---
tags:
- k8s
- l1
- flashcard-deck
- k8s-core
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Core](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
k8s-core/0018698ddade	k8s-core	medium	kubernetes, scheduler, node	What the master node is responsible for?	The master coordinates all the workflows in the cluster:\n\n* Scheduling applications\n* Managing desired state\n* Rolling out new updates\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/012-what-the-master-node-is-responsible-for.txt
k8s-core/00751ac0607c	k8s-core	medium	kubernetes, api-server, controller-manager	What is the role of kube-apiserver aggregation layer in Kubernetes?	* kube-apiserver Aggregation Layer: The aggregation layer extends the kube-apiserver to support custom APIs and resources.\n* It allows third-party APIs and controllers to be seamlessly integrated into the Kubernetes API.\n* Facilitates the development and deployment of custom extensions by different organizations or vendors.\n* The kube-apiserver aggregation layer enables the Kubernetes API to be extensible, supporting custom resources and APIs beyond the core Kubernetes objects. \n* This extensibility is essential for accommodating a wide range of use cases and domain-specific requirements.	projects/knowledge/interview/kubernetes/336-what-is-the-role-of-kube-apiserver-aggregation-lay.txt
k8s-core/0191f9fa0aeb	k8s-core	easy	kubernetes, node, pod	What is the role of the kube-proxy in Kubernetes networking?	Network proxy that runs on each node in the cluster. \nMaintains network rules on nodes, enabling communication between pods and services. \nImplements load balancing for services with multiple pod instances. \nkube-proxy plays a key role in Kubernetes networking by managing network connectivity for pods and services. It ensures that communication is correctly routed between pods and facilitates the exposure of services to the external network. Load balancing of service traffic is achieved by kube-proxy distributing requests among the available pod instances.	projects/knowledge/interview/kubernetes/321-what-is-the-role-of-the-kube-proxy-in-kubernetes-n.txt
k8s-core/0380752a57a8	k8s-core	easy	kubernetes, etcd, node	What is etcd and what role does it play in Kubernetes?	Kubernetes uses etcd as a distributed key-value store for all of its data, including metadata and configuration data, and allows nodes in Kubernetes clusters to read and write data. Although etcd was purposely built for CoreOS, it also works on a variety of operating systems (e.g., Linux, BSD, and OS X) because it is open-source. Etcd represents the state of a cluster at a specific moment in time and is a canonical hub for state management and cluster coordination of a Kubernetes cluster.	projects/knowledge/interview/kubernetes/398-what-is-etcd.txt
k8s-core/05630c40ec2b	k8s-core	easy	kubernetes, node, pod	What are the possible Pod phases?	* Running - The Pod bound to a node and at least one container is running\n  * Failed/Error - At least one container in the Pod terminated with a failure\n  * Succeeded - Every container in the Pod terminated with success\n  * Unknown - Pod's state could not be obtained\n  * Pending - Containers are not yet running (Perhaps images are still being downloaded or the pod wasn't scheduled yet)\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/032-what-are-the-possible-pod-phases.txt
k8s-core/0602657902a2	k8s-core	hard	kubernetes, controller-manager, node	What is the purpose of the kube-controller-manager in Kubernetes?	* kube-controller-manager: The kube-controller-manager runs controller processes that regulate the state of the system.\n* Various controllers include Node Controller, Replication Controller, and Endpoints Controller.\n* Each controller manages specific aspects, ensuring that the desired state is maintained.\n* kube-controller-manager hosts multiple controllers, each responsible for specific tasks related to maintaining the desired state of the Kubernetes cluster. \n* These controllers work collaboratively to manage nodes, ensure replica sets are maintained, and update endpoints as services change.\n\nRemember: Controllers run reconciliation loops: desired state vs actual state → take action.\n\nExample: ReplicaSet controller: 2 running, 3 desired → create 1. That's reconciliation.	projects/knowledge/interview/kubernetes/333-what-is-the-purpose-of-the-kube-controller-manager.txt
k8s-core/08783c1fb5b3	k8s-core	medium	kubernetes, namespace, node	Which components can't be created within a namespace?	Volume and Node.\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/189-which-components-cant-be-created-within-a-namespac.txt
k8s-core/08d0be968e72	k8s-core	medium	kubernetes, pod	Discuss the relationship between Kubernetes and container runtimes like Docker and containerd.	* Kubernetes and Container Runtimes: Kubernetes interacts with container runtimes to deploy and manage containers.\n* Common container runtimes include Docker, containerd, and others.\n* Kubernetes abstracts the container runtime, allowing flexibility in choosing the underlying technology.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/359-discuss-the-relationship-between-kubernetes-and-co.txt
k8s-core/09b240933eac	k8s-core	medium	kubernetes, api-server, kubelet, node	What happens to running pods if if you stop Kubelet on the worker nodes?	When you stop the kubelet service on a worker node, it will no longer be able to communicate with the Kubernetes API server. As a result, the node will be marked as NotReady and the pods running on that node will be marked as Unknown. The Kubernetes control plane will then attempt to reschedule the pods to other available nodes in the cluster.\n\nRemember: kubelet = node agent. Takes PodSpecs, ensures containers are running and healthy.\n\nUnder the hood: kubelet talks to container runtime (containerd, CRI-O) via CRI interface.	projects/knowledge/interview/kubernetes/023-what-happens-to-running-pods-if-if-you-stop-kubele.txt
k8s-core/0cb97529d666	k8s-core	medium	kubernetes, kubelet, pod	Describe how would you delete a static Pod	Locate the static Pods directory (look at `staticPodPath` in kubelet configuration file).\n\nGo to that directory and remove the manifest/definition of the staic Pod (`rm <STATIC_POD_PATH>/<POD_DEFINITION_FILE>`)\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/056-describe-how-would-you-delete-a-static-pod.txt
k8s-core/0ecf1a6b4a37	k8s-core	medium	kubernetes, namespace	How to list all the components that bound to a namespace?	`kubectl api-resources --namespaced=true`\n\nRemember: 4 default namespaces: default, kube-system, kube-public, kube-node-lease. Mnemonic: "DSPL."\n\nGotcha: Never run production workloads in `default` — no quotas, harder RBAC.	projects/knowledge/interview/kubernetes/190-how-to-list-all-the-components-that-bound-to-a-nam.txt
k8s-core/0f828cbf7009	k8s-core	medium	kubernetes, scheduler, node, pod	Running kubectl get pods you see Pods in "Pending" status. What would you do?	One possible path is to run `kubectl describe pod <pod name>` to get more details. \nYou might see one of the following:\n * Cluster is full. In this case, extend the cluster.\n * ResourcesQuota limits are met. In this case you might want to modify them\n * Check if PersistentVolumeClaim mount is pending\n\nIf none of the above helped, run the command (`get pods`) with `-o wide` to see if the node is assigned to a node. If not, there might be an issue with scheduler.	projects/knowledge/interview/kubernetes/266-running-kubectl-get-pods-you-see-pods-in-pending-s.txt
k8s-core/10b685f8a933	k8s-core	medium	kubernetes, namespace	How to get the name of the current namespace?	`kubectl config view | grep namespace`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/181-how-to-get-the-name-of-the-current-namespace.txt
k8s-core/123a7b5b09db	k8s-core	medium	kubernetes, scheduler, label, node	Using node affinity, set a Pod to never schedule on a node where the key is "region" and value is "neverland"	`vi pod.yaml`\n\n```yaml\naffinity:\n  nodeAffinity:\n    requiredDuringSchedulingIgnoredDuringExecution:\n      nodeSelectorTerms:\n      - matchExpressions:\n        - key: region\n          operator: NotIn\n          values:\n          - neverland\n```\n\nRemember: Node affinity=where. Pod affinity=near whom. Pod anti-affinity=away from whom.\n\nGotcha: `required`=hard rule (must match). `preferred`=soft (best effort).	projects/knowledge/interview/kubernetes/277-using-node-affinity-set-a-pod-to-never-schedule-on.txt
k8s-core/12633a0a7356	k8s-core	hard	kubernetes, scheduler, pod	Assuming you have multiple schedulers, how to know which scheduler was used for a given Pod?	Running `kubectl get events` you can see which scheduler was used.\n\nUnder the hood: Scheduler: filter (which nodes CAN?) then score (which is BEST?). "Filter then Score."\n\nRemember: Scheduler watches for unassigned pods (no nodeName). It does NOT move running pods.	projects/knowledge/interview/kubernetes/280-assuming-you-have-multiple-schedulers-how-to-know-.txt
k8s-core/13bbb279b2fd	k8s-core	easy	kubernetes, api-server, controller-manager, namespace	What is the Kubernetes controller manager?	The controller manager is a daemon that is used for embedding core control loops, garbage collection, and Namespace creation. It enables the running of multiple processes on the master node even though they are compiled to run as a single process. The controller manager watches the shared state of the cluster through the API server and makes changes attempting to move the current state towards the desired state.\n\nRemember: Controllers run reconciliation loops: desired state vs actual state → take action.\n\nExample: ReplicaSet controller: 2 running, 3 desired → create 1. That's reconciliation.	projects/knowledge/interview/kubernetes/396-what-is-the-kubernetes-controller-manager.txt
k8s-core/17356ece10a6	k8s-core	medium	kubernetes, pod	How can you find out information on a Service related to a certain Pod if all you can use is kubectl exec --	You can run `kubectl exec <POD_NAME> -- env` which will give you a couple environment variables related to the Service. \nVariables such as `[SERVICE_NAME]_SERVICE_HOST`, `[SERVICE_NAME]_SERVICE_PORT`, ...\n\nExample: `kubectl exec -it pod -- /bin/sh`. Multi-container: `--container=name`.\n\nGotcha: exec needs a running container. For crashed pods: `kubectl logs --previous`.	projects/knowledge/interview/kubernetes/108-how-can-you-find-out-information-on-a-service-rela.txt
k8s-core/18af6ef78033	k8s-core	hard	kubernetes, scheduler, pod	Can you deploy multiple schedulers?	Yes, it is possible. You can run another pod with a command similar to:\n\n```\nspec:\n  containers:\n  - command:\n    - kube-scheduler\n    - --address=127.0.0.1\n    - --leader-elect=true\n    - --scheduler-name=some-custom-scheduler\n...\n```\n\nUnder the hood: Scheduler: filter (which nodes CAN?) then score (which is BEST?). "Filter then Score."\n\nRemember: Scheduler watches for unassigned pods (no nodeName). It does NOT move running pods.	projects/knowledge/interview/kubernetes/279-can-you-deploy-multiple-schedulers.txt
k8s-core/1b5fa4d63e5f	k8s-core	medium	kubernetes, kubelet, pod	Explain readiness probes	readiness probes used by Kubelet to know when a container is ready to start running, accepting traffic. \nFor example, a readiness probe can be to connect port 8080 on a container. Once Kubelet manages to connect it, the Pod is marked as ready\n\nYou can read more about it in [kubernetes.io](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes)\n\nRemember: Liveness=alive? Readiness=ready for traffic? Startup=done booting? Three probes, three purposes.\n\nGotcha: Aggressive liveness probe kills slow starters. Use startup probe or initialDelaySeconds.	projects/knowledge/interview/kubernetes/045-explain-readiness-probes.txt
k8s-core/1d76f4ea28c6	k8s-core	medium	kubernetes, pod	How many containers can a pod contain?	A pod can include multiple containers but in most cases it would probably be one container per pod.\n\nThere are some patterns where it makes to run more than one container like the "side-car" pattern where you might want to perform logging or some other operation that is executed by another container running with your app container in the same Pod.\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/030-how-many-containers-can-a-pod-contain.txt
k8s-core/1e16548e3453	k8s-core	hard	kubernetes, namespace, api-server, controller-manager	What is a Custom Resource Definition (CRD) in Kubernetes and how is it used?	CRD (Custom Resource Definition) extends the Kubernetes API with your own resource types.\n\nHow it works:\n- Define a CRD YAML specifying group, version, kind, and schema\n- `kubectl apply` the CRD to register the new type\n- Now you can create instances of your custom resource like any built-in resource\n- Pair with a custom controller (Operator pattern) to add business logic\n\nExample: Define a `Database` CRD, then `kubectl apply -f my-database.yaml` to create managed DB instances. The operator watches for these resources and handles provisioning, backups, and failover.	projects/knowledge/interview/kubernetes/204-explain-crd.txt
k8s-core/2034775b0361	k8s-core	hard	kubernetes, etcd, api-server, node	What is the role of the kube-apiserver in Kubernetes?	The kube-apiserver is a key component of the Kubernetes control plane and serves as the API server for the entire Kubernetes cluster. It exposes the Kubernetes API, which is used by various components to interact with the cluster, including users, the command-line interface (kubectl), and other Kubernetes master components. \nThe kube-apiserver validates and processes RESTful API requests, enforces security policies, and updates the corresponding objects in etcd, the cluster's distributed key-value store. It acts as the entry point for API requests, making it a critical component for the entire Kubernetes architecture. The API server provides a unified endpoint for communication with the cluster and ensures consistency in the desired state of the system.	projects/knowledge/interview/kubernetes/309-what-is-the-role-of-the-kube-apiserver-in-kubernet.txt
k8s-core/223dacfdde8f	k8s-core	hard	kubernetes, etcd, api-server, scheduler	Explain the main components of Kubernetes architecture.	The main components of Kubernetes architecture include: \n**Master Node:**\n* kube-apiserver: Serves as the API server for Kubernetes, handling communication with the cluster.\n* etcd: Consistent and highly available key-value store for storing configuration data.\n* kube-scheduler: Assigns work (pods) to nodes based on resource availability and constraints. \n**Node (Minion) Nodes:**\n* kubelet: Acts as the node agent, ensuring that containers are running on the node as expected.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/306-explain-the-main-components-of-kubernetes-architec.txt
k8s-core/22883271b49d	k8s-core	hard	kubernetes, etcd, api-server, scheduler	What happens when you run a Pod with kubectl?	1. Kubectl sends a request to the API server (kube-apiserver) to create the Pod\n   1. In the process the user gets authenticated and the request is being validated.\n   2. etcd is being updated with the data\n2. The Scheduler detects that there is an unassigned Pod by monitoring the API server (kube-apiserver)\n3. The Scheduler chooses a node to assign the Pod to\n   1. etcd is being updated with the information\n4. The Scheduler updates the API server about which node it chose\n5.	projects/knowledge/interview/kubernetes/037-what-happens-when-you-run-a-pod-with-kubectl.txt
k8s-core/253a1675f3f0	k8s-core	easy	kubernetes, api-server, kubelet, node	What is the kubelet and what role does it play on each Kubernetes node?	The kubelet is a service agent that controls and maintains a set of pods by watching for pod specs through the Kubernetes API server. It preserves the pod lifecycle by ensuring that a given set of containers are all running as they should. The kubelet runs on each node and enables the communication between the master and slave nodes.\n\nRemember: kubelet = node agent. Takes PodSpecs, ensures containers are running and healthy.\n\nUnder the hood: kubelet talks to container runtime (containerd, CRI-O) via CRI interface.	projects/knowledge/interview/kubernetes/409-what-is-kubelet.txt
k8s-core/26086a2dece8	k8s-core	hard	kubernetes, label, annotation	How annotations different from labels?	[Kubernetes.io](https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/): "Labels can be used to select objects and to find collections of objects that satisfy certain conditions. In contrast, annotations are not used to identify and select objects. The metadata in an annotation can be small or large, structured or unstructured, and can include characters not permitted by labels."	projects/knowledge/interview/kubernetes/070-how-annotations-different-from-labels.txt
k8s-core/26436d5421af	k8s-core	hard	kubernetes, scheduler, node, pod	Discuss the role of kube-scheduler in the Kubernetes control plane.	* kube-scheduler: The kube-scheduler is responsible for scheduling pods onto nodes in the cluster.\n* It considers factors such as resource availability, affinity, anti-affinity, and user-defined constraints.\n* kube-scheduler helps maintain balance and efficiency in the allocation of workloads across the cluster.\n* As part of the Kubernetes control plane, kube-scheduler plays a crucial role in optimizing resource utilization. \n* It ensures that pods are scheduled onto nodes that meet their requirements and constraints, contributing to the overall health and performance of the cluster.	projects/knowledge/interview/kubernetes/330-discuss-the-role-of-kube-scheduler-in-the-kubernet.txt
k8s-core/2be4bce36566	k8s-core	medium	kubernetes, pod	Explain liveness probes	Liveness probes is a useful mechanism used for restarting the container when a certain check/probe, the user has defined, fails. \nFor example, the user can define that the command `cat /app/status` will run every X seconds and the moment this command fails, the container will be restarted.\n\nYou can read more about it in [kubernetes.io](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes)\n\nRemember: Liveness=alive? Readiness=ready for traffic? Startup=done booting? Three probes, three purposes.\n\nGotcha: Aggressive liveness probe kills slow starters. Use startup probe or initialDelaySeconds.	projects/knowledge/interview/kubernetes/044-explain-liveness-probes.txt
k8s-core/2c12d7c9b055	k8s-core	easy	kubernetes, api-server, kubelet, node	What are Static Pods?	[Kubernetes.io](https://kubernetes.io/docs/tasks/configure-pod-container/static-pod/): "Static Pods are managed directly by the kubelet daemon on a specific node, without the API server observing them. Unlike Pods that are managed by the control plane (for example, a Deployment); instead, the kubelet watches each static Pod (and restarts it if it fails)."\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/050-what-are-static-pods.txt
k8s-core/2c33659bf217	k8s-core	medium	kubernetes, namespace, node	What special namespaces are there by default when creating a Kubernetes cluster?	* default\n* kube-system\n* kube-public\n* kube-node-lease\n\nRemember: 4 default namespaces: default, kube-system, kube-public, kube-node-lease. Mnemonic: "DSPL."\n\nGotcha: Never run production workloads in `default` — no quotas, harder RBAC.	projects/knowledge/interview/kubernetes/171-what-special-namespaces-are-there-by-default-when-.txt
k8s-core/2c541879ea94	k8s-core	hard	kubernetes, namespace, rbac	An engineer from your organization should see only their team's Kubernetes resources, but can see resources from multiple teams. Which Kubernetes controls should you use?	Separate team resources into namespaces, then grant least-privilege access with namespace-scoped Roles and RoleBindings. A namespace organizes and scopes resources; RBAC is what authorizes the user to view or change them. Prefer RoleBindings over ClusterRoleBindings when access should be limited to one namespace.\n\nReferences: [Kubernetes multi-tenancy](https://kubernetes.io/docs/concepts/security/multi-tenancy/#access-controls) and [RBAC good practices](https://kubernetes.io/docs/concepts/security/rbac-good-practices/#least-privilege).	projects/knowledge/interview/kubernetes/301-an-engineer-form-your-organization-told-you-he-is-.txt
k8s-core/2d3a188007ae	k8s-core	medium	kubernetes, node, pod	How to schedule a pod on a node called "node1"?	`k run some-pod --image=redix -o yaml --dry-run=client > pod.yaml`\n\n`vi pod.yaml` and add:\n\n```\nspec:\n  nodeName: node1\n```\n\n`k apply -f pod.yaml`\n\nNote: if you don't have a node1 in your cluster the Pod will be stuck on "Pending" state.\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/275-how-to-schedule-a-pod-on-a-node-called-node1.txt
k8s-core/2d795dd7a1ca	k8s-core	medium	kubernetes, node, pod	You applied a taint with k taint node minikube app=web:NoSchedule on the only node in your cluster and then executed kubectl run some-pod --image=redis but the Pod is in pending state. How to fix it?	`kubectl edit po some-pod` and add the following\n\n```\n  - effect: NoSchedule\n    key: app\n    operator: Equal\n    value: web\n```\n\nExit and save. The pod should be in Running state now.\n\nRemember: Taint effects: NoSchedule (block), PreferNoSchedule (soft), NoExecute (evict+block).\n\nExample: Add: `kubectl taint nodes n1 key=val:NoSchedule`. Remove: append `-` at end.	projects/knowledge/interview/kubernetes/285-you-applied-a-taint-with-k-taint-node-minikube-app.txt
k8s-core/2e379aec5e55	k8s-core	easy	kubernetes, node, pod	True or False? Once a Pod is assisgned to a worker node, it will only run on that node, even if it fails at some point and spins up a new Pod	True. Once the scheduler assigns a Pod to a node, it stays bound to that node for its lifetime. If the Pod fails, the controller (Deployment/ReplicaSet) creates a new Pod, which may be scheduled to a different node.\n\nRemember: K8s true/false questions test defaults and edge cases. Verify: `kubectl explain`.	projects/knowledge/interview/kubernetes/048-true-or-false-once-a-pod-is-assisgned-to-a-worker-.txt
k8s-core/2f423f8d0477	k8s-core	medium	kubernetes, pod	What kubectl describe pod [pod name] does? command does?	Show details of a specific resource or group of resources.\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/064-what-kubectl-describe-pod-pod-name-does-command-do.txt
k8s-core/33fb9b92a2dc	k8s-core	hard	kubernetes, controller-manager, node	What do you understand by Cloud controller manager?	With the help of cloud infrastructure technologies, you can run Kubernetes on them. In the context of Cloud Controller Manager, it is the control plane component that embeds the cloud-specific control logic. This process lets you link the cluster into the cloud provider's API and separates the elements that interact with the cloud platform from components that only interact with your cluster.\n\nThis also enables the cloud providers to release the features at a different pace compared to the main Kubernetes project. It is structured using a plugin mechanism and allows various cloud providers to integrate their platforms with Kubernetes.	projects/knowledge/interview/kubernetes/404-what-do-you-understand-by-cloud-controller.txt
k8s-core/354e4ba62ff6	k8s-core	easy	kubernetes, pods	What is a Kubernetes Pod and why is it the smallest deployable unit?	The smallest deployable unit in Kubernetes.\n\nRemember: Pod = smallest deployable unit (not a container!). Multiple containers share network + volumes.\n\nFun fact: "Pod" from "pod of whales" — a group traveling together, like co-located containers.\n\nGotcha: Pod IP changes on restart. Never rely on pod IPs — use Services for stable endpoints.	projects/knowledge/interview/kubernetes/415-what-is-pod.txt
k8s-core/381d3babe3b6	k8s-core	medium	kubernetes, node, pod	Explain the working of the master node in Kubernetes?	The master node dignifies the node that controls and manages the set of worker nodes. This kind resembles a cluster in Kubernetes. The nodes are responsible for the cluster management and the API used to configure and manage the resources within the collection. The master nodes of Kubernetes can run with Kubernetes itself, the asset of dedicated pods.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/382-explain-the-working-of-the-master-node-in.txt
k8s-core/392ab97f0371	k8s-core	medium	kubernetes, label, pod	List all the pods with the label "env=prod"	`k get po -l env=prod`\n\nTo count them: `k get po -l env=prod --no-headers | wc -l`\n\nExample: `kubectl label pod mypod app=web tier=frontend`\n\nRemember: Labels = key-value pairs for selection. Services, Deployments, Jobs all use selectors.	projects/knowledge/interview/kubernetes/059-list-all-the-pods-with-the-label-envprod.txt
k8s-core/3967c0783921	k8s-core	medium	kubernetes, namespace, pod	Check how many pods exist in the "dev" namespace	`k get po -n dev`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/177-check-how-many-pods-exist-in-the-dev-namespace.txt
k8s-core/39a5b75e8a1c	k8s-core	medium	kubernetes, node, pod	What does the node status contain?	The main components of a node status are:\n\n* Address - Contains the hostname, external IP, and internal IP\n* Condition - Describes the status of all running nodes\n* Capacity - Describes the resources available on the node (CPU, memory, max pods)\n* Info - Contains general information about the node (kernel version, Kubernetes version, container runtime details, OS)\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/385-what-does-the-node-status-contain.txt
k8s-core/3a34720080f1	k8s-core	hard	kubernetes, kubelet, pod	Where static Pods manifests are located?	Most of the time it's in /etc/kubernetes/manifests but you can verify with `grep -i static /var/lib/kubelet/config.yaml` to locate the value of `statisPodsPath`.\n\nIt might be that your config is in different path. To verify run `ps -ef | grep kubelet` and see what is the value of --config argument of the process `/usr/bin/kubelet`\n\nThe key itself for defining the path of static Pods is `staticPodPath`. So if your config is in `/var/lib/kubelet/config.yaml` you can run `grep staticPodPath /var/lib/kubelet/config.yaml`.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/055-where-static-pods-manifests-are-located.txt
k8s-core/3df2e644e0e1	k8s-core	hard	kubernetes, etcd, storage, performance	Why is etcd performance tied to disk latency more than CPU?	etcd uses Raft consensus which requires synchronous disk writes for every committed operation.\n\nThe bottleneck:\n\n1. Raft consensus protocol\n   - Every write must be persisted before acknowledgment\n   - Leader writes to WAL (Write-Ahead Log)\n   - Followers must also persist before ACK\n   - Quorum requires majority to persist\n\n2. fsync per commit\n   - etcd calls fsync() after every write batch\n   - fsync() = wait for disk confirmation\n   - Network latency + disk latency = total latency\n   - CPU sits idle waiting for disk\n\nRemember: etcd is the cluster's "brain" — all state lives here. Back up with `etcdctl snapshot save`.\n\nFun fact: etcd uses Raft consensus. 3 nodes tolerate 1 failure; 5 tolerate 2.	projects/knowledge/interview/kubernetes/402-etcd-disk-latency.txt
k8s-core/3e8032b92fe0	k8s-core	medium	kubernetes, label	Explain Labels. What are they and why would one use them?	Kubernetes labels are key-value pairs that can connect identifying metadata with Kubernetes objects.\n\nExample: `kubectl label pod mypod app=web tier=frontend`\n\nRemember: Labels = key-value pairs for selection. Services, Deployments, Jobs all use selectors.	projects/knowledge/interview/kubernetes/247-explain-labels-what-are-they-and-why-would-one-use.txt
k8s-core/3feefa49d316	k8s-core	hard	kubernetes, api-server, controller-manager	What are Custom Resource Definitions (CRDs) in Kubernetes?	* Custom Resource Definitions (CRDs): CRDs extend the Kubernetes API to support custom resources defined by users.\n* They allow users to define and use custom resource types beyond the core Kubernetes objects.\n* CRDs are the foundation for creating custom controllers and operators.\n* CRDs empower users to extend Kubernetes with domain-specific resources tailored to their applications. By defining custom resources, users can leverage the Kubernetes API and benefit from the same management capabilities for their specialized workloads.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/331-what-are-custom-resource-definitions-crds-in-kuber.txt
k8s-core/40c6c2cbefba	k8s-core	medium	kubernetes, namespace	How to create components in a namespace?	One way is by specifying --namespace like this: `kubectl apply -f my_component.yaml --namespace=some-namespace`\nAnother way is by specifying it in the YAML itself:\n\n```\napiVersion: v1\nkind: ConfigMap\nmetadata:\n  name: some-configmap\n  namespace: some-namespace\n```\n\nand you can verify with: `kubectl get configmap -n some-namespace`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/191-how-to-create-components-in-a-namespace.txt
k8s-core/46534390a0fc	k8s-core	easy	kubernetes, pod	True or False? Each Pod, when created, gets its own public IP address	False. Each Pod gets an IP address but an internal one and not publicly accessible.\n\nTo make a Pod externally accessible, we need to use an object called Service in Kubernetes.\n\nRemember: K8s true/false questions test defaults and edge cases. Verify: `kubectl explain`.	projects/knowledge/interview/kubernetes/049-true-or-false-each-pod-when-created-gets-its-own-p.txt
k8s-core/47a5ed6179fc	k8s-core	hard	kubernetes, etcd, node, pod	Describe the role of etcd in a Kubernetes cluster.	**etcd:**\n* Distributed, consistent, and highly available key-value store.\n* Stores configuration data, state information, and metadata about the cluster.\n* Provides a reliable and centralized data store for the entire Kubernetes control plane.\n* etcd ensures consistency among the components of the Kubernetes control plane by serving as the primary data store. It holds critical information such as cluster configuration, node status, and metadata about pods, services, and other resources. Its distributed nature makes it resilient to failures, contributing to the overall reliability of the Kubernetes cluster.	projects/knowledge/interview/kubernetes/314-describe-the-role-of-etcd-in-a-kubernetes-cluster.txt
k8s-core/4ca449b2be20	k8s-core	easy	kubernetes, namespace	True or False? When a namespace is deleted all resources in that namespace are not deleted but moved to another default namespace	False. When a namespace is deleted, the resources in that namespace are deleted as well.\n\nRemember: 4 default namespaces: default, kube-system, kube-public, kube-node-lease. Mnemonic: "DSPL."\n\nGotcha: Never run production workloads in `default` — no quotas, harder RBAC.	projects/knowledge/interview/kubernetes/170-true-or-false-when-a-namespace-is-deleted-all-reso.txt
k8s-core/4eec4fe1c61f	k8s-core	medium	kubernetes, node, pod	Discuss the use of Taints and Tolerations in Kubernetes for node affinity.	Taints and Tolerations:\n* Taints are applied to nodes to repel certain pods.\n* Tolerations are set in pod specifications to allow them to tolerate taints.\n* This mechanism helps influence pod placement based on node affinity requirements.\n\nRemember: "Taints repel, Tolerations permit." Node taints say "stay away unless you tolerate me."\n\nExample: `kubectl taint nodes node1 gpu=true:NoSchedule` — only tolerating pods land there.	projects/knowledge/interview/kubernetes/372-discuss-the-use-of-taints-and-tolerations-in-kuber.txt
k8s-core/50c3b17607e5	k8s-core	hard	kubernetes, etcd, api-server, scheduler	How to identify which Pods are Static Pods?	There are several ways to identify static pods:\n\n1. **Node name suffix**: Static pods have the node name appended as a suffix to their pod name. For example, a static pod from manifest `etcd.yaml` on node `master-01` would be named `etcd-master-01`.\n\n2. **Owner reference**: Static pods have their `ownerReferences` field set to a Node object rather than a ReplicaSet, Deployment, or other controller.\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/053-how-to-identify-which-pods-are-static-pods.txt
k8s-core/523a16edae97	k8s-core	hard	kubernetes, pod	What use cases exist for running multiple containers in a single pod?	A web application with separate (= in their own containers) logging and monitoring components/adapters is one examples. \nA CI/CD pipeline (using Tekton for example) can run multiple containers in one Pod if a Task contains multiple commands.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/031-what-use-cases-exist-for-running-multiple-containe.txt
k8s-core/533a71f01808	k8s-core	easy	kubernetes, api-server, scheduler, node	What are some use cases for using Static Pods?	One clear use case is running Control Plane Pods -  running Pods such as kube-apiserver, scheduler, etc. These should run and operate regardless of whether some components of the cluster work or not and they should run on specific nodes of the cluster.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/052-what-are-some-use-cases-for-using-static-pods.txt
k8s-core/53aeb27f20c6	k8s-core	medium	kubernetes, node, pod	Which of the following is not a static pod?:	kube-proxy - it's a DaemonSet (since it has to be presented on every node in the cluster). There is no one specific node on which it has to run.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/054-which-of-the-following-is-not-a-static-pod-kube-sc.txt
k8s-core/5404fe026b34	k8s-core	medium	kubernetes, scheduler, pod	You want to run a new Pod and you would like it to be scheduled by a custom scheduler. How to achieve it?	Add the following to the spec of the Pod:\n\n```\nspec:\n  schedulerName: some-custom-scheduler\n```\n\nUnder the hood: Scheduler: filter (which nodes CAN?) then score (which is BEST?). "Filter then Score."\n\nRemember: Scheduler watches for unassigned pods (no nodeName). It does NOT move running pods.	projects/knowledge/interview/kubernetes/281-you-want-to-run-a-new-pod-and-you-would-like-it-to.txt
k8s-core/57dddc1f1209	k8s-core	easy	kubernetes, node, pod	What is kube-proxy and how does it handle Kubernetes networking?	Kube-proxy is an implementation of a load balancer and network proxy used to support service abstraction with other networking operations. Kube-proxy is responsible for directing traffic to the right container based on IP and the port number of incoming requests. It runs on each node in the cluster.\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/412-what-is-kube-proxy.txt
k8s-core/592babd27736	k8s-core	medium	kubernetes, namespace	Which resources are accessible from different namespaces?	Services (and a few other cluster-scoped resources like Nodes and PersistentVolumes). A Service in namespace A can be reached from namespace B via `<svc>.<ns>.svc.cluster.local`.\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/187-which-resources-are-accessible-from-different-name.txt
k8s-core/5b923ea1832c	k8s-core	hard	kubernetes, namespace	You have one Kubernetes cluster and multiple teams that would like to use it. You would like to limit the resources each team consumes in the cluster. Which Kubernetes concept would you use for that?	Namespaces will allow to limit resources and also make sure there are no collisions between teams when working in the cluster (like creating an app with the same name).\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/238-you-have-one-kubernetes-cluster-and-multiple-teams.txt
k8s-core/5f25d3927f20	k8s-core	medium	kubernetes, namespace, pod	Create a pod called "kartos" in the namespace dev. The pod should be using the "redis" image.	If the namespace doesn't exist already: `k create ns dev`\n\n`k run kratos --image=redis -n dev`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/178-create-a-pod-called-kartos-in-the-namespace-dev-th.txt
k8s-core/62602d1e2678	k8s-core	easy	kubernetes, controller-manager	What are controllers?	[Kubernetes.io](https://kubernetes.io/docs/concepts/architecture/controller): "In Kubernetes, controllers are control loops that watch the state of your cluster, then make or request changes where needed. Each controller tries to move the current cluster state closer to the desired state."\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/269-what-are-controllers.txt
k8s-core/64f62afc4604	k8s-core	medium	kubernetes, pod	There are two containers inside a Pod called "some-pod". What will happen if you run kubectl logs some-pod	It won't work because there are two containers inside the Pod and you need to specify one of them with `kubectl logs POD_NAME -c CONTAINER_NAME`\n\nExample: `kubectl logs -f pod --previous` — `-f` follows, `--previous` shows crash logs.\n\nRemember: Multi-container: `--container=name`. Without it, errors on multi-container pods.	projects/knowledge/interview/kubernetes/072-there-are-two-containers-inside-a-pod-called-some-.txt
k8s-core/6555c0163f80	k8s-core	hard	kubernetes, label	What are Kubernetes selectors and how do they match resources?	[Kubernetes.io](https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#label-selectors): "Unlike names and UIDs, labels do not provide uniqueness. In general, we expect many objects to carry the same label(s).\n\nVia a label selector, the client/user can identify a set of objects. The label selector is the core grouping primitive in Kubernetes.\n\nThe API currently supports two types of selectors: equality-based and set-based. A label selector can be made of multiple requirements which are comma-separated. In the case of multiple requirements, all must be satisfied so the comma separator acts as a logical AND (&&) operator."	projects/knowledge/interview/kubernetes/067-explain-selectors.txt
k8s-core/65d1f4e82ee9	k8s-core	medium	kubernetes, node	What kube-node-lease contains?	It holds information on heartbeats of nodes. Each node gets an object which holds information about its availability.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/182-what-kube-node-lease-contains.txt
k8s-core/678835d21f00	k8s-core	medium	kubernetes, namespace	How to switch to another namespace? In other words how to change active namespace?	`kubectl config set-context --current --namespace=some-namespace` and validate with `kubectl config view --minify | grep namespace:`\n\nOR\n\n`kubens some-namespace`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/184-how-to-switch-to-another-namespace-in-other-words-.txt
k8s-core/6ab255f4a9be	k8s-core	medium	kubernetes, node	What Kube Proxy does?	Kube Proxy is a network proxy that runs on each node in your cluster, implementing part of the Kubernetes Service concept\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/239-what-kube-proxy-does.txt
k8s-core/6bb6f1b62d6f	k8s-core	easy	kubernetes, pod	True or False? By default, pods are isolated. This means they are unable to receive traffic from any source	False. By default, pods are non-isolated = pods accept traffic from any source.\n\nRemember: K8s true/false questions test defaults and edge cases. Verify: `kubectl explain`.	projects/knowledge/interview/kubernetes/033-true-or-false-by-default-pods-are-isolated-this-me.txt
k8s-core/71911689a639	k8s-core	medium	kubernetes, scheduler, node, pod	What taint effects are there? Explain each one of them	`NoSchedule`: prevents from resources to be scheduled on a certain node\n`PreferNoSchedule`: will prefer to shcedule resources on other nodes before resorting to scheduling the resource on the chosen node (on which the taint was applied)\n`NoExecute`: Applying "NoSchedule" will not evict already running Pods (or other resources) from the node as opposed to "NoExecute" which will evict any already running resource from the Node\n\nRemember: Taint effects: NoSchedule (block), PreferNoSchedule (soft), NoExecute (evict+block).\n\nExample: Add: `kubectl taint nodes n1 key=val:NoSchedule`. Remove: append `-` at end.	projects/knowledge/interview/kubernetes/287-what-taint-effects-are-there-explain-each-one-of-t.txt
k8s-core/71c49356d1a5	k8s-core	medium	kubernetes, scheduler, label, node	Provide some actual examples of how labels are used	* Can be used by the scheduler to place certain Pods (with certain labels) on specific nodes\n* Used by replicasets to track pods which have to be scaled\n\nExample: `kubectl label pod mypod app=web tier=frontend`\n\nRemember: Labels = key-value pairs for selection. Services, Deployments, Jobs all use selectors.	projects/knowledge/interview/kubernetes/068-provide-some-actual-examples-of-how-labels-are-use.txt
k8s-core/749d9059a6d1	k8s-core	medium	kubernetes, namespace, pod	While namespaces do provide scope for resources, they are not isolating them	True. Try create two pods in two separate namespaces for example, and you'll see there is a connection between the two.\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/173-while-namespaces-do-provide-scope-for-resources-th.txt
k8s-core/7526431764e2	k8s-core	hard	kubernetes, namespace	Why to use namespaces? What is the problem with using one default namespace?	When using the default namespace alone, it becomes hard over time to get an overview of all the applications you manage in your cluster. Namespaces make it easier to organize the applications into groups that makes sense, like a namespace of all the monitoring applications and a namespace for all the security applications, etc.\n\nNamespaces can also be useful for managing Blue/Green environments where each namespace can include a different version of an app and also share resources that are in other namespaces (namespaces like logging,	projects/knowledge/interview/kubernetes/169-why-to-use-namespaces-what-is-the-problem-with-usi.txt
k8s-core/782693c329ba	k8s-core	medium	kubernetes, node	Create a taint on one of the nodes in your cluster with key of "app" and value of "web" and effect of "NoSchedule". Verify it was applied	`k taint node minikube app=web:NoSchedule`\n\n`k describe no minikube | grep -i taints`\n\nRemember: Taint effects: NoSchedule (block), PreferNoSchedule (soft), NoExecute (evict+block).\n\nExample: Add: `kubectl taint nodes n1 key=val:NoSchedule`. Remove: append `-` at end.	projects/knowledge/interview/kubernetes/283-create-a-taint-on-one-of-the-nodes-in-your-cluster.txt
k8s-core/7bccd8bf9340	k8s-core	hard	kubernetes, node, pod	Discuss the role of kube-proxy in Kubernetes networking.	* kube-proxy Role: kube-proxy is responsible for maintaining network rules on nodes.\n* It enables communication to and from pods and services.\n* Implements load balancing for services with multiple pod instances.\n* kube-proxy operates at the network layer, ensuring that communication between pods and services is correctly routed. It plays a crucial role in load balancing service traffic among available pod instances, contributing to the overall stability and performance of the Kubernetes networking model.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/352-discuss-the-role-of-kube-proxy-in-kubernetes-netwo.txt
k8s-core/7ed8596eb2b9	k8s-core	hard	kubernetes, pod	Discuss the importance of readiness and liveness probes in Kubernetes.	• Readiness Probe:\n • Determines when a pod is ready to start accepting traffic.\n • Used to avoid directing traffic to pods that are still initializing or experiencing issues.\n • Specifies a condition that must be met for the pod to be considered ready.\n • Liveness Probe:\n • Detects whether a pod is healthy and operational.\n • Periodically checks the pod's health, restarting it if the probe fails.\n • Helps maintain the overall health and responsiveness of the application.\n\nRemember: Liveness=alive? Readiness=ready for traffic? Startup=done booting? Three probes, three purposes.\n\nGotcha: Aggressive liveness probe kills slow starters. Use startup probe or initialDelaySeconds.	
k8s-core/8003792543d9	k8s-core	easy	kubernetes, scheduler, pod	True or False? The "Pending" phase means the Pod was not yet accepted by the Kubernetes cluster so the scheduler can't run it unless it's accepted	False. "Pending" is after the Pod was accepted by the cluster, but the container can't run for different reasons like images not yet downloaded.\n\nUnder the hood: Scheduler: filter (which nodes CAN?) then score (which is BEST?). "Filter then Score."\n\nRemember: Scheduler watches for unassigned pods (no nodeName). It does NOT move running pods.	projects/knowledge/interview/kubernetes/034-true-or-false-the-pending-phase-means-the-pod-was-.txt
k8s-core/82edca08a419	k8s-core	easy	kubernetes, pod	What is a pod in Kubernetes?	Pods are high-level structures that wrap one or more containers. This is because containers are not run directly in Kubernetes. Containers in the same pod share a local network and the same resources, allowing them to easily communicate with other containers in the same pod as if they were on the same machine while at the same time maintaining a degree of isolation.\n\nRemember: Pod = smallest deployable unit (not a container!). Multiple containers share network + volumes.\n\nFun fact: "Pod" from "pod of whales" — a group traveling together, like co-located containers.	projects/knowledge/interview/kubernetes/387-what-is-a-pod-in-kubernetes.txt
k8s-core/82f0d1f50841	k8s-core	medium	kubernetes, node	Remove an existing taint from one of the nodes in your cluster	`k taint node minikube app=web:NoSchedule-`\n\nRemember: Taint effects: NoSchedule (block), PreferNoSchedule (soft), NoExecute (evict+block).\n\nExample: Add: `kubectl taint nodes n1 key=val:NoSchedule`. Remove: append `-` at end.	projects/knowledge/interview/kubernetes/286-remove-an-existing-taint-from-one-of-the-nodes-in-.txt
k8s-core/862704d72abb	k8s-core	easy	kubernetes, controller-manager, namespace, node	What are the types of controller managers?	The primary controller managers that can run on the master node are:\n\n* Node controller - Responsible for noticing and responding when nodes go down\n* Replication controller - Responsible for maintaining the correct number of pods\n* Endpoints controller - Populates the Endpoints object\n* Service accounts controller - Creates default accounts for new namespaces\n* Token controller - Creates tokens for the service accounts\n* Namespace controller - Manages the lifecycle of namespaces\n\nRemember: Controllers run reconciliation loops: desired state vs actual state → take action.\n\nExample: ReplicaSet controller: 2 running, 3 desired → create 1. That's reconciliation.	projects/knowledge/interview/kubernetes/397-what-are-the-types-of-controller-managers.txt
k8s-core/8e57b1b42f24	k8s-core	hard	kubernetes, api-server	Describe the Kubernetes API versioning strategy.	* API Versioning Strategy: Kubernetes follows a versioning scheme for its API to maintain compatibility and introduce new features.\n* API versions are structured as "group/version."\n* For example, "v1" represents the stable core API, while "apps/v1" may represent a group-specific version for certain resources.\n* The versioning strategy allows Kubernetes to introduce enhancements without breaking existing deployments. \n* It provides stability for core resources while enabling extensions and improvements through versioned groups.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/328-describe-the-kubernetes-api-versioning-strategy.txt
k8s-core/91065beb28fc	k8s-core	easy	kubernetes, architecture	What is a Kubernetes cluster and what are its components?	A Kubernetes cluster is a group of nodes (machines) managed by the Kubernetes control plane. It consists of: control plane components (API server, etcd, scheduler, controller-manager) and worker nodes running kubelet, kube-proxy, and a container runtime. Use `kubectl cluster-info` to view endpoints.	projects/knowledge/interview/kubernetes/417-what-is-cluster.txt
k8s-core/91a9b5d959eb	k8s-core	easy	kubernetes, node	True or False? Every cluster must have 0 or more master nodes and at least 1 worker	False. A Kubernetes cluster consists of at least 1 master and can have 0 workers (although that wouldn't be very useful...)\n\nRemember: K8s true/false questions test defaults and edge cases. Verify: `kubectl explain`.	projects/knowledge/interview/kubernetes/014-true-or-false-every-cluster-must-have-0-or-more-ma.txt
k8s-core/95faa6cb6695	k8s-core	medium	kubernetes, node, controller-manager, pod	Name two controllers you are familiar with	1. Node Controller: manages the nodes of a cluster. Among other things, the controller is responsible for monitoring nodes' health - if the node is suddenly unreachable it will evacuate all the pods running on it and will mark the node status accordingly.\n2. Replication Controller - monitors the status of pod replicas based on what should be running. It makes sure the number of pods that should be running is actually running\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/270-name-two-controllers-you-are-familiar-with.txt
k8s-core/9635c45ace61	k8s-core	easy	kubernetes, etcd, api-server, scheduler	What are the main components of Kubernetes architecture?	There are two primary components of Kubernetes Architecture: the master node and the worker node. Each of these components has individual components in them.\n\nThe master node contains:\n* API Server\n* Controller Manager\n* Scheduler\n* etcd\n\nThe worker node contains:\n* Kubelet\n* Kube-proxy\n* Container runtime\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/381-what-are-the-main-components-of-kubernetes.txt
k8s-core/97d8edef8966	k8s-core	medium	kubernetes, label, node	Check what labels one of your nodes in the cluster has	`k get no minikube --show-labels`\n\nExample: `kubectl label pod mypod app=web tier=frontend`\n\nRemember: Labels = key-value pairs for selection. Services, Deployments, Jobs all use selectors.	projects/knowledge/interview/kubernetes/026-check-what-labels-one-of-your-nodes-in-the-cluster.txt
k8s-core/999a658c42f2	k8s-core	medium	kubernetes, etcd, architecture	What is etcd's role in Kubernetes?	etcd is the distributed key-value store that Kubernetes uses as its backing store for all cluster data – it holds the state and configuration of the cluster (such as what pods should be running, ConfigMaps, secrets, etc.). It's a critical component for Kubernetes' high availability and consistency.\n\nRemember: etcd is the cluster's "brain" — all state lives here. Back up with `etcdctl snapshot save`.\n\nFun fact: etcd uses Raft consensus. 3 nodes tolerate 1 failure; 5 tolerate 2.	projects/knowledge/interview/kubernetes/418-what-is-etcd.txt
k8s-core/9b841301212a	k8s-core	easy	kubernetes, architecture	What is the "Control Plane"?	Components that manage the overall state of the cluster.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/418-control-plane.txt
k8s-core/9c42fcdf98a4	k8s-core	easy	kubernetes, scheduler, node, pod	True or False? Using the node affinity type "preferredDuringSchedulingIgnoredDuringExecution" means the scheduler can't schedule unless the rule is met	False. The scheduler tries to find a node that meets the requirements/rules and if it doesn't it will schedule the Pod anyway.\n\nUnder the hood: Scheduler: filter (which nodes CAN?) then score (which is BEST?). "Filter then Score."\n\nRemember: Scheduler watches for unassigned pods (no nodeName). It does NOT move running pods.	projects/knowledge/interview/kubernetes/278-true-of-false-using-the-node-affinity-type-preferr.txt
k8s-core/9dc18e464ce0	k8s-core	hard	kubernetes, kubelet, node, pod	Explain the purpose of kubelet in the Kubernetes cluster.	The kubelet is a node agent that runs on each node in a Kubernetes cluster and is responsible for ensuring that containers are running in a Pod as expected. It interacts with the container runtime (e.g., Docker) to manage the containers and communicates with the master node to receive pod specifications and report the status of pods. \n**Key responsibilities of the kubelet include:**\n* Pod Lifecycle Management: Ensures that the containers within a pod are running and healthy.\n\nRemember: kubelet = node agent. Takes PodSpecs, ensures containers are running and healthy.\n\nUnder the hood: kubelet talks to container runtime (containerd, CRI-O) via CRI interface.	projects/knowledge/interview/kubernetes/311-explain-the-purpose-of-kubelet-in-the-kubernetes-c.txt
k8s-core/a14b50acc21f	k8s-core	medium	kubernetes, etcd, api-server, scheduler	What are the components of the master node (aka control plane)?	* API Server - the Kubernetes API. All cluster components communicate through it\n  * Scheduler - assigns an application with a worker node it can run on\n  * Controller Manager - cluster maintenance (replications, node failures, etc.)\n  * etcd - stores cluster configuration\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/015-what-are-the-components-of-the-master-node-aka-con.txt
k8s-core/a3659cc00905	k8s-core	hard	kubernetes, namespace, pod	True or False? By default there is no communication between two Pods in two different namespaces	False. By default two Pods in two different namespaces are able to communicate with each other.\n\nTry it for yourself:\n\nkubectl run test-prod -n prod --image ubuntu -- sleep 2000000000\nkubectl run test-dev -n dev --image ubuntu -- sleep 2000000000\n\n`k describe po test-prod -n prod` to get the IP of test-prod Pod.\n\nAccess dev Pod: `kubectl exec --stdin --tty test-dev -n dev -- /bin/bash`\n\nAnd ping the IP of test-prod Pod you get earlier.You'll see that there is communication between the two pods, in two separate namespaces.	projects/knowledge/interview/kubernetes/161-true-or-false-by-default-there-is-no-communication.txt
k8s-core/a3ba47636a29	k8s-core	hard	kubernetes, kubelet, node, pod	Discuss the role of the kubelet in the node's container runtime.	* kubelet Role: The kubelet is an agent that runs on each node in the cluster.\n* It is responsible for managing and maintaining the state of pods on the node.\n* kubelet interacts with the container runtime (e.g., Docker, containerd) to start, stop, and monitor containers.\n* kubelet is a critical component in the Kubernetes node. It communicates with the control plane, ensuring that containers defined in pods are running and healthy. \n* It works in tandem with the container runtime to execute the desired state of the pod.	projects/knowledge/interview/kubernetes/340-discuss-the-role-of-the-kubelet-in-the-nodes-conta.txt
k8s-core/a807597d21a2	k8s-core	medium	kubernetes, namespace, pod	How to list the pods in the current namespace?	`kubectl get po`\n\nRemember: 4 default namespaces: default, kube-system, kube-public, kube-node-lease. Mnemonic: "DSPL."\n\nGotcha: Never run production workloads in `default` — no quotas, harder RBAC.	projects/knowledge/interview/kubernetes/060-how-to-list-the-pods-in-the-current-namespace.txt
k8s-core/a9726e7b6b10	k8s-core	easy	kubernetes, organization	What is a "Namespace"?	A way to divide cluster resources between users or teams.\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/422-namespace.txt
k8s-core/a9fbd6112e06	k8s-core	easy	kubernetes, components	What is the "Kubelet"?	An agent on each node that ensures containers are running.\n\nRemember: kubelet = node agent. Takes PodSpecs, ensures containers are running and healthy.\n\nUnder the hood: kubelet talks to container runtime (containerd, CRI-O) via CRI interface.	projects/knowledge/interview/kubernetes/419-kubelet.txt
k8s-core/ab84a424cb44	k8s-core	easy	kubernetes, api-server, controller-manager, pod	What is the role of Kube-apiserver?	The kube-apiserver validates and provides configuration data for the API objects. It includes pods, services, replication controllers. Also, it provides REST operations and also the frontend of the cluster. This frontend cluster state is shared through which all other components interact.\n\nRemember: API server = "front door." kubectl, kubelet, scheduler, controllers all go through it.\n\nUnder the hood: Request flow: Authenticate→Authorize→Admit→Validate→etcd. Mnemonic: "AAAVE."	projects/knowledge/interview/kubernetes/383-what-is-the-role-of-kube-apiserver.txt
k8s-core/ad43efa457fe	k8s-core	hard	kubernetes, label, node, pod	Explain the concept of Labels and Selectors in Kubernetes.	**Labels:**\n • Key-value pairs attached to objects (e.g., pods, nodes, services) in Kubernetes.\n • Used to organize and categorize objects based on arbitrary attributes.\n • Provide metadata that can be queried to select and filter objects. \n**Selectors:**\n • Queries based on labels used to filter and match objects in Kubernetes.\n • Allow for the creation of groups of objects based on common attributes.\n • Used in various contexts, such as selecting pods for services or ReplicaSets.\n\nExample: `kubectl get pods -l app=web,tier=frontend` — match both labels.\n\nRemember: Labels = sticky notes. Selectors = search queries. Services use selectors to find pods.	
k8s-core/b1d8e64f4f59	k8s-core	medium	kubernetes, pod	What are your thoughts on "Pods are not meant to be created directly"?	Pods are usually indeed not created directly. You'll notice that Pods are usually created as part of another entities such as Deployments or ReplicaSets.\n\nIf a Pod dies, Kubernetes will not bring it back. This is why it's more useful for example to define ReplicaSets that will make sure that a given number of Pods will always run, even after a certain Pod dies.\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/029-what-are-your-thoughts-on-pods-are-not-meant-to-be.txt
k8s-core/b320af79443c	k8s-core	medium	kubernetes, pod	Explain the purpose of the following lines	They define a readiness probe where the Pod will not be marked as "Ready" before it will be possible to connect to port 2017 of the container. The first check/probe will start after 15 seconds from the moment the container started to run and will continue to run the check/probe every 20 seconds until it will manage to connect to the defined port.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/041-explain-the-purpose-of-the-following-lines-readine.txt
k8s-core/b4342645bcc6	k8s-core	medium	kubernetes, scheduler, label, node	Using node affinity, set a Pod to schedule on a node where the key is "region" and value is either "asia" or "emea"	`vi pod.yaml`\n\n```yaml\naffinity:\n  nodeAffinity:\n    requiredDuringSchedulingIgnoredDuringExecution:\n      nodeSelectorTerms:\n      - matchExpressions:\n        - key: region\n          operator: In\n          values:\n          - asia\n          - emea\n```\n\nRemember: Node affinity=where. Pod affinity=near whom. Pod anti-affinity=away from whom.\n\nGotcha: `required`=hard rule (must match). `preferred`=soft (best effort).	projects/knowledge/interview/kubernetes/276-using-node-affinity-set-a-pod-to-schedule-on-a-nod.txt
k8s-core/b4ea604f60c7	k8s-core	easy	kubernetes, namespace	True or False? With namespaces you can limit the resources consumed by the users/teams	True. With namespaces you can limit CPU, RAM and storage usage.\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/183-true-or-false-with-namespaces-you-can-limit-the-re.txt
k8s-core/b6b2c276b44f	k8s-core	medium	kubernetes, node	Check if there are taints on node "master"	`k describe no master | grep -i taints`\n\nRemember: Taint effects: NoSchedule (block), PreferNoSchedule (soft), NoExecute (evict+block).\n\nExample: Add: `kubectl taint nodes n1 key=val:NoSchedule`. Remove: append `-` at end.	projects/knowledge/interview/kubernetes/282-check-if-there-are-taints-on-node-master.txt
k8s-core/b75a3613523e	k8s-core	medium	kubernetes, namespace	Which service and in which namespace the following file is referencing?	It's referencing the service "samurai" in the namespace called "jack".\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/188-which-service-and-in-which-namespace-the-following.txt
k8s-core/bb6b8ceb0136	k8s-core	medium	kubernetes, node	What kubectl get componentstatus does?	Outputs the status of each of the control plane components.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/022-what-kubectl-get-componentstatus-does.txt
k8s-core/be5b07b9a3df	k8s-core	medium	kubernetes, scheduler, node, pod	How does scheduling work in kubernetes?	The control plane component kube-scheduler asks the following questions,\n1. What to schedule? It tries to understand the pod-definition specifications\n2. Which node to schedule? It tries to determine the best node with available resources to spin a pod\n3. Binds the Pod to a given node\n\nView more [here](https://www.youtube.com/watch?v=rDCWxkvPlAw)\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/245-how-does-scheduling-work-in-kubernetes.txt
k8s-core/bf4718f5935b	k8s-core	medium	kubernetes, namespace	Create a namespace called 'alle'	`k create ns alle`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/175-create-a-namespace-called-alle.txt
k8s-core/c13c445af6e8	k8s-core	hard	kubernetes, etcd, node	Why etcd? Why not some SQL or NoSQL database?	When chosen as the data store etcd was (and still is of course):\n\n* Highly Available - you can deploy multiple nodes\n* Fully Replicated - any node in etcd cluster is "primary" node and has full access to the data\n* Consistent - reads return latest data\n* Secured - supports both TLS and SSL\n* Speed - high performance data store (10k writes per sec!)\n\nRemember: etcd is the cluster's "brain" — all state lives here. Back up with `etcdctl snapshot save`.\n\nFun fact: etcd uses Raft consensus. 3 nodes tolerate 1 failure; 5 tolerate 2.	projects/knowledge/interview/kubernetes/167-why-etcd-why-not-some-sql-or-nosql-database.txt
k8s-core/c1671b63d1fc	k8s-core	medium	kubernetes, api-server, node	What process runs on Kubernetes Master Node?	The Kube-api server process runs on the master node and serves to scale the deployment of more instances.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/386-what-process-runs-on-kubernetes-master-node.txt
k8s-core/c237daa97fc2	k8s-core	medium	kubernetes, label, pod	How to delete all pods whose status is not "Running"?	`kubectl delete pods --field-selector=status.phase!=Running` removes all pods not in Running state. This catches Failed, Succeeded, Pending, and Unknown pods. \nGotcha: add `--dry-run=client` first to preview what would be deleted. Use `--field-selector=status.phase==Failed` to target only failed pods specifically.	projects/knowledge/interview/kubernetes/196-how-to-delete-all-pods-whose-status-is-not-running.txt
k8s-core/c30462c1068c	k8s-core	medium	kubernetes, pod	What kubectl logs [pod-name] command does?	Prints the logs for a container in a pod.\n\nExample: `kubectl logs -f pod --previous` — `-f` follows, `--previous` shows crash logs.\n\nRemember: Multi-container: `--container=name`. Without it, errors on multi-container pods.	projects/knowledge/interview/kubernetes/063-what-kubectl-logs-pod-name-command-does.txt
k8s-core/c3b1f28fc562	k8s-core	easy	kubernetes, api-server, node, pod	What is a cluster of containers in Kubernetes?	A cluster of containers is a set of machine elements that are nodes. Clusters initiate specific routes so that the containers running on the nodes can communicate with each other. In Kubernetes, the container engine (not the server of the Kubernetes API) provides hosting for the API server.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/389-what-is-a-cluster-of-containers-in-kubernetes.txt
k8s-core/c94838e94343	k8s-core	medium	kubernetes, label, node, pod	An engineer form your organization asked whether there is a way to prevent from Pods (with cretain label) to be scheduled on one of the nodes in the cluster. Your reply is:	Yes, using taints, we could run the following command and it will prevent from all resources with label "app=web" to be scheduled on node1: `kubectl taint node node1 app=web:NoSchedule`\n\nExample: `kubectl label pod mypod app=web tier=frontend`\n\nRemember: Labels = key-value pairs for selection. Services, Deployments, Jobs all use selectors.	projects/knowledge/interview/kubernetes/303-an-engineer-form-your-organization-asked-whether-t.txt
k8s-core/c9fd6092c25f	k8s-core	easy	kubernetes, node, pod	True or False? A single Pod can be split across multiple nodes	False. A single Pod can run on a single node.\n\nRemember: K8s true/false questions test defaults and edge cases. Verify: `kubectl explain`.	projects/knowledge/interview/kubernetes/035-true-or-false-a-single-pod-can-be-split-across-mul.txt
k8s-core/cc452abff1ea	k8s-core	medium	kubernetes, namespace	What can you find in kube-system namespace?	* Master and Kubectl processes\n* System processes\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/172-what-can-you-find-in-kube-system-namespace.txt
k8s-core/cd2de34b005d	k8s-core	medium	kubernetes, pod	Why it's common to have only one container per Pod in most cases?	One reason is that it makes it harder to scale when you need to scale only one of the containers in a given Pod.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/047-why-its-common-to-have-only-one-container-per-pod-.txt
k8s-core/cea790f0d0cc	k8s-core	hard	kubernetes, label, pod	What are Kubernetes labels and how are they used?	[Kubernetes.io](https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/): "Labels are key/value pairs that are attached to objects, such as pods. Labels are intended to be used to specify identifying attributes of objects that are meaningful and relevant to users, but do not directly imply semantics to the core system. Labels can be used to organize and to select subsets of objects. Labels can be attached to objects at creation time and subsequently added and modified at any time. Each object can have a set of key/value labels defined. Each Key must be unique for a given object."	projects/knowledge/interview/kubernetes/066-explain-labels.txt
k8s-core/d23c80c2ceda	k8s-core	medium	kubernetes, node, pod	How to check to which worker node the pods were scheduled to? In other words, how to check on which node a certain Pod is running?	`kubectl get pods -o wide` shows pod details including the NODE column indicating which worker node each pod runs on. You can also use `kubectl describe pod <name>` and look for the 'Node:' field. For filtering: `kubectl get pods --field-selector spec.nodeName=worker-01` lists pods on a specific node.	projects/knowledge/interview/kubernetes/057-how-to-check-to-which-worker-node-the-pods-were-sc.txt
k8s-core/d3599eec8ebc	k8s-core	medium	kubernetes, pod	What happens when you delete a Pod?	1. The `TERM` signal is sent to kill the main processes inside the containers of the given Pod\n2. Each container is given a period of 30 seconds to shut down the processes gracefully\n3. If the grace period expires, the `KILL` signal is used to kill the processes forcefully and the containers as well\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/043-what-happens-when-you-delete-a-pod.txt
k8s-core/d574a45faf64	k8s-core	easy	kubernetes, node, pod	What is a Kubernetes Cluster?	Red Hat Definition: "A Kubernetes cluster is a set of node machines for running containerized applications. If you’re running Kubernetes, you’re running a cluster.\nAt a minimum, a cluster contains a worker node and a master node."\n\nRead more [here](https://www.redhat.com/en/topics/containers/what-is-a-kubernetes-cluster)\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/010-what-is-a-kubernetes-cluster.txt
k8s-core/d6cf42131ec9	k8s-core	medium	kubernetes, namespace, pod	You are looking for a Pod called "atreus". How to check in which namespace it runs?	`k get po -A | grep atreus`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/179-you-are-looking-for-a-pod-called-atreus-how-to-che.txt
k8s-core/db5f653a0cb7	k8s-core	hard	kubernetes, namespace, pod	Explain the concept of Namespaces in Kubernetes.	* Namespaces:\n * Virtual clusters within a physical cluster, providing a way to partition resources.\n * Used to organize and scope objects, preventing naming conflicts.\n * Enable the isolation of resources, making it easier to manage and share clusters. \nNamespaces allow multiple teams or applications to coexist within a shared Kubernetes cluster without interfering with each other. They provide a logical separation of resources, such as pods, services, and storage, making it possible to create isolated environments within a single physical cluster.	projects/knowledge/interview/kubernetes/320-explain-the-concept-of-namespaces-in-kubernetes.txt
k8s-core/dcff72ee8149	k8s-core	easy	kubernetes, node	What is a Kubernetes node and what components run on it?	A node is a virtual or a physical machine that serves as a worker for running the applications. \nIt's recommended to have at least 3 nodes in a production environment.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/011-what-is-a-node.txt
k8s-core/e06c801fbe59	k8s-core	medium	kubernetes, namespace	Name the initial namespaces from which Kubernetes starts?	Kubernetes starts with three initial namespaces:\n\n* default - The default namespace for objects with no other namespace\n* kube-system - The namespace for objects created by the Kubernetes system\n* kube-public - This namespace is readable by all users and is reserved for cluster usage\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/395-name-the-initial-namespaces-from-which.txt
k8s-core/e1e23ce6fbee	k8s-core	medium	kubernetes, namespace, controller-manager, pod	What Kubernetes objects are there?	* Pod\n  * Service\n  * ReplicationController\n  * ReplicaSet\n  * DaemonSet\n  * Namespace\n  * ConfigMap\n  ...\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/004-what-kubernetes-objects-are-there.txt
k8s-core/e2065f57d2e9	k8s-core	medium	kubernetes, pod	How to confirm a container is running after running the command kubectl run web --image nginxinc/nginx-unprivileged	* When you run `kubectl describe pods <POD_NAME>` it will tell whether the container is running:\n`Status:       Running`\n* Run a command inside the container: `kubectl exec web -- ls`\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/038-how-to-confirm-a-container-is-running-after-runnin.txt
k8s-core/e23f871054af	k8s-core	easy	kubernetes, pod	Explain what is a Pod	A Pod is a group of one or more containers, with shared storage and network resources, and a specification for how to run the containers.\n\nPods are the smallest deployable units of computing that you can create and manage in Kubernetes.\n\nRemember: Pod = smallest deployable unit (not a container!). Multiple containers share network + volumes.\n\nFun fact: "Pod" from "pod of whales" — a group traveling together, like co-located containers.	projects/knowledge/interview/kubernetes/027-explain-what-is-a-pod.txt
k8s-core/e2e4908799c5	k8s-core	medium	kubernetes, pod	How to view the logs of a container running in a Pod?	`k logs POD_NAME`\n\nExample: `kubectl logs -f pod --previous` — `-f` follows, `--previous` shows crash logs.\n\nRemember: Multi-container: `--container=name`. Without it, errors on multi-container pods.	projects/knowledge/interview/kubernetes/071-how-to-view-the-logs-of-a-container-running-in-a-p.txt
k8s-core/e381e8e1ebed	k8s-core	easy	kubernetes, architecture	What is a node in Kubernetes and what runs on it?	A worker machine (physical or virtual) that runs containers.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/416-what-is-node.txt
k8s-core/e3ef190b9974	k8s-core	easy	kubernetes, namespace	What are Kubernetes namespaces and when should you use them?	Namespaces allow you split your cluster into virtual clusters where you can group your applications in a way that makes sense and is completely separated from the other groups (so you can for example create an app with the same name in two different namespaces)\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/168-what-are-namespaces.txt
k8s-core/e4a82b87ffde	k8s-core	medium	kubernetes, kubelet, pod	Create a static pod with the image python that runs the command sleep 2017	First change to the directory tracked by kubelet for creating static pod: `cd /etc/kubernetes/manifests` (you can verify path by reading kubelet conf file)\n\nNow create the definition/manifest in that directory\n`k run some-pod --image=python --command sleep 2017 --restart=Never --dry-run=client -o yaml > statuc-pod.yaml`\n\nRemember: `--dry-run=client -o yaml` generates manifests. `kubectl explain` shows field schemas.	projects/knowledge/interview/kubernetes/065-create-a-static-pod-with-the-image-python-that-run.txt
k8s-core/e4c83a8a710e	k8s-core	medium	kubernetes, namespace, pod	How view all the pods running in all the namespaces?	`kubectl get pods --all-namespaces`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/061-how-view-all-the-pods-running-in-all-the-namespace.txt
k8s-core/e695b65d0245	k8s-core	medium	kubernetes, namespace	What kube-public contains?	* A configmap, which contains cluster information\n* Publicly accessible data\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/180-what-kube-public-contains.txt
k8s-core/e71e40cd7c59	k8s-core	easy	kubernetes, node, pod	What is a node in Kubernetes?	A node is the smallest fundamental unit of computing hardware. It represents a single machine in a cluster, which could be a physical machine in a data center or a virtual machine from a cloud provider. Each machine can substitute any other machine in a Kubernetes cluster. The master in Kubernetes controls the nodes that have containers.\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/384-what-is-a-node-in-kubernetes.txt
k8s-core/ede1cc8d28aa	k8s-core	medium	kubernetes, namespace	Check how many namespaces are there	`k get ns --no-headers | wc -l`\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/176-check-how-many-namespaces-are-there.txt
k8s-core/ee17c41fc21a	k8s-core	hard	probes, health-checks, pods	What is the difference between liveness and readiness probes in Kubernetes?	Both are health check mechanisms, but they serve different purposes:\n\nLiveness Probe:\n- Determines if the container is running\n- If it fails, kubelet kills the container and restarts it\n- Use case: Detect deadlocks, unresponsive applications\n- "Is the application alive?"\n\nReadiness Probe:\n- Determines if the container is ready to receive traffic\n- If it fails, Pod is removed from Service endpoints\n- Container is NOT restarted\n- Use case: Waiting for dependencies, warming caches\n- "Is the application ready to serve requests?"\n\nBest practices:\n- Liveness: Simple check, shouldn't depend on external services\n- Readiness: Can include dependency checks\n- Don't make liveness check the same as readiness\n- Set appropriate initialDelaySeconds for slow-starting apps	projects/knowledge/interview/kubernetes/453-liveness-readiness.txt
k8s-core/f3dd9f5b07e5	k8s-core	medium	kubernetes, controller-manager	What are all the phases/steps of a control loop?	- Observe - identify the cluster current state\n- Diff - Identify whether a diff exists between current state and desired state\n- Act - Bring current cluster state to the desired state (basically reach a state where there is no diff)\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/273-what-are-all-the-phasessteps-of-a-control-loop.txt
k8s-core/f428bc68b9f1	k8s-core	easy	kubernetes, annotation	What are Annotations?	[Kubernetes.io](https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/): "You can use Kubernetes annotations to attach arbitrary non-identifying metadata to objects. Clients such as tools and libraries can retrieve this metadata."\n\nExample: `kubectl annotate pod mypod description='Web server' build='v1.2.3'`\n\nRemember: Annotations can't be used in selectors. Store non-identifying metadata.	projects/knowledge/interview/kubernetes/069-what-are-annotations.txt
k8s-core/f549641d3548	k8s-core	medium	kubernetes, node, pod	You applied a taint with k taint node minikube app=web:NoSchedule on the only node in your cluster and then executed kubectl run some-pod --image=redis. What will happen?	The Pod will remain in "Pending" status due to the only node in the cluster having a taint of "app=web".\n\nRemember: Taint effects: NoSchedule (block), PreferNoSchedule (soft), NoExecute (evict+block).\n\nExample: Add: `kubectl taint nodes n1 key=val:NoSchedule`. Remove: append `-` at end.	projects/knowledge/interview/kubernetes/284-you-applied-a-taint-with-k-taint-node-minikube-app.txt
k8s-core/f61604f2cdab	k8s-core	easy	kubernetes, scheduler, kubelet, node	True or False? The scheduler is responsible for both deciding where a Pod will run and actually running it	False. While the scheduler is responsible for choosing the node on which the Pod will run, Kubelet is the one that actually runs the Pod.\n\nUnder the hood: Scheduler: filter (which nodes CAN?) then score (which is BEST?). "Filter then Score."\n\nRemember: Scheduler watches for unassigned pods (no nodeName). It does NOT move running pods.	projects/knowledge/interview/kubernetes/274-true-of-false-the-scheduler-is-responsible-for-bot.txt
k8s-core/f740e3fb5263	k8s-core	easy	kubernetes, namespace	What is a Namespace in Kubernetes?	Namespaces are used for dividing cluster resources between multiple users. They are meant for environments where there are many users spread across projects or teams and provide a scope of resources. Namespaces provide a mechanism for isolating groups of resources within a single cluster.\n\nExample: `kubectl create ns staging && kubectl config set-context --current --namespace=staging`\n\nRemember: Namespaces = logical isolation. Combine with ResourceQuotas, NetworkPolicies, RBAC.	projects/knowledge/interview/kubernetes/394-what-is-a-namespace-in-kubernetes.txt
k8s-core/f742bcdf946c	k8s-core	medium	kubernetes, namespace	How to list all namespaces?	`kubectl get namespaces` OR `kubectl get ns`\n\nRemember: 4 default namespaces: default, kube-system, kube-public, kube-node-lease. Mnemonic: "DSPL."\n\nGotcha: Never run production workloads in `default` — no quotas, harder RBAC.	projects/knowledge/interview/kubernetes/174-how-to-list-all-namespaces.txt
k8s-core/fac9ee3b6017	k8s-core	medium	kubernetes, controller-manager	What process is responsible for running and installing the different controllers?	The kube-controller-manager runs all built-in controllers (ReplicaSet, Deployment, Job, Node, ServiceAccount, etc.) as goroutines in a single process. Each controller watches the API server for its resource type and reconciles desired vs actual state. If kube-controller-manager crashes, no new reconciliation happens until it restarts.	projects/knowledge/interview/kubernetes/271-what-process-is-responsible-for-running-and-instal.txt
k8s-core/fc55026562e5	k8s-core	medium	kubernetes, namespace	How to get list of resources which are not bound to a specific namespace?	kubectl api-resources --namespaced=false\n\nRemember: 4 default namespaces: default, kube-system, kube-public, kube-node-lease. Mnemonic: "DSPL."\n\nGotcha: Never run production workloads in `default` — no quotas, harder RBAC.	projects/knowledge/interview/kubernetes/195-how-to-get-list-of-resources-which-are-not-bound-t.txt
k8s-core/fe25711a9a7e	k8s-core	medium	kubernetes, kubelet, node, pod	What are the components of a worker node (aka data plane)?	* Kubelet - an agent responsible for node communication with the master.\n  * Kube-proxy - load balancing traffic between app components\n  * Container runtime - the engine runs the containers (Podman, Docker, ...)\n\nRemember: Use `kubectl explain <resource>` to explore API fields from the CLI.	projects/knowledge/interview/kubernetes/016-what-are-the-components-of-a-worker-node-aka-data-.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Adversarial Interview Gauntlet (30 sequences)](../../../../library/interview-scenarios/gauntlet/README.md) (Scenario, L2) — Kubernetes Core
- [Case Study: Alert Storm — Flapping Health Checks](../../../../library/case-studies/cross-domain/alert-storm-flapping-healthchecks/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Canary Deploy Routing to Wrong Backend — Ingress Misconfigured](../../../../library/case-studies/cross-domain/canary-deploy-wrong-backend-ingress/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: CrashLoopBackOff No Logs](../../../../library/case-studies/kubernetes_ops/crashloopbackoff-no-logs/README.md) (Case Study, L1) — Kubernetes Core
- [Case Study: DNS Looks Broken — TLS Expired, Fix Is Cert-Manager](../../../../library/case-studies/cross-domain/dns-tls-certmanager/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: DaemonSet Blocks Eviction](../../../../library/case-studies/kubernetes_ops/daemonset-blocks-eviction/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Deployment Stuck — ImagePull Auth Failure, Vault Secret Rotation](../../../../library/case-studies/cross-domain/deployment-stuck-imagepull-vault/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Drain Blocked by PDB](../../../../library/case-studies/kubernetes_ops/drain-blocked-by-pdb/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: HPA Flapping — Metrics Server Clock Skew, Fix Is NTP](../../../../library/case-studies/cross-domain/hpa-flapping-clock-skew-ntp/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: ImagePullBackOff Registry Auth](../../../../library/case-studies/kubernetes_ops/imagepullbackoff-registry-auth/README.md) (Case Study, L1) — Kubernetes Core

<!-- wiki:related:end -->
