Kubernetes
Kubernetes is a platform for desired state: you declare what should run, and controllers reconcile toward it. These notes aim at broad coverage — the pieces you actually meet in production clusters — without turning into a flag encyclopedia.
Read in order if you are building intuition; jump by topic if you already ship on EKS/Rancher/GKE and need a sharper take on one area.
Topics
- What Kubernetes is for
When the orchestrator earns its complexity — and when a simpler runtime is the senior choice.
- Architecture and control plane
API server, etcd, scheduler, controllers, and kubelet — how desired state becomes reality on nodes.
- Objects, labels, and namespaces
The API object model — names, labels, selectors, namespaces, and why identity discipline matters at scale.
- Pods and containers
The scheduling unit — containers, probes, lifecycle hooks, and why Pods are ephemeral on purpose.
- Workloads and rollout
Deployments, pods, and rolling updates — shipping changes without confusing readiness with “the process started.”
- Stateful, daemon, and batch workloads
StatefulSets, DaemonSets, Jobs, and CronJobs — when Deployments are the wrong tool.
- Configuration and secrets
ConfigMaps, Secrets, and twelve-factor config — without baking credentials into images or cluster YAML lore.
- Scheduling and placement
Affinity, taints, topology spread, and priorities — putting Pods where they belong without fighting the scheduler.
- Resources, QoS, and quotas
Requests, limits, QoS classes, and namespace quotas — fair sharing without silent eviction surprises.
- Networking and exposure
Services, Ingress, and DNS — getting traffic to pods without turning the mesh into the product.
- Storage and volumes
Volumes, PVCs, StorageClasses, and CSI — persistent data without pretending every disk is forever.
- Reliability and scaling
HPA, PDBs, disruption, and graceful shutdown — staying up when nodes and deploys move under you.
- Autoscaling
HPA, VPA, and cluster autoscaler — scaling Pods and nodes without thrash or pending queues.
- Security and RBAC
ServiceAccounts, least privilege, and supply chain basics — hardening the cluster without security theater.
- Admission and policy
Validating/mutating admission, Pod Security, and policy engines — enforcing defaults before bad objects land.
- Observability on Kubernetes
Logs, metrics, and traces in a world where pods disappear — correlating deploys with user pain.
- CRDs and operators
Extending the API — custom resources, controllers, and when an operator is worth the operational cost.
- Packaging and Helm
Charts, Kustomize, and GitOps packaging — reusable templates without snowflake YAML per environment.
- Debugging and troubleshooting
A senior path through Pending, CrashLoop, ImagePull, and networking faults — status before speculation.
- Day-2 operations
GitOps, upgrades, backups, and cost — running the platform after the first demo cluster.
- Multi-tenancy and isolation
Soft vs hard multi-tenancy — namespaces, quotas, network and security boundaries between teams.