๐What Kubernetes Interviews Test
Kubernetes interviews move quickly from definitions to scenarios: "a pod is Pending โ what do you check?" Learn the concepts below, then practise on a real cluster. Our live Kubernetes course includes break-and-fix labs and mock interviews.
๐Architecture
1. What is Kubernetes?
An open-source platform that automates deploying, scaling and operating containers across a cluster of machines.2. What are the control plane components?
kube-apiserver (the front door), etcd (cluster state store), kube-scheduler (places pods on nodes) and kube-controller-manager (runs reconciliation loops). Cloud clusters add a cloud-controller-manager.3. What runs on a worker node?
The kubelet (runs pods), kube-proxy (service networking) and a container runtime such as containerd.4. What is the reconciliation loop?
Controllers continuously compare desired state (what you declared) with actual state and act to close the gap. It is why Kubernetes self-heals.5. What happens when you run kubectl apply?
kubectl sends the manifest to the API server, which validates it, runs admission controllers and stores it in etcd. Controllers create the required objects, the scheduler assigns pods to nodes and the kubelet starts the containers.๐Workloads
6. Pod vs container?
A pod is the smallest deployable unit โ one or more containers that share a network namespace and storage volumes.7. Deployment vs ReplicaSet?
A ReplicaSet keeps N pods running. A Deployment manages ReplicaSets to provide rolling updates and rollbacks โ you almost always use Deployments.8. Deployment vs StatefulSet?
StatefulSets give each pod a stable name, stable network identity and its own persistent volume, for databases and clustered systems.9. What is a DaemonSet?
It runs one pod on every (or selected) node โ for log shippers, monitoring agents and network plugins.10. Job vs CronJob?
A Job runs pods to completion once; a CronJob creates Jobs on a schedule.11. What are init and sidecar containers?
Init containers run to completion before the main container starts (migrations, waiting for dependencies). Sidecars run alongside it (proxies, log shippers).๐Networking
12. What Service types exist?
ClusterIP (internal only), NodePort (a port on every node), LoadBalancer (cloud load balancer) and ExternalName (DNS alias).13. Service vs Ingress?
A Service gives a stable address to a set of pods. Ingress provides HTTP(S) routing by host and path to many Services through one entry point. The Gateway API is the newer, more expressive successor.14. How does service discovery work?
CoreDNS gives every Service a DNS name such asmy-svc.my-namespace.svc.cluster.local.15. What is a NetworkPolicy?
A firewall rule for pods that controls which pods and namespaces can talk to each other. By default all pod traffic is allowed.๐Configuration and Storage
16. ConfigMap vs Secret?
Both inject configuration as environment variables or files. Secrets are for sensitive data and are base64-encoded, not encrypted by default โ enable encryption at rest or use an external secret manager.17. PV vs PVC vs StorageClass?
A PersistentVolume is a piece of storage, a PersistentVolumeClaim is a request for storage, and a StorageClass provisions PVs dynamically when a PVC is created.๐Scheduling and Scaling
18. Requests vs limits?
Requests are what the scheduler reserves; limits are the maximum. Exceeding the memory limit gets a container OOMKilled; exceeding the CPU limit throttles it.19. What are QoS classes?
Guaranteed (requests equal limits), Burstable and BestEffort. Under node pressure, BestEffort pods are evicted first.20. HPA vs VPA vs Cluster Autoscaler?
HPA adds or removes pod replicas, VPA adjusts pod requests, and the Cluster Autoscaler adds or removes nodes.21. Taints, tolerations and affinity?
Taints repel pods from nodes unless they tolerate the taint; node affinity attracts pods to nodes; pod anti-affinity spreads replicas across nodes or zones.๐Health and Releases
22. Liveness vs readiness vs startup probes?
Liveness restarts an unhealthy container, readiness removes a pod from Service endpoints until it is ready, and startup protects slow-starting apps from early liveness failures.23. How does a rolling update work?
The Deployment creates new pods and removes old ones gradually, controlled bymaxSurge and maxUnavailable. Roll back with kubectl rollout undo.24. How do you do blue-green or canary releases?
With two Deployments and Service selector switching, an Ingress or service mesh traffic split, or a tool such as Argo Rollouts.๐Security
25. How does RBAC work?
Roles and ClusterRoles define allowed verbs on resources; RoleBindings and ClusterRoleBindings grant them to users, groups or ServiceAccounts.26. What is a ServiceAccount?
An identity for pods to call the Kubernetes API, and on EKS (through IRSA or Pod Identity) to access AWS services without static keys.27. What are Pod Security Standards?
Privileged, Baseline and Restricted profiles enforced per namespace, for example blocking root containers or privileged pods.๐Packaging and GitOps
28. What is Helm?
A package manager that templates Kubernetes manifests into versioned charts with configurable values, and supports upgrades and rollbacks.29. What is GitOps?
Git is the source of truth for cluster state, and a controller such as Argo CD or Flux continuously syncs the cluster to match it.๐Troubleshooting Scenarios
30. A pod is in CrashLoopBackOff.
kubectl logs --previous to see why it crashed, kubectl describe pod for events, then check the command, configuration, missing Secrets and liveness probes.31. A pod is stuck in Pending.
kubectl describe pod โ usually insufficient CPU or memory, an unbound PVC, a taint without a toleration, or a node selector that matches no node.32. ImagePullBackOff?
A wrong image name or tag, a private registry without an imagePullSecret, or no network access to the registry.33. A Service is not reachable.
Check that the Service selector matches the pod labels (kubectl get endpoints), that targetPort matches the container port, that readiness probes pass and that no NetworkPolicy blocks traffic.34. A node is NotReady.
Check the kubelet status and logs on the node, disk and memory pressure, the container runtime and the CNI plugin.35. How do you upgrade a cluster safely?
Upgrade the control plane first, then nodes one at a time: cordon, drain (respecting PodDisruptionBudgets), upgrade and uncordon. On EKS or GKE, use managed node group upgrades.For a deeper walkthrough of these scenarios, read our Kubernetes troubleshooting guide.
๐Prepare With a Mentor
Prakalpana's Kubernetes course is taught live online on real clusters with an optional 1-on-1 track, CKA/CKAD preparation and mock interviews. WhatsApp or call +91 9243078181 for a free demo.