Container Services Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Container Services flashcards as text
Which AWS service provides a managed Kubernetes experience and handles control plane upgrades and patching automatically?
Answer: Amazon EKS
Amazon EKS is a fully managed Kubernetes service where AWS operates and upgrades the control plane, including API servers and etcd.
A CI/CD pipeline builds a Docker image and must push it to ECR. After running 'docker build', what is the correct sequence of AWS CLI steps?
Answer: aws ecr get-login-password | docker login → docker tag → docker push
You must authenticate Docker to ECR using get-login-password piped to docker login, then tag the image with the ECR URI, then push it.
What is the function of a Kubernetes Ingress resource in an EKS cluster?
Answer: It manages external HTTP/HTTPS access to services within the cluster
An Ingress resource configures an Ingress controller (e.g., AWS Load Balancer Controller) to route external HTTP/HTTPS traffic to internal Kubernetes services.
Which ECS feature allows you to define CPU and memory at the task level and override them per container?
Answer: Task-level and container-level resource limits in the task definition
ECS task definitions support task-level CPU/memory (required for Fargate) and optional per-container limits that cannot exceed the task-level allocation.
In a CodePipeline deploying to EKS, which action would apply a Kubernetes manifest stored in S3 to the cluster?
Answer: Use an AWS Lambda action that runs kubectl apply
Since CodePipeline has no native EKS action, a Lambda function (or CodeBuild step) running kubectl apply is the standard pattern for deploying Kubernetes manifests.
Which ECS capacity provider strategy setting ensures a minimum number of tasks run on Fargate while using EC2 Spot for additional capacity?
Answer: base and weight parameters in a mixed capacity provider strategy
Setting a 'base' value on Fargate ensures a guaranteed minimum task count, while 'weight' distributes additional tasks proportionally between providers.
What AWS feature allows you to share ECR repositories across multiple AWS accounts in an organization without copying images?
Answer: ECR cross-account resource policies
ECR supports repository policies that grant cross-account pull/push permissions, enabling multiple accounts to use the same image without duplication.