Interview Preparation¶
Every question below ties back to a real operational concept, not a memorized definition. Reciting "a Service has four types" is worth far less than being able to explain what breaks when a selector doesn't match — which is the difference between passing a screening question and holding up under a senior follow-up.
How This Is Organized¶
By subject, since that's how you'll actually study:
- Core Concepts — Pods, Deployments, Services, namespaces, ConfigMaps/Secrets, labels/selectors
- Architecture & Networking — control plane components, kubelet/kube-proxy, CNI, DNS, Ingress vs. Service
- Scenario-Based Questions — full debugging walkthroughs for the classic production scenarios
- Security & RBAC — RBAC design, service accounts, Pod Security Admission, secrets handling
- Senior & Architect Questions — multi-cluster strategy, capacity planning, disaster recovery, cost, build-vs-buy
By Level, Roughly¶
| Level | Where to focus |
|---|---|
| Beginner | Core Concepts |
| Intermediate | Architecture & Networking, Security & RBAC |
| Advanced | Scenario-Based Questions |
| Senior / Architect | Senior & Architect Questions |
How senior interviews actually differ
A senior interview rarely asks "what is a Service" in isolation — it asks you to reason through a live situation ("15% of requests are 503ing during peak traffic, go") using several concepts at once. Scenario-Based Questions is built around exactly that shape.
Most Common Kubernetes Interview Questions, Answered Briefly¶
What is Kubernetes? A container orchestrator: you declare the desired state (which images, how many replicas, what resources), and its controllers continuously reconcile the cluster toward it, rescheduling and restarting as things fail. What Is Kubernetes?
What happens when you run kubectl apply?
The API server authenticates, authorizes, and admits the request and stores it in etcd; controllers create ReplicaSets and Pods; the scheduler assigns nodes; each node's kubelet starts the containers. Architecture
Deployment vs. StatefulSet vs. DaemonSet? Deployment: interchangeable replicas. StatefulSet: stable names and a volume per replica, for databases and clustered systems. DaemonSet: one Pod per node, for agents. StatefulSets
Liveness vs. readiness vs. startup probe? Liveness failure restarts the container; readiness failure removes it from Service endpoints; the startup probe holds off the other two until a slow app has booted. Probes
Requests vs. limits? Requests are what the scheduler reserves; limits are hard caps. Exceeding a CPU limit throttles; exceeding a memory limit gets the container OOM-killed. Requests and Limits
How do you debug a CrashLoopBackOff?
Read the last termination reason and exit code, then kubectl logs --previous, then events. CrashLoopBackOff
How does a Service find its Pods? Its label selector; matching Ready Pods are published in EndpointSlices, which kube-proxy turns into routing rules. Services
Ingress vs. Gateway API? Both route external HTTP traffic to Services. Gateway API is the newer, role-based successor with typed routing features; ingress-nginx, the most common Ingress controller, was retired in 2026. Gateway API
HPA vs. VPA? HPA changes the number of replicas; VPA changes each Pod's CPU and memory requests. Autoscaling
Are Kubernetes Secrets encrypted? Not by default: they're base64-encoded, and encryption at rest in etcd must be configured. Restrict them with RBAC, or source them from an external manager. Secrets and Encryption at Rest
What is a PodDisruptionBudget? A limit on how many of a workload's Pods voluntary disruptions (drains, upgrades, autoscaler scale-downs) may take down at once. PodDisruptionBudgets
Next¶
Start with Core Concepts, or skip ahead to Quick Reference.