---
tags:
- k8s
- l1
- flashcard-deck
- k8s-config
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Core](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
k8s-config/112a65bbecd7	k8s-config	medium	kubernetes, volume-mount, resource-quota, resource-limits	What is Resource Quota?	Resource quota provides constraints that limit aggregate resource consumption per namespace. It can limit the quantity of objects that can be created in a namespace by type, as well as the total amount of compute resources that may be consumed by resources in that namespace.\n\nExample: `kubectl create quota my-quota --hard=pods=10,requests.cpu=4,requests.memory=8Gi -n dev` limits namespace resources.\n\nRemember: Quotas are per-namespace. Think "Quota = Namespace Budget" — each team gets a spending limit.	projects/knowledge/interview/kubernetes/185-what-is-resource-quota.txt
k8s-config/17962354b34b	k8s-config	easy	kubernetes, secret	True or False? storing data in a Secret component makes it automatically secured	"False. Some known security mechanisms like ""encryption"" aren't enabled by default."\n\nGotcha: K8s Secrets are base64-encoded, not encrypted at rest by default. Enable EncryptionConfiguration for etcd encryption.\n\nRemember: "Base64 is a disguise, not a safe" — anyone with etcd access can decode without encryption at rest.\n\nSee also: External secret managers (Vault, AWS Secrets Manager) provide true encryption and rotation.	projects/knowledge/interview/kubernetes/217-true-or-false-storing-data-in-a-secret-component-m.txt
k8s-config/1c1557ee20a7	k8s-config	easy	kubernetes, secret	What is the problem with the following Secret file:	Password isn't encrypted.\nYou should run something like this: `echo -n 'mySecretPassword' | base64` and paste the result to the file instead of using plain-text.\n\nRemember: `echo -n` is critical — without `-n`, a trailing newline gets base64-encoded, causing auth failures.\n\nGotcha: `echo -n 'myPassword' | base64` vs `echo 'myPassword' | base64` produce different results. The newline matters!\n\nExample: Compare: `echo -n 'pass' | base64` → `cGFzcw==` vs `echo 'pass' | base64` → `cGFzcwo=` (extra newline).	projects/knowledge/interview/kubernetes/218-what-is-the-problem-with-the-following-secret-file.txt
k8s-config/20a3c60eccc4	k8s-config	hard	kubernetes, resource-limits	How do you prevent high memory usage in your Kubernetes cluster and possibly issues like memory leak and OOM?	Apply requests and limits, especially on third party applications (where the uncertainty is even bigger)\n\nExample: Set in pod spec: `resources: {limits: {memory: 512Mi}, requests: {memory: 256Mi}}`.\n\nRemember: "Requests = minimum guaranteed, Limits = maximum allowed." Think "Request a seat, Limit the legroom."\n\nGotcha: CPU is throttled; memory is OOMKilled. Over-limit CPU just slows down; over-limit memory kills the container.	projects/knowledge/interview/kubernetes/019-how-do-you-prevent-high-memory-usage-in-your-kuber.txt
k8s-config/2a54fb8b3f1f	k8s-config	medium	kubernetes, secret, security	What is a Secret in Kubernetes?	A Secret is like a ConfigMap but for sensitive data (passwords, tokens, keys). Secrets store base64-encoded data and are intended to be kept confidential (with optional encryption at rest enabled via configuration). Pods use Secrets via environment variables or mounted files, similar to ConfigMaps, but with stricter access controls.\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.	projects/knowledge/interview/kubernetes/424-what-is-secret.txt
k8s-config/2fd691444d71	k8s-config	easy	kubernetes, resource-limits	True or False? Memory is a compressible resource, meaning that when a container reach the memory limit, it will keep running	False. CPU is a compressible resource while memory is a non compressible resource - once a container reached the memory limit, it will be terminated.\n\nRemember: CPU is compressible (throttled when over-limit), memory is NOT (OOMKilled). This distinction is critical.\n\nUnder the hood: Kernel CFS scheduler throttles CPU. OOM killer terminates memory hogs. Different enforcement mechanisms.\n\nGotcha: Over-provision memory to be safe (OOM=crash). CPU can be slightly under-provisioned (just slower).	projects/knowledge/interview/kubernetes/200-true-or-false-memory-is-a-compressible-resource-me.txt
k8s-config/421389c9dbe8	k8s-config	hard	kubernetes, secret, env-vars, volume-mount	How are secrets managed in Kubernetes, and what are best practices for securing them?	* Secrets Management in Kubernetes: Kubernetes stores secrets as base64-encoded data.\n* Secrets are accessed by mounting them into pods as volumes or using them as environment variables.\n* Best practices include using RBAC to control access, avoiding storing sensitive information in image layers, and rotating secrets regularly.\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.	projects/knowledge/interview/kubernetes/354-how-are-secrets-managed-in-kubernetes-and-what-are.txt
k8s-config/4652c6033204	k8s-config	medium	kubernetes, secret	Explain Kubernetes Secrets	Secrets let you store and manage sensitive information (passwords, ssh keys, etc.)\n\nExample: `kubectl create secret generic db-creds --from-literal=user=admin --from-literal=pass=s3cret`\n\nRemember: Secrets are like ConfigMaps wearing sunglasses — same structure, base64-encoded, slightly more restricted access.\n\nGotcha: Secrets stored unencrypted in etcd by default. Enable encryption at rest for production clusters.	projects/knowledge/interview/kubernetes/213-explain-kubernetes-secrets.txt
k8s-config/5e98b871927c	k8s-config	easy	kubernetes, resource-limits	True or False? Resource limits applied on a Pod level meaning, if limits is 2gb RAM and there are two container in a Pod that it's 1gb RAM each	False. It's per container and not per Pod.\n\nRemember: K8s true/false questions test edge cases and defaults. Verify with `kubectl explain <resource>`.\n\nGotcha: Use `kubectl explain <resource>.spec` to check field behavior directly from the CLI.	projects/knowledge/interview/kubernetes/289-true-or-false-resource-limits-applied-on-a-pod-lev.txt
k8s-config/6954ca5b38ee	k8s-config	medium	kubernetes, configmap	What is a Kubernetes ConfigMap and how is it used?	Separate configuration from pods.\nIt's good for cases where you might need to change configuration at some point but you don't want to restart the application or rebuild the image so you create a ConfigMap and connect it to a pod but externally to the pod.\n\nOverall it's good for:\n* Sharing the same configuration between different pods\n* Storing external to the pod configuration\n\nExample: `kubectl create configmap app-cfg --from-file=config.yaml --from-literal=LOG_LEVEL=debug`\n\nGotcha: ConfigMap updates don't auto-restart pods. Use Reloader or hash annotations for rolling updates.	projects/knowledge/interview/kubernetes/240-explain-configmap.txt
k8s-config/737cdcf9fbe9	k8s-config	medium	kubernetes, resource-limits	"Run a pod called ""yay2"" with the image ""python"". Make sure it has resources request of 64Mi memory and 250m CPU and the limits are 128Mi memory and 500m CPU"	`kubectl run yay2 --image=python --dry-run=client -o yaml > pod.yaml`\n\n`vi pod.yaml`\n\n```\nspec:\n  containers:\n  - image: python\n    imagePullPolicy: Always\n    name: yay2\n    resources:\n      limits:\n        cpu: 500m\n        memory: 128Mi\n      requests:\n        cpu: 250m\n        memory: 64Mi\n```\n\n`kubectl apply -f pod.yaml`\n\nRemember: Use `kubectl explain <resource>` to explore API fields interactively from the CLI.	projects/knowledge/interview/kubernetes/292-run-a-pod-called-yay2-with-the-image-python-make-s.txt
k8s-config/7427f641c166	k8s-config	medium	kubernetes, resource-limits	What happens what pods are using too much memory? (more than its limit)	They become candidates to for termination.\n\nUnder the hood: K8s eviction manager monitors memory pressure. Evicts BestEffort→Burstable→Guaranteed.\n\nRemember: "No limits? First to go." Pods without resource requests get BestEffort QoS — evicted first.\n\nSee also: Check node conditions: `kubectl describe node` — look for MemoryPressure.	projects/knowledge/interview/kubernetes/199-what-happens-what-pods-are-using-too-much-memory-m.txt
k8s-config/8115b761caa5	k8s-config	medium	kubernetes, resource-limits	"Run a pod called ""yay"" with the image ""python"" and resources request of 64Mi memory and 250m CPU"	`kubectl run yay --image=python --dry-run=client -o yaml > pod.yaml`\n\n`vi pod.yaml`\n\n```\nspec:\n  containers:\n  - image: python\n    imagePullPolicy: Always\n    name: yay\n    resources:\n      requests:\n        cpu: 250m\n        memory: 64Mi\n```\n\n`kubectl apply -f pod.yaml`\n\nRemember: Use `kubectl explain <resource>` to explore API fields interactively from the CLI.	projects/knowledge/interview/kubernetes/291-run-a-pod-called-yay-with-the-image-python-and-res.txt
k8s-config/828a1ede19e4	k8s-config	medium	kubernetes, resource-limits	What QoS classes are there?	* Guaranteed\n* Burstable\n* BestEffort\n\nRemember: QoS eviction order: BestEffort first, Burstable second, Guaranteed last. Mnemonic: "BBG."\n\nUnder the hood: Guaranteed=requests==limits for ALL containers. Burstable=at least one request. BestEffort=zero.\n\nGotcha: Miss one container's limits and the pod drops from Guaranteed to Burstable.	projects/knowledge/interview/kubernetes/246-what-qos-classes-are-there.txt
k8s-config/834954cd0918	k8s-config	hard	kubernetes, secret	How to commit secrets to Git and in general how to use encrypted secrets?	One possible process would be as follows:\n\n1. You create a Kubernetes secret (but don't commit it)\n2. You encrypt it using some 3rd party project (.e.g kubeseal)\n3. You apply the sealed/encrypted secret\n4. You commit the sealed secret to Git\n5. You deploy an application that requires the secret and it can be automatically decrypted by using for example a Bitnami Sealed secrets controller\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.	projects/knowledge/interview/kubernetes/220-how-to-commit-secrets-to-git-and-in-general-how-to.txt
k8s-config/88cec447db9f	k8s-config	easy	kubernetes, configmap, configuration	What is a ConfigMap in Kubernetes?	A ConfigMap is an object to store non-sensitive configuration data as key-value pairs. Pods can consume ConfigMaps as environment variables or config files. This decouples configuration from container images.\n\nExample: `kubectl create configmap app-cfg --from-file=config.yaml --from-literal=LOG_LEVEL=debug`\n\nGotcha: ConfigMap updates don't auto-restart pods. Use Reloader or hash annotations for rolling updates.\n\nRemember: ConfigMaps decouple config from images — same image, different config per environment.	projects/knowledge/interview/kubernetes/423-what-is-configmap.txt
k8s-config/b402ec923a20	k8s-config	medium	kubernetes, secret	How to create a Secret from a key and value?	`kubectl create secret generic some-secret --from-literal=password='donttellmypassword'`\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.\n\nExample: `kubectl create secret generic ssh-key --from-file=ssh-privatekey=~/.ssh/id_rsa`	projects/knowledge/interview/kubernetes/214-how-to-create-a-secret-from-a-key-and-value.txt
k8s-config/bde5dbc45c69	k8s-config	hard	kubernetes, configmap, env-vars	What is a ConfigMap, and how is it used in Kubernetes?	**ConfigMap:**\n* Kubernetes resource that stores configuration data in key-value pairs.\n* Decouples configuration from application code.\n* Can be used to store configuration files, command-line arguments, environment variables, etc.\n* ConfigMaps allow for the separation of configuration from application logic, making it easier to manage and update configurations without modifying the application code.Applications can reference ConfigMaps, and changes to the ConfigMap are automatically reflected in the pods that reference it.\n\nExample: `kubectl create configmap app-cfg --from-file=config.yaml --from-literal=LOG_LEVEL=debug`\n\nGotcha: ConfigMap updates don't auto-restart pods. Use Reloader or hash annotations for rolling updates.	projects/knowledge/interview/kubernetes/316-what-is-a-configmap-and-how-is-it-used-in-kubernet.txt
k8s-config/c5237d20a5ae	k8s-config	easy	kubernetes, configuration	"What is a ""ConfigMap""?"	An object used to store non-sensitive configuration data.\n\nExample: `kubectl create configmap app-cfg --from-file=config.yaml --from-literal=LOG_LEVEL=debug`\n\nGotcha: ConfigMap updates don't auto-restart pods. Use Reloader or hash annotations for rolling updates.\n\nRemember: ConfigMaps decouple config from images — same image, different config per environment.	projects/knowledge/interview/kubernetes/425-configmap.txt
k8s-config/caa106c449bd	k8s-config	medium	kubernetes, resource-limits, pod-disruption	Explain the concept of PodDisruptionBudget in Kubernetes.	* PodDisruptionBudget: PodDisruptionBudget is a resource in Kubernetes that defines policies for pod disruptions during voluntary disruptions (e.g., rolling updates).\n* It limits the number of concurrently disrupted pods and ensures that a minimum number of replicas are available during disruptions.\n* Helps prevent service disruption and ensures stability during maintenance activities.\n* PodDisruptionBudgets are useful for controlling the impact of disruptions, reducing the risk of service degradation during planned maintenance or updates. \n* They provide a balance between maintaining high availability and executing necessary maintenance tasks.	projects/knowledge/interview/kubernetes/334-explain-the-concept-of-poddisruptionbudget-in-kube.txt
k8s-config/d5338f5b4db3	k8s-config	medium	kubernetes, resource-quota, resource-limits	How to create a Resource Quota?	kubectl create quota some-quota --hard=cpu=2,pods=2\n\nExample: `kubectl create quota my-quota --hard=pods=10,requests.cpu=4,requests.memory=8Gi -n dev` limits namespace resources.\n\nRemember: Quotas are per-namespace. Think "Quota = Namespace Budget" — each team gets a spending limit.\n\nGotcha: If a ResourceQuota exists but pod specs omit requests/limits, pods are rejected. Pair with LimitRange for defaults.	projects/knowledge/interview/kubernetes/186-how-to-create-a-resource-quota.txt
k8s-config/da2850350079	k8s-config	hard	kubernetes, configmap, secret	True or False? Sensitive data, like credentials, should be stored in a ConfigMap	False. Use secret.\n\nRemember: Sensitive data → Secrets, not ConfigMaps. ConfigMaps are plain text, visible to namespace users.\n\nGotcha: Even Secrets are only base64-encoded by default. Enable encryption at rest + RBAC.\n\nSee also: External Secrets Operator syncs from Vault/AWS into K8s Secrets automatically.	projects/knowledge/interview/kubernetes/242-true-or-false-sensitive-data-like-credentials-shou.txt
k8s-config/db5b9c0f3f76	k8s-config	medium	kubernetes, configmap, env-vars, volume-mount	How to use ConfigMaps?	1. Create it (from key&value, a file or an env file)\n2. Attach it. Mount a configmap as a volume\n\nRemember: `--dry-run=client -o yaml` generates templates. Pipe to a file and customize.\n\nGotcha: `create` = imperative (fails if exists). `apply` = declarative (creates or updates). Production = `apply`.	projects/knowledge/interview/kubernetes/241-how-to-use-configmaps.txt
k8s-config/dee68559a42c	k8s-config	medium	kubernetes, resource-limits	Explain why one would specify resource limits in regards to Pods	* You know how much RAM and/or CPU your app should be consuming and anything above that is not valid\n* You would like to make sure that everyone can run their apps in the cluster and resources are not being solely used by one type of application\n\nRemember: Use `kubectl explain <resource>` to explore API fields interactively from the CLI.	projects/knowledge/interview/kubernetes/288-explain-why-one-would-specify-resource-limits-in-r.txt
k8s-config/e340b8b10705	k8s-config	hard	kubernetes, secret	Explain how Kubernetes secrets are managed and secured.	* Kubernetes Secrets: Secrets in Kubernetes store sensitive information like passwords, API keys, or certificates.\n* They are stored in etcd, the distributed key-value store, and are base64-encoded for encoding.\n* Access to secrets is controlled through RBAC (Role-Based Access Control) to ensure secure handling.\n* Kubernetes Secrets provide a secure way to manage sensitive information required by applications. \n* They are accessible only to authorized entities, and the use of RBAC ensures that only authorized users or processes can access and manipulate secrets.	projects/knowledge/interview/kubernetes/337-explain-how-kubernetes-secrets-are-managed-and-sec.txt
k8s-config/e7926baabb03	k8s-config	medium	kubernetes, secret	What type: Opaque in a secret file means? What other types are there?	Opaque is the default type used for key-value pairs.\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.\n\nExample: `kubectl create secret generic ssh-key --from-file=ssh-privatekey=~/.ssh/id_rsa`	projects/knowledge/interview/kubernetes/216-what-type-opaque-in-a-secret-file-means-what-other.txt
k8s-config/eb4419e362ab	k8s-config	medium	kubernetes, secret	How to create a Secret from a file?	`kubectl create secret generic some-secret --from-file=/some/file.txt`\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.\n\nExample: `kubectl create secret generic ssh-key --from-file=ssh-privatekey=~/.ssh/id_rsa`	projects/knowledge/interview/kubernetes/215-how-to-create-a-secret-from-a-file.txt
k8s-config/eeba1f59c35b	k8s-config	medium	kubernetes, configmap, secret	Explain how ConfigMap and Secret updates are handled in Kubernetes.	* ConfigMap and Secret Updates: Changes to ConfigMaps or Secrets trigger updates in associated pods automatically.\n* Pods referencing ConfigMaps or Secrets receive notifications about updates.\n* Containers in the pod can watch for changes and adapt their configurations dynamically.\n* ConfigMap and Secret updates are dynamically propagated to pods using them. \n* Containers within pods can watch for changes and reconfigure themselves accordingly, ensuring that any modifications to configuration data are seamlessly applied.\n\nExample: `kubectl create secret generic db-creds --from-literal=user=admin --from-literal=pass=s3cret`\n\nRemember: Secrets are like ConfigMaps wearing sunglasses — same structure, base64-encoded, slightly more restricted access.	projects/knowledge/interview/kubernetes/342-explain-how-configmap-and-secret-updates-are-handl.txt
k8s-config/f35f8503edae	k8s-config	easy	kubernetes, security	What is a Kubernetes Secret and how does it store sensitive data?	An object for storing sensitive data like passwords or tokens.\n\nRemember: `kubectl create secret generic` supports `--from-literal`, `--from-file`, `--from-env-file`.\n\nGotcha: Special chars need shell quoting. Use single quotes: `--from-literal=pass='p@ss!'`.\n\nExample: `kubectl create secret generic ssh-key --from-file=ssh-privatekey=~/.ssh/id_rsa`	projects/knowledge/interview/kubernetes/426-secret.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Adversarial Interview Gauntlet (30 sequences)](../../../../library/interview-scenarios/gauntlet/README.md) (Scenario, L2) — Kubernetes Core
- [Case Study: Alert Storm — Flapping Health Checks](../../../../library/case-studies/cross-domain/alert-storm-flapping-healthchecks/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Canary Deploy Routing to Wrong Backend — Ingress Misconfigured](../../../../library/case-studies/cross-domain/canary-deploy-wrong-backend-ingress/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: CrashLoopBackOff No Logs](../../../../library/case-studies/kubernetes_ops/crashloopbackoff-no-logs/README.md) (Case Study, L1) — Kubernetes Core
- [Case Study: DNS Looks Broken — TLS Expired, Fix Is Cert-Manager](../../../../library/case-studies/cross-domain/dns-tls-certmanager/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: DaemonSet Blocks Eviction](../../../../library/case-studies/kubernetes_ops/daemonset-blocks-eviction/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Deployment Stuck — ImagePull Auth Failure, Vault Secret Rotation](../../../../library/case-studies/cross-domain/deployment-stuck-imagepull-vault/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Drain Blocked by PDB](../../../../library/case-studies/kubernetes_ops/drain-blocked-by-pdb/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: HPA Flapping — Metrics Server Clock Skew, Fix Is NTP](../../../../library/case-studies/cross-domain/hpa-flapping-clock-skew-ntp/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: ImagePullBackOff Registry Auth](../../../../library/case-studies/kubernetes_ops/imagepullbackoff-registry-auth/README.md) (Case Study, L1) — Kubernetes Core

<!-- wiki:related:end -->
