Learning · Kubernetes

Kubernetes

Kubernetes is a platform for desired state: you declare what should run, and controllers reconcile toward it. These notes aim at broad coverage — the pieces you actually meet in production clusters — without turning into a flag encyclopedia.

Read in order if you are building intuition; jump by topic if you already ship on EKS/Rancher/GKE and need a sharper take on one area.

Topics

  • What Kubernetes is for

    When the orchestrator earns its complexity — and when a simpler runtime is the senior choice.

  • Architecture and control plane

    API server, etcd, scheduler, controllers, and kubelet — how desired state becomes reality on nodes.

  • Objects, labels, and namespaces

    The API object model — names, labels, selectors, namespaces, and why identity discipline matters at scale.

  • Pods and containers

    The scheduling unit — containers, probes, lifecycle hooks, and why Pods are ephemeral on purpose.

  • Workloads and rollout

    Deployments, pods, and rolling updates — shipping changes without confusing readiness with “the process started.”

  • Stateful, daemon, and batch workloads

    StatefulSets, DaemonSets, Jobs, and CronJobs — when Deployments are the wrong tool.

  • Configuration and secrets

    ConfigMaps, Secrets, and twelve-factor config — without baking credentials into images or cluster YAML lore.

  • Scheduling and placement

    Affinity, taints, topology spread, and priorities — putting Pods where they belong without fighting the scheduler.

  • Resources, QoS, and quotas

    Requests, limits, QoS classes, and namespace quotas — fair sharing without silent eviction surprises.

  • Networking and exposure

    Services, Ingress, and DNS — getting traffic to pods without turning the mesh into the product.

  • Storage and volumes

    Volumes, PVCs, StorageClasses, and CSI — persistent data without pretending every disk is forever.

  • Reliability and scaling

    HPA, PDBs, disruption, and graceful shutdown — staying up when nodes and deploys move under you.

  • Autoscaling

    HPA, VPA, and cluster autoscaler — scaling Pods and nodes without thrash or pending queues.

  • Security and RBAC

    ServiceAccounts, least privilege, and supply chain basics — hardening the cluster without security theater.

  • Admission and policy

    Validating/mutating admission, Pod Security, and policy engines — enforcing defaults before bad objects land.

  • Observability on Kubernetes

    Logs, metrics, and traces in a world where pods disappear — correlating deploys with user pain.

  • CRDs and operators

    Extending the API — custom resources, controllers, and when an operator is worth the operational cost.

  • Packaging and Helm

    Charts, Kustomize, and GitOps packaging — reusable templates without snowflake YAML per environment.

  • Debugging and troubleshooting

    A senior path through Pending, CrashLoop, ImagePull, and networking faults — status before speculation.

  • Day-2 operations

    GitOps, upgrades, backups, and cost — running the platform after the first demo cluster.

  • Multi-tenancy and isolation

    Soft vs hard multi-tenancy — namespaces, quotas, network and security boundaries between teams.