---
tags:
- k8s
- l1
- flashcard-deck
- k8s-core
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Core](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
openshift/000649f22ca5	openshift	medium	openshift, routes, builds	What Route is consists of?	- name\n  - service selector\n  - (optional) security configuration\n\nRemember: Route = OpenShift's Ingress. Predates K8s Ingress, more TLS options.\n\nUnder the hood: OpenShift Routes predate Kubernetes Ingress. Routes support edge, re-encrypt, and passthrough TLS termination modes.\n\nExample: `oc expose svc/myapp --hostname=myapp.example.com` creates a Route from a Service.	projects/knowledge/interview/openshift/026-what-route-is-consists-of.txt
openshift/01405d09c81b	openshift	hard	openshift, routes, builds	Explain OpenShift CLIs like oc and odo	"oc is used for creating applications, but also for administrating OpenShift cluster \nodo is used solely for managing applications on OpenShift (mainly from developers' perspective) and has nothing to do with administrating the cluster\n\nRemember: `oc` extras: new-app, new-project, login, adm. kubectl superset.\n\nRemember: ""oc = admin + developer, odo = developer only."" odo abstracts Kubernetes complexity for developers who just want to deploy code."	projects/knowledge/interview/openshift/010-explain-openshift-clis-like-oc-and-odo.txt
openshift/0ac3c593b5fd	openshift	medium	openshift, scc, oauth	"What are ""Security Context Constraints""?"	"From [OpenShift Docs](https://docs.openshift.com/container-platform/4.7/authentication/managing-security-context-constraints.html): ""Similar to the way that RBAC resources control user access, administrators can use security context constraints (SCCs) to control permissions for pods"".\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nUnder the hood: SCCs are more powerful than K8s PodSecurityPolicies (now deprecated) or PodSecurityStandards. They control SELinux, capabilities, volumes, and UID ranges."	projects/knowledge/interview/openshift/029-what-are-security-context-constraints.txt
openshift/0c94525d7d70	openshift	medium	openshift, routes, builds	What would be the best way to run and manage multiple OpenShift environments?	Federation (or Red Hat Advanced Cluster Management). It provides a single control plane to deploy, manage, and enforce policies across multiple OpenShift clusters from one dashboard.\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.\n\nExample: RHACM provides a single dashboard for cluster lifecycle, policy enforcement, and application deployment across hybrid/multi-cloud OpenShift clusters.	projects/knowledge/interview/openshift/015-what-would-be-the-best-way-to-run-and-manage-multi.txt
openshift/1c45f8e5c2f5	openshift	medium	openshift, routes, builds	What types of nodes OpenShift has?	- Workers: Where the end-user applications are running\n- Masters: Responsible for managing the cluster\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.\n\nUnder the hood: OpenShift 4.x also has infrastructure nodes for routers, monitoring, and registry to keep worker nodes focused on application workloads.	projects/knowledge/interview/openshift/006-what-types-of-nodes-openshift-has.txt
openshift/1e6da5322513	openshift	easy	openshift, routes, builds	How to check what is the current context?	`oc whoami --show-context`\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nExample: `oc whoami` shows the current user. `oc project` shows the current project. `oc config view` shows the full kubeconfig.	projects/knowledge/interview/openshift/031-how-to-check-what-is-the-current-context.txt
openshift/200edce8e9f2	openshift	hard	openshift, routes, builds	Given an example of how a router is used	1. Client is using an address of application running on OpenShift\n2. DNS resolves to host running the router\n3. Router checks whether route exists\n4. Router proxies the request to the internal pod\n\nRemember: Route = OpenShift's Ingress. Predates K8s Ingress, more TLS options.\n\nUnder the hood: The OpenShift router performs L7 routing. It reads the Host header (HTTP) or SNI (TLS) to select the correct backend Service.	projects/knowledge/interview/openshift/028-given-an-example-of-how-a-router-is-used.txt
openshift/21259cefaa4b	openshift	medium	openshift, routes, builds	Which component responsible for determining pod placement?	The Scheduler — the OpenShift/Kubernetes component that watches for newly created Pods with no assigned node, then selects the best node based on resource requests, affinity/anti-affinity rules, taints, tolerations, and topology constraints.\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.	projects/knowledge/interview/openshift/007-which-component-responsible-for-determining-pod-pl.txt
openshift/25795413e8f1	openshift	easy	openshift, routes, builds	What is Random Seek Time?	The time it takes for a disk to reach the place where the data is located and read a single block/sector.\n\nBones question: What is the random seek time in SSD and Magnetic Disk?\nAnswer: Magnetic is about 10ms and SSD is somewhere between 0.08 and 0.16ms\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nNumber anchor: HDD random seek ~10ms, SSD random seek ~0.1ms. This 100x difference explains why databases on SSD are dramatically faster.	projects/knowledge/interview/openshift/019-what-is-random-seek-time.txt
openshift/29cae55a6941	openshift	hard	openshift, routes, builds	Explain Services and their benefits	- Services in OpenShift define access policy to one or more set of pods. \n - They are connecting applications together by enabling communication between them\n - They provide permanent internal IP addresses and hostnames for applications\n - They are able to provide basic internal load balancing\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nUnder the hood: OpenShift Services use kube-proxy (iptables or IPVS mode) to load-balance traffic to pods matching the label selector.	projects/knowledge/interview/openshift/023-explain-services-and-their-benefits.txt
openshift/334314546cb1	openshift	medium	openshift, projects, routes	"You have a new team member and you would like to assign to him the ""admin"" role on your project in OpenShift. How to achieve that?"	`oc adm policy add-role-to-user admin <user> -n <project>` grants the admin role on a specific project. Common roles: admin (full control), edit (create/modify resources), view (read-only). In OpenShift, a Project is a Namespace with additional metadata and default policies. Use `oc get rolebindings -n <project>` to verify the assignment.	projects/knowledge/interview/openshift/013-you-have-a-new-team-member-and-you-would-like-to-a.txt
openshift/35590c36be92	openshift	medium	openshift, routes, builds	How to find out on which node a certain pod is running?	`oc get po -o wide`\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nExample: `oc get po -o wide` shows NODE, IP, and STATUS columns. For detailed placement info: `oc describe pod <name> | grep Node:`.	projects/knowledge/interview/openshift/022-how-to-find-out-on-which-node-a-certain-pod-is-run.txt
openshift/5a01c9a7453b	openshift	hard	openshift, routes, builds	What happens when a pod fails or exit due to container crash	Master node automatically restarts the pod unless it fails too often.\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nUnder the hood: The kubelet\'s restartPolicy controls behavior: Always (default for Deployments), OnFailure (for Jobs), Never (for debugging).	projects/knowledge/interview/openshift/020-what-happens-when-a-pod-fails-or-exit-due-to-conta.txt
openshift/5e80e00d357d	openshift	medium	openshift, routes, builds	True or False? Router container can run only on the Master node	False. It can run on any node.\n\nRemember: Route = OpenShift's Ingress. Predates K8s Ingress, more TLS options.\n\nUnder the hood: The OpenShift router uses HAProxy by default. It runs as a DaemonSet on designated infrastructure nodes.	projects/knowledge/interview/openshift/027-true-or-false-router-container-can-run-only-on-the.txt
openshift/731665b67569	openshift	hard	openshift, routes, builds	What happens when a pod fails too often?	It's marked as bad by the master node and temporary not restarted anymore.\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nUnder the hood: This is CrashLoopBackOff — Kubernetes exponentially backs off restart attempts (10s, 20s, 40s... up to 5 min). Check logs with `oc logs <pod> --previous`.	projects/knowledge/interview/openshift/021-what-happens-when-a-pod-fails-too-often.txt
openshift/88d2ee7f48fb	openshift	hard	openshift, routes, builds	Explain the following in regards to Federation:	* Multi Cluster - Multiple clusters deployed independently, not being aware of each other\n  * Federated Cluster - Multiple clusters managed by the OpenShift Federation Control Plane\n  * Host Cluster - The cluster that runs the Federation Control Plane\n  * Member Cluster - Cluster that is part of the Federated Cluster and connected to Federation Control Plane\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.	projects/knowledge/interview/openshift/017-explain-the-following-in-regards-to-federation-mul.txt
openshift/8eca6ac602d5	openshift	medium	openshift, projects, routes	How to add the ability for the user `user1` to view the project `wonderland` assuming you are authorized to do so	`oc adm policy add-role-to-user view user1 -n wonderland` grants read-only access to the wonderland project. The 'view' role allows listing and getting resources but not creating, modifying, or deleting them. To revoke: `oc adm policy remove-role-from-user view user1 -n wonderland`. Always follow least-privilege — start with 'view' and escalate only when needed.	projects/knowledge/interview/openshift/030-how-to-add-the-ability-for-the-user-user1-to-view-.txt
openshift/8f87578fadd8	openshift	hard	openshift, builds, routes	How OpenShift is related to Kubernetes?	OpenShift is build on top of Kubernetes while defining its own custom resources in addition to the built-in resources.\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.	projects/knowledge/interview/openshift/002-how-openshift-is-related-to-kubernetes.txt
openshift/a02975113018	openshift	medium	openshift, routes, builds	OpenShift supports many resources. How to get a list of all these resources?	`oc api-resources`\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.	projects/knowledge/interview/openshift/009-openshift-supports-many-resources-how-to-get-a-lis.txt
openshift/a7cc74a755b7	openshift	hard	openshift, routes, builds	Explain labels. What are they? When do you use them?	- Labels are used to group or select API objects\n  - They are simple key-value pairs and can be included in metadata of some objects\n  - A common use case: group pods, services, deployments, ... all related to a certain application\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc get pods -l app=myapp,tier=frontend` selects pods with both labels. Labels are how Services find their target pods.	projects/knowledge/interview/openshift/024-explain-labels-what-are-they-when-do-you-use-them.txt
openshift/ae01b86131ed	openshift	medium	openshift, routes, builds	What are some of OpenShift added features on top of Kubernetes?	- UI: OpenShift provides unified UI out-of-the-box\n- Routes: Simple procedure for exposing services\n- Developer Workflow Support: built-in CI/CD (openshift pipelines), built-in container registry and tooling for building artifacts from source to container images\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.	projects/knowledge/interview/openshift/004-what-are-some-of-openshift-added-features-on-top-o.txt
openshift/b096939205d2	openshift	medium	openshift, routes, builds	What are some of the event sources you can use with OpenShift Serverless?	* Kafka\n  * Kubernetes APIs\n  * AWS Kinesis\n  * AWS SQS\n  * JIRA\n  * Slack\n\nMore are supported and provided with OpenShift.\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.\n\nUnder the hood: OpenShift Serverless is built on Knative Serving (scale-to-zero) and Knative Eventing (event-driven). It\'s the Kubernetes-native alternative to AWS Lambda.\n\nUnder the hood: Event sources implement the CloudEvents specification, providing a standardized envelope for events regardless of the source system.	projects/knowledge/interview/openshift/033-what-are-some-of-the-event-sources-you-can-use-wit.txt
openshift/bd8ecd04d9db	openshift	easy	openshift, routes, builds	What is a route in networking and how does routing work?	A route is exposing a service by giving it hostname which is externally reachable\n\nRemember: Route = OpenShift's Ingress. Predates K8s Ingress, more TLS options.	projects/knowledge/interview/openshift/025-what-is-a-route.txt
openshift/c76d26cfd76f	openshift	easy	openshift, routes, builds	How to create a MySQL application using an image from Docker Hub?	`oc new-app mysql`\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.	projects/knowledge/interview/openshift/014-how-to-create-a-mysql-application-using-an-image-f.txt
openshift/c9592bda59d9	openshift	medium	openshift, builds, projects	What is OpenShift Serverless?	- In general 'serverless' is a cloud computing model where scaling and provisioning is taken care for application developers, so they can focus on the development aspect rather infrastructure related tasks\n  - OpenShift Serverless allows you to dynamically scale your applications and provides the ability to build event-driven applications, whether the sources are on Kubernetes, the cloud or on-premise solutions\n  - OpenShift Serverless is based on the Knative project.\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.	projects/knowledge/interview/openshift/032-what-is-openshift-serverless.txt
openshift/c9f44fa28682	openshift	medium	openshift, scc, routes	True or False? To run containers on OpenShift, you have to own root privileges	False. OpenShift supports rootless containers by default.\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.	projects/knowledge/interview/openshift/005-true-or-false-to-run-containers-on-openshift-you-h.txt
openshift/cedc3aa85529	openshift	medium	openshift, routes, builds	What else the scheduler responsible for except pod placement?	Application high availability by spreading pod replicas between worker nodes\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nUnder the hood: Pod topology spread constraints and pod anti-affinity rules ensure replicas are distributed across failure domains (nodes, zones, racks).	projects/knowledge/interview/openshift/008-what-else-the-scheduler-responsible-for-except-pod.txt
openshift/e388e4c0d649	openshift	medium	openshift, routes, builds	True or False? OpenShift is a IaaS (infrastructure as a service) solution	"False. OpenShift is a PaaS (platform as a service) solution.\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nRemember: ""IaaS = raw compute (EC2, VMs). PaaS = platform (OpenShift, Heroku). SaaS = application (Gmail, Slack)."" OpenShift abstracts infrastructure."	projects/knowledge/interview/openshift/003-true-or-false-openshift-is-a-iaas-infrastructure-a.txt
openshift/e51286044f9d	openshift	easy	openshift, routes, builds	What is a storage device? What storage devices are there?	* Hard Disks\n* SSD\n* USB\n* Magnetic Tape\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nExample: `oc new-app python~https://github.com/user/repo` — S2I from source.\n\nUnder the hood: In OpenShift/Kubernetes, storage is abstracted via PersistentVolumes (PV) and PersistentVolumeClaims (PVC). The underlying device type is hidden from the application.	projects/knowledge/interview/openshift/018-what-is-a-storage-device-what-storage-devices-are-.txt
openshift/e687fcc9d9f3	openshift	medium	openshift, routes, builds	What is OpenShift and how does it extend Kubernetes?	OpenShift is a container orchestration platform based on Kubernetes. \nIt can be used for deploying applications while having minimal management overhead.\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.\n\nFun fact: OpenShift 4.x runs on CoreOS (RHCOS) immutable nodes managed by the Machine Config Operator — the OS itself is managed as code.	projects/knowledge/interview/openshift/001-what-is-openshift.txt
openshift/eec816766851	openshift	medium	openshift, routes, builds	What is Replication Controller?	Replication Controller responsible for ensuring the specified number of pods is running at all times. \nIf more pods are running than needed -> it deletes some of them \nIf not enough pods are running -> it creates more\n\nRemember: OpenShift = K8s + Routes, SCCs, S2I, OperatorHub, built-in CI/CD.\n\nGotcha: `restricted` SCC blocks root by default — common gotcha for Docker Hub images.\n\nGotcha: ReplicationControllers are legacy — use Deployments (which create ReplicaSets) instead. Deployments support rolling updates and rollbacks.	projects/knowledge/interview/openshift/034-what-is-replication-controller.txt
openshift/f248ea835352	openshift	easy	openshift, routes, builds	What is OpenShift Federation?	Management and deployment of services and workloads across multiple independent clusters from a single API\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.\n\nUnder the hood: Red Hat Advanced Cluster Management (RHACM) replaced the earlier OpenShift Federation approach with a more mature multi-cluster management plane.	projects/knowledge/interview/openshift/016-what-is-openshift-federation.txt
openshift/f67d8333b592	openshift	easy	openshift, projects, routes	What is a project in OpenShift?	A project in OpenShift is a Kubernetes namespace with annotations. \nIn simpler words, think about it as an isolated environment for users to manage and organize their resources (like Pods, Deployments, Service, etc.).\n\nRemember: OpenShift = Red Hat K8s + CI/CD + console + registry + OAuth + SCC.\n\nFun fact: `oc` CLI = kubectl superset. Every kubectl cmd works, plus `oc new-app`.\n\nUnder the hood: A Project is a Namespace with additional annotations for display name, description, and admin user. `oc new-project` creates these automatically.	projects/knowledge/interview/openshift/011-what-is-a-project-in-openshift.txt
openshift/fe8b7b79a34f	openshift	easy	openshift, projects, routes	"How to list all projects? What the ""STATUS"" column means in projects list output?"	"`oc get projects` will list all projects. The ""STATUS"" column can be used to see which projects are currently active.\n\nRemember: Project = Namespace + metadata. `oc new-project` creates with defaults.\n\nExample: STATUS=Active means the project is functional. STATUS=Terminating means `oc delete project` was called and cleanup is in progress."	projects/knowledge/interview/openshift/012-how-to-list-all-projects-what-the-status-column-me.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Adversarial Interview Gauntlet (30 sequences)](../../../../library/interview-scenarios/gauntlet/README.md) (Scenario, L2) — Kubernetes Core
- [Case Study: Alert Storm — Flapping Health Checks](../../../../library/case-studies/cross-domain/alert-storm-flapping-healthchecks/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Canary Deploy Routing to Wrong Backend — Ingress Misconfigured](../../../../library/case-studies/cross-domain/canary-deploy-wrong-backend-ingress/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: CrashLoopBackOff No Logs](../../../../library/case-studies/kubernetes_ops/crashloopbackoff-no-logs/README.md) (Case Study, L1) — Kubernetes Core
- [Case Study: DNS Looks Broken — TLS Expired, Fix Is Cert-Manager](../../../../library/case-studies/cross-domain/dns-tls-certmanager/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: DaemonSet Blocks Eviction](../../../../library/case-studies/kubernetes_ops/daemonset-blocks-eviction/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Deployment Stuck — ImagePull Auth Failure, Vault Secret Rotation](../../../../library/case-studies/cross-domain/deployment-stuck-imagepull-vault/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: Drain Blocked by PDB](../../../../library/case-studies/kubernetes_ops/drain-blocked-by-pdb/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: HPA Flapping — Metrics Server Clock Skew, Fix Is NTP](../../../../library/case-studies/cross-domain/hpa-flapping-clock-skew-ntp/README.md) (Case Study, L2) — Kubernetes Core
- [Case Study: ImagePullBackOff Registry Auth](../../../../library/case-studies/kubernetes_ops/imagepullbackoff-registry-auth/README.md) (Case Study, L1) — Kubernetes Core

<!-- wiki:related:end -->
