Core K8s topics: pods, services, ingress, CRDs, and debugging.
- Deploying a New Application
- Services vs Ingress
- CRDs & Operators
- Logs & Crash Troubleshooting
- Resource in “Terminating” State
- Debugging Inside a Container
- Editing a Resource Live
- Service-to-Service Communication
- Sidecar/Init Containers
- Bonus: Resource Name Limits
- Scenario: RBAC Permissions for Kaniko Builds
- Scenario: Kubernetes Pod Logs Lost After Crash
- Scenario: Resource Exhaustion (OOMKills) in Pods
Question:
If you have a new microservice to run in Kubernetes, what resources do you usually set up?
Hints / Key Points
- Usually a Deployment (or StatefulSet if stateful) and a Service.
- Possibly an Ingress or LoadBalancer if external access is required.
- Might use Helm for templating.
Question:
What does a Service do in Kubernetes, and how is it different from an Ingress?
Hints / Key Points
- Service: Exposes pods at a stable address, can be ClusterIP, NodePort, or LoadBalancer.
- Ingress: Defines routing rules for HTTP/HTTPS traffic to one or more Services.
Question:
How do CRDs (Custom Resource Definitions) and Operators help you extend Kubernetes beyond its default features?
Hints / Key Points
- A CRD adds a new type of object (like “MyDatabase”) to the cluster.
- An Operator watches these CRDs and automates tasks (install, upgrade, manage).
- Good for complex/stateful apps so K8s can handle them more natively.
Question (Scenario):
Your app keeps crashing after a few minutes in Kubernetes. How would you check what’s going on?
Hints / Key Points
- Inspect logs from the pod/container.
- Check events or error messages for the pod.
- See if it’s an OOM kill, code exception, or config problem.
Question:
Sometimes a pod or other resource is stuck “Terminating” for a long time. Why could that happen, and what might you do?
Hints / Key Points
- Finalizers might be blocking deletion.
- The app might not handle termination signals well, so it never exits.
- You can remove the finalizer or do a force delete if absolutely needed.
Question:
You need to run commands inside a container for debugging. How do you do that in a Kubernetes environment?
Hints / Key Points
- Typically use a CLI to exec into the container.
- If multiple containers, specify which container.
- Make sure you have the right RBAC privileges.
Question (Scenario):
You spot a small config mistake in a live resource. How would you fix it right away in the cluster? What risks might that cause?
Hints / Key Points
- You can edit the resource in place with the CLI, but that can cause drift from Git or Helm config.
- If you’re using GitOps, the next sync might overwrite your manual fix.
- Best practice: fix it in your config repo or chart too.
Question:
How do different services within the same cluster talk to each other?
Hints / Key Points
- Cluster DNS:
<service-name>.<namespace>.svc.cluster.local. - A Service provides a stable endpoint, even if pod IPs change.
Question:
What are sidecar containers and init containers, and why might you use them?
Hints / Key Points
- Init containers run first to do setup tasks (migrations, config).
- Sidecar containers run alongside the main app for logging, proxying, etc.
- Helps separate concerns in a single pod.
Question:
Is there a name length limit or other format rule for K8s resources?
Hints / Key Points
- Usually follows DNS label rules (lowercase, up to 63 chars, alphanumeric + dashes).
- Some resource types might vary slightly, but typically the same constraints apply.
Question:
You’re running an Azure DevOps agent in Kubernetes, which uses Kaniko to build and push Docker images. It’s failing because it can’t create needed resources.
- How would you troubleshoot the missing permissions?
- How can RBAC be configured to give Kaniko the required access?
Hints / Key Points
- Check the Pod logs for permission errors (e.g., “forbidden”).
- Assign a ServiceAccount with an appropriate Role/RoleBinding that allows creating ConfigMaps, Pods, etc.
- Verify that the agent is using this ServiceAccount when building.
Question:
A Kubernetes Pod crashes unexpectedly, and its logs are lost because the container restarts too quickly.
- How would you recover logs from a previously crashed container?
- How can you ensure logs are always accessible?
Hints / Key Points
- Use the CLI to get logs from the previous container instance (
-poption), if still available. - Centralize logs in an external system like ELK, Loki, or FluentD.
- Ensure your app flushes logs frequently so they aren’t lost on crash.
Question:
A Kubernetes Pod crashes intermittently and is marked as OOMKilled.
- How would you identify the cause of the memory spikes?
- How do you stop the Pod from running out of memory in the future?
Hints / Key Points
- Check resource usage with
kubectl topor a monitoring tool. - Increase the memory limit if the app truly needs more, or find memory leaks.
- Monitor usage over time, maybe use VPA (Vertical Pod Autoscaler) if appropriate.