review status flags and determine disk exhaustion.Click to select
Connect to the node, clean up dangling docker layers, and configure log rotation policies.Click to select
Modify the Pod definitions to include explicit resource limits to prevent single container disk/memory abuse.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Cross-Namespace Connection
Establish secure communication between an app pod in frontend namespace and a database pod in backend namespace.
Update the frontend connection URI to DB DNS format: db-service.backend.svc.cluster.local.Click to select
Configure a NetworkPolicy in the backend namespace that permits ingress from pods matching frontend labels.Click to select
Test connection by executing nc -zv from frontend container terminal and reviewing logs.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
We value your privacy
We use cookies to analyze site traffic, personalize content, and support our free educational platforms. By clicking "Accept All", you consent to our use of cookies.