Kubernetes
An open-source platform that automates deploying, scaling, networking, and operating containerized workloads.
Kubernetes vocabulary.
A practical reference for the cluster components, commands, and resources used to run workloads.
Control plane to node.
The control plane makes global decisions and reconciles the cluster; worker nodes run Pods through the kubelet, network proxy, and container runtime.
- Control plane
- The Kubernetes management layer that exposes the API, makes scheduling decisions, and continuously reconciles cluster state.
- API server
- The authenticated HTTP API entry point for Kubernetes objects and operations.
- etcd
- The strongly consistent key-value store that holds Kubernetes configuration and current cluster state.
- Scheduler
- The control-plane component that selects a suitable node for each unscheduled Pod.
- Controller manager
- A collection of controllers that observe objects and move the cluster toward the declared desired state.
- Kubelet
- The node agent that ensures the containers described by assigned Pods are running and healthy.
- Container runtime
- The software on a node that pulls images and runs containers through the Kubernetes runtime interface.
- kubectl get
- Lists Kubernetes resources and their current high-level status.
- kubectl describe
- Shows detailed fields and recent events for a resource, useful for diagnosing scheduling and startup issues.
- kubectl apply
- Creates or updates resources from declarative YAML or JSON manifests.
- kubectl delete
- Deletes named resources or resources selected by a manifest, label, or namespace.
- kubectl logs
- Reads the stdout and stderr emitted by a container in a Pod.
- kubectl exec
- Runs a command inside a running container for inspection or controlled troubleshooting.
- kubectl rollout
- Inspects, pauses, resumes, or rolls back a workload rollout.
- Pod
- The smallest deployable Kubernetes unit: one or more containers sharing networking and storage context.
- Deployment
- Manages a replicated, replaceable set of Pods and coordinates rolling updates and rollbacks.
- DaemonSet
- Ensures a copy of a Pod runs on every eligible node, or on a selected set of nodes.
- StatefulSet
- Manages stateful Pods with stable identities, ordered deployment, and persistent storage association.
- Service
- Provides a stable virtual endpoint and load balancing for a changing set of Pods.
- Ingress
- Declares HTTP or HTTPS routing from outside the cluster to Services through an ingress controller.
- ConfigMap
- Stores non-sensitive configuration that can be injected into Pods as environment variables or files.
- Secret
- Stores sensitive values for workloads, though encryption at rest, access control, and rotation still require deliberate configuration.
- Namespace
- Provides a logical scope for names, access policies, quotas, and environment or team boundaries.
- PersistentVolumeClaim
- A workload’s request for durable storage that Kubernetes binds to an available PersistentVolume.
- CustomResourceDefinition
- Extends the Kubernetes API with a new resource kind that operators or controllers can reconcile.
- ClusterIP
- The default Service type with an internal virtual IP reachable from within the cluster.
- NodePort
- Opens a port on each node and forwards traffic to the Service’s selected Pods.
- LoadBalancer
- Requests an external load balancer from the infrastructure or cloud provider and routes traffic to the Service.
- ExternalName
- Maps a Service name to an external DNS name instead of selecting Pods inside the cluster.
- Headless Service
- A Service with `clusterIP: None` that returns Pod addresses directly through DNS.
Components
Commands
kubectl get pods -n productionkubectl describe pod api-7d9f6d8b7f-x2k4mkubectl apply -f deployment.yamlkubectl delete -f deployment.yamlkubectl logs deploy/api -fkubectl exec -it deploy/api -- shkubectl rollout status deploy/apiResources
Run one application instance or a tightly coupled group of containers.
Run stateless web servers, APIs, and workers with controlled releases.
Run node-level agents such as log collectors, monitoring agents, or storage plugins.
Run databases, queues, and clustered systems that need stable names or volumes.
Let clients reach a workload without knowing which Pods are currently running.
Expose multiple web applications behind shared host, path, and TLS rules.
Separate environment-specific settings from an application image.
Provide credentials, tokens, certificates, or connection strings to workloads.
Separate teams or environments and apply distinct access and resource policies.
Give stateful workloads storage that survives Pod replacement.
Model platform-specific APIs and let an operator manage their lifecycle.
Service types
Expose an internal API or database to other workloads.
Provide simple external access when a cloud load balancer is unavailable or unnecessary.
Publish a production application through a provider-managed external endpoint.
Give applications a stable Kubernetes name for an external database or managed service.
Enable client-side discovery for StatefulSets and systems that manage their own membership.
Why it exists.
It solves the operational complexity of keeping many containers healthy, discoverable, and scheduled across a cluster of machines.
Where it shines.
Platform teams running resilient, portable services that need declarative infrastructure and automated scheduling at scale.
Where not to use it.
Do not use it for a single small service, a simple static site, or a team that does not need the operational overhead of a cluster.
What it is made of.
- Control plane
- Worker nodes
- API server
- Scheduler, controllers, and kubelet
- Services and networking
How it works.
- A manifest describes the desired workload
- The API server stores the desired state
- The scheduler places workloads on nodes
- Controllers reconcile the cluster continuously