Scoring Rubric - Kubernetes¶
Score 0-1¶
- Don't know what Kubernetes is for
- Haven't used kubectl
Score 2-3¶
- Can explain pods, deployments, services at a high level
- Have deployed something with
kubectl apply -f - Need to look up every kubectl command
- Don't understand how services route to pods
Score 4-5¶
- Can create deployments, services, configmaps from memory
- Understand labels, selectors, and how services find pods
- Can read
kubectl describeoutput and identify basic problems - Know the difference between ClusterIP, NodePort, LoadBalancer
- Can do basic debugging:
kubectl logs,kubectl exec - "You are here if you can": deploy an app, expose it, and check its logs without looking up syntax
Score 6-7¶
- Understand the control loop: desired state vs actual state
- Can debug CrashLoopBackOff, ImagePullBackOff, Pending pods
- Understand RBAC: roles, bindings, service accounts
- Know how to use resource requests/limits correctly
- Can explain probes (liveness, readiness, startup) and when to use each
- Comfortable with Helm values, templates, releases
- Can perform rolling updates and rollbacks
- "You are here if you can": diagnose why a pod is pending and fix it, explain the difference between liveness and readiness probes, and deploy with Helm
Score 8¶
- Can perform node maintenance (cordon, drain, uncordon) safely
- Understand PodDisruptionBudgets and when they matter
- Can debug network policies, DNS issues, and service mesh problems
- Know version skew rules for cluster upgrades
- Understand etcd's role and can take snapshots
- Can explain how the scheduler makes placement decisions
- Know the difference between voluntary and involuntary disruptions
- "You are here if you can": upgrade a cluster node without dropping traffic, explain why a network policy isn't working, and design a proper PDB strategy
Score 9¶
- Deep understanding of kube-apiserver, etcd, scheduler, controller-manager internals
- Can diagnose problems at the API server audit log level
- Understand CRI, CNI, CSI plugin interfaces
- Can debug kubelet issues, certificate expiration, control plane failures
- Have dealt with split-brain, etcd quorum loss, or API server overload
- "You are here if you can": recover a cluster from etcd backup, debug a kubelet that won't register, or explain the admission controller chain