← All SRE Flashcard Decks

Kubernetes and Container Orchestration Flashcards

6 cards from real SRE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Kubernetes and Container Orchestration flashcards as text
  1. What is the purpose of Kubernetes namespace-level resource quotas, and how do they support multi-tenant cluster reliability?

    Answer: Resource quotas cap total CPU, memory, and object counts per namespace, preventing one team's workload from consuming all cluster resources and starving other tenants

    ResourceQuota objects set per-namespace upper bounds on total resource consumption (CPU requests/limits, memory, pod count, PVC count, etc.), ensuring no single namespace monopolizes the cluster in a multi-tenant environment.

  2. What is a Kubernetes Ingress resource, and how does it differ from a LoadBalancer-type Service?

    Answer: An Ingress provides HTTP/HTTPS routing with path-based and host-based rules managed by an Ingress controller; a LoadBalancer Service provisions a cloud load balancer for each service, which is more expensive but simpler for non-HTTP protocols

    Ingress controllers provide L7 (HTTP/HTTPS) routing with SSL termination, path-based routing, and virtual hosting — sharing one external IP across many services. LoadBalancer services provision one cloud LB per service, which is simpler but more expensive.

  3. What is the 'eviction API' in Kubernetes, and why should SREs prefer it over directly deleting pods during maintenance?

    Answer: The eviction API respects PodDisruptionBudgets and waits for replacement pods to be ready before completing the eviction, whereas direct deletion bypasses these safety checks

    The eviction API checks PodDisruptionBudgets before terminating a pod and will block or fail the eviction if it would violate the PDB — ensuring minimum availability is maintained during maintenance operations.

  4. What does 'node affinity' in Kubernetes allow, and how does it differ from 'node taints and tolerations'?

    Answer: Node affinity defines rules for which nodes a pod prefers or requires (based on node labels); taints and tolerations define nodes that repel all pods EXCEPT those with matching tolerations

    Node affinity expresses attraction: a pod wants to run ON certain nodes. Taints repel: a node wants to push pods AWAY unless they explicitly tolerate the taint. Both can be required or preferred.

  5. A Kubernetes cluster upgrade is planned for next weekend. What is the MOST important reliability preparation?

    Answer: Verify all workloads have proper PodDisruptionBudgets, check API version compatibility (deprecations), test the upgrade in a staging cluster, and ensure etcd backups are current before starting

    A safe cluster upgrade requires PDB verification (no pod disruption during node drains), API compatibility checks (deprecated APIs may break workloads), staging validation, and fresh etcd backups as the last-resort recovery option.

  6. What is the 'container init pattern' (init containers) in Kubernetes, and what reliability problem does it solve?

    Answer: Init containers run to completion before the main container starts, solving the dependency ordering problem — ensuring databases, config services, or network dependencies are available before the application starts receiving traffic

    Init containers run sequentially to completion before the application container starts, allowing pods to wait for external dependencies (database availability, config service, certificate generation) before beginning to serve traffic.