---
tags:
- k8s
- l1
- flashcard-deck
- k8s-concept-chain
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Concept Chain](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
k8s-concept-chain/a1b2c3d401	k8s-concept-chain	easy	k8s,pods,containers	What happens when you run a container as a bare Pod in Kubernetes and it crashes?	It stays dead. Nobody restarts it. A bare Pod has no controller managing its lifecycle.\n\nRemember: Never run bare Pods in production. Always use a Deployment (or StatefulSet/DaemonSet).	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d402	k8s-concept-chain	easy	k8s,deployment,self-healing	What problem does a Deployment solve that bare Pods cannot?	A Deployment ensures a desired number of replicas are always running. If a Pod dies, the Deployment controller creates a replacement automatically.\n\nRemember: Deployment → ReplicaSet → Pods. The Deployment manages ReplicaSets for rolling updates.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d403	k8s-concept-chain	easy	k8s,service,networking	Why can't you hardcode Pod IPs to let services communicate?	Pods get a new IP every time they restart or reschedule. At scale, IPs change constantly. A Service provides one stable ClusterIP that routes to healthy Pods using label selectors.\n\nRemember: Services use labels, not IPs. Pods die and come back — the Service does not care.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d404	k8s-concept-chain	easy	k8s,service,types	What are the four Kubernetes Service types, from most to least restrictive?	1. ClusterIP — internal only (default)\n2. NodePort — static port on every node (30000-32767)\n3. LoadBalancer — provisions an external cloud LB\n4. ExternalName — DNS CNAME redirect, no proxying\n\nRemember: ClusterIP is the default. Each type builds on the previous one.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d405	k8s-concept-chain	easy	k8s,ingress,routing	What problem does Ingress solve that Services alone cannot?	With Services, each externally-exposed service needs its own LoadBalancer (one cloud LB each, at ~$18-20/month). Ingress provides L7 routing (hostname + path) so one load balancer can serve many services.\n\nRemember: Ingress = one LB, many services, smart routing by host/path.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d406	k8s-concept-chain	easy	k8s,ingress-controller	Why do Ingress resources do nothing by themselves?	Ingress is just a set of routing rules. An Ingress Controller (nginx, Traefik, AWS LB Controller) must be deployed to watch Ingress resources and actually configure traffic routing.\n\nGotcha: No Ingress Controller deployed = Ingress resources are completely inert. No errors, no warnings — just silence.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d407	k8s-concept-chain	easy	k8s,configmap,configuration	What problem does a ConfigMap solve?	Hardcoding config inside the container image means rebuilding for every config change and risking wrong values per environment. A ConfigMap externalizes config so the same image runs in dev, staging, and prod with different settings injected at runtime.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d408	k8s-concept-chain	easy	k8s,secret,security	Why should you use a Secret instead of a ConfigMap for passwords?	ConfigMaps have no special access controls — anyone who can read ConfigMaps in the namespace sees the data. Secrets have separate RBAC controls and are meant for sensitive data like passwords, tokens, and TLS certs.\n\nGotcha: Secrets are base64-encoded, NOT encrypted. Enable etcd encryption at rest for real protection.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d409	k8s-concept-chain	medium	k8s,hpa,autoscaling	What does HPA do and what problem remains after you enable it?	HPA (Horizontal Pod Autoscaler) watches metrics (CPU, memory, custom) and adjusts Deployment replica count automatically. But HPA only creates Pods — if nodes are full, new Pods sit in Pending state.\n\nRemember: HPA scales Pods. Karpenter/Cluster Autoscaler scales nodes. You often need both.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d410	k8s-concept-chain	medium	k8s,karpenter,node-autoscaling	How does Karpenter differ from Cluster Autoscaler?	Cluster Autoscaler adjusts node group sizes (ASGs/MIGs) — slower, constrained to predefined instance types. Karpenter provisions right-sized nodes directly based on pending Pod requirements — faster, more flexible.\n\nRemember: Karpenter = fast, right-sized nodes. Cluster Autoscaler = adjusts existing node groups.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d411	k8s-concept-chain	medium	k8s,resources,requests,limits	What is the difference between resource requests and limits?	Requests = minimum guaranteed resources for scheduling. The scheduler places the Pod on a node with enough unrequested capacity.\nLimits = maximum a container can consume. CPU limits cause throttling; memory limits cause OOMKill.\n\nRemember: Requests are for the scheduler. Limits are for enforcement.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d412	k8s-concept-chain	medium	k8s,qos,resources	What are the three Kubernetes QoS classes and how are they determined?	Guaranteed: requests == limits for all containers (last evicted)\nBurstable: requests < limits or only requests set (middle)\nBestEffort: no requests or limits at all (first evicted)\n\nRemember: QoS class determines eviction order under memory pressure. BestEffort dies first.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d413	k8s-concept-chain	medium	k8s,deployment,replicaset	What is the relationship between Deployment, ReplicaSet, and Pod?	Deployment manages ReplicaSets. ReplicaSet manages Pods. During a rolling update, the Deployment creates a new ReplicaSet (with the updated spec) and scales it up while scaling the old ReplicaSet down.\n\nRemember: Deployment → ReplicaSet → Pods. Never edit ReplicaSets directly.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d414	k8s-concept-chain	medium	k8s,service,endpoints	How does a Kubernetes Service find the right Pods to route traffic to?	The Service uses label selectors to match Pods. Matching Pods are added to the Service's Endpoints list. kube-proxy (or the CNI) programs iptables/IPVS rules to route Service IP traffic to endpoint Pod IPs.\n\nRemember: No label match = no endpoints = Service returns connection refused.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d415	k8s-concept-chain	medium	k8s,configmap,update	What happens to running Pods when you update a ConfigMap?	Nothing — automatically. Pods using env var injection keep the old values until restarted. Pods using volume mounts see updates after the kubelet sync period (default ~60s), but the app must re-read the files.\n\nGotcha: ConfigMap updates don't trigger Pod restarts. Use `kubectl rollout restart` or a checksum annotation.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d416	k8s-concept-chain	medium	k8s,secret,encryption	Are Kubernetes Secrets encrypted at rest by default?	No. Secrets are base64-encoded (not encrypted) and stored in etcd in cleartext by default. You must explicitly configure encryption at rest via EncryptionConfiguration at the API server level.\n\nRemember: base64 != encryption. Anyone with etcd access sees all Secrets without encryption at rest.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d417	k8s-concept-chain	medium	k8s,hpa,conflict	What happens when you set replicas in a Deployment manifest and also use HPA?	Every time you `kubectl apply` the manifest, it resets the replica count to the hardcoded value, overriding HPA's scaling decisions.\n\nFix: remove the `replicas` field from the Deployment manifest when using HPA, or use server-side apply.	training/library/topics/k8s-concept-chain/footguns.md
k8s-concept-chain/a1b2c3d418	k8s-concept-chain	hard	k8s,cpu,throttling	Why do some teams set CPU requests but no CPU limits?	CPU limits cause kernel-level throttling (CFS quota) even when the node has spare CPU capacity. This creates unpredictable latency spikes. Memory limits should always be set (OOM is catastrophic), but CPU throttling is annoying rather than fatal.\n\nRemember: CPU limit = throttle. Memory limit = OOMKill. Different failure modes require different strategies.	training/library/topics/k8s-concept-chain/footguns.md
k8s-concept-chain/a1b2c3d419	k8s-concept-chain	hard	k8s,pdb,autoscaling	Why is a PodDisruptionBudget important when using node autoscaling?	Without a PDB, Karpenter or Cluster Autoscaler can evict all replicas of a service from a node simultaneously during scale-down. A PDB (minAvailable or maxUnavailable) ensures the autoscaler respects application availability during node drains.\n\nRemember: PDB protects against voluntary disruptions — node drains, autoscaler evictions, maintenance.	training/library/topics/k8s-concept-chain/footguns.md
k8s-concept-chain/a1b2c3d420	k8s-concept-chain	hard	k8s,ingress,troubleshooting	You applied an Ingress resource but traffic returns 404. What are the three most likely causes?	1. No Ingress Controller is deployed in the cluster (Ingress resources are inert)\n2. The backend service name or port in the Ingress spec is wrong\n3. The backend Service has no endpoints (selector labels don't match Pod labels)\n\nDebug: kubectl get pods -n ingress-nginx, kubectl describe ingress NAME, kubectl get endpoints BACKEND_SVC	training/library/topics/k8s-concept-chain/street_ops.md
k8s-concept-chain/a1b2c3d421	k8s-concept-chain	hard	k8s,pending,troubleshooting	Pods are stuck in Pending state. Walk through the diagnostic steps.	1. kubectl describe pod NAME — check Events for "Insufficient cpu" or "Insufficient memory"\n2. kubectl describe nodes — check Allocated resources vs Allocatable\n3. Check if node autoscaler (Karpenter/CA) is running and has capacity to provision\n4. Check if PersistentVolumeClaims are pending (storage-bound scheduling)\n5. Check taints/tolerations and nodeSelector constraints\n\nRemember: Pending = scheduler can't place the Pod. The Events section tells you why.	training/library/topics/k8s-concept-chain/street_ops.md
k8s-concept-chain/a1b2c3d422	k8s-concept-chain	hard	k8s,resources,starvation	A single Pod with no resource limits consumes all memory on a node. What happens to other Pods?	The kernel OOM killer fires. It targets processes by OOM score. Pods with QoS BestEffort (no requests/limits) are killed first, then Burstable, then Guaranteed. The rogue Pod (also BestEffort) may or may not be the one killed — it depends on OOM scoring.\n\nFix: always set memory limits. Use LimitRange to enforce defaults namespace-wide.	training/library/topics/k8s-concept-chain/footguns.md
k8s-concept-chain/a1b2c3d423	k8s-concept-chain	medium	k8s,dns,service	What DNS name does Kubernetes create for a ClusterIP Service?	<service-name>.<namespace>.svc.cluster.local\n\nWithin the same namespace, you can use just the service name. Cross-namespace, use <service>.<namespace> or the full FQDN.\n\nRemember: CoreDNS runs in kube-system and auto-discovers Services. Pod /etc/resolv.conf points to it.	training/library/topics/k8s-concept-chain/primer.md
k8s-concept-chain/a1b2c3d424	k8s-concept-chain	easy	k8s,concepts,chain	What is the Kubernetes concept chain?	Each K8s abstraction exists because the previous layer has an unresolved problem:\nPod crashes → Deployment\nIPs change → Service\nToo many LBs → Ingress\nRules need engine → Ingress Controller\nConfig in image → ConfigMap\nPasswords exposed → Secret\nManual scaling → HPA\nNodes full → Karpenter\nRogue resources → Requests & Limits\n\nRemember: Every K8s concept is a solution to a specific problem. Learn the problems, and the solutions make sense.	training/library/topics/k8s-concept-chain/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Kubernetes Concept Chain](../../../../library/topics/k8s-concept-chain/index.md) (Topic Pack, L0) — Kubernetes Concept Chain

<!-- wiki:related:end -->
