Skip to content

Interview Preparation

Every question below ties back to a real operational concept, not a memorized definition. Reciting "a Service has four types" is worth far less than being able to explain what breaks when a selector doesn't match — which is the difference between passing a screening question and holding up under a senior follow-up.

How This Is Organized

By subject, since that's how you'll actually study:

  1. Core Concepts — Pods, Deployments, Services, namespaces, ConfigMaps/Secrets, labels/selectors
  2. Architecture & Networking — control plane components, kubelet/kube-proxy, CNI, DNS, Ingress vs. Service
  3. Scenario-Based Questions — full debugging walkthroughs for the classic production scenarios
  4. Security & RBAC — RBAC design, service accounts, Pod Security Admission, secrets handling
  5. Senior & Architect Questions — multi-cluster strategy, capacity planning, disaster recovery, cost, build-vs-buy

By Level, Roughly

Level Where to focus
Beginner Core Concepts
Intermediate Architecture & Networking, Security & RBAC
Advanced Scenario-Based Questions
Senior / Architect Senior & Architect Questions

How senior interviews actually differ

A senior interview rarely asks "what is a Service" in isolation — it asks you to reason through a live situation ("15% of requests are 503ing during peak traffic, go") using several concepts at once. Scenario-Based Questions is built around exactly that shape.

Most Common Kubernetes Interview Questions, Answered Briefly

What is Kubernetes? A container orchestrator: you declare the desired state (which images, how many replicas, what resources), and its controllers continuously reconcile the cluster toward it, rescheduling and restarting as things fail. What Is Kubernetes?

What happens when you run kubectl apply? The API server authenticates, authorizes, and admits the request and stores it in etcd; controllers create ReplicaSets and Pods; the scheduler assigns nodes; each node's kubelet starts the containers. Architecture

Deployment vs. StatefulSet vs. DaemonSet? Deployment: interchangeable replicas. StatefulSet: stable names and a volume per replica, for databases and clustered systems. DaemonSet: one Pod per node, for agents. StatefulSets

Liveness vs. readiness vs. startup probe? Liveness failure restarts the container; readiness failure removes it from Service endpoints; the startup probe holds off the other two until a slow app has booted. Probes

Requests vs. limits? Requests are what the scheduler reserves; limits are hard caps. Exceeding a CPU limit throttles; exceeding a memory limit gets the container OOM-killed. Requests and Limits

How do you debug a CrashLoopBackOff? Read the last termination reason and exit code, then kubectl logs --previous, then events. CrashLoopBackOff

How does a Service find its Pods? Its label selector; matching Ready Pods are published in EndpointSlices, which kube-proxy turns into routing rules. Services

Ingress vs. Gateway API? Both route external HTTP traffic to Services. Gateway API is the newer, role-based successor with typed routing features; ingress-nginx, the most common Ingress controller, was retired in 2026. Gateway API

HPA vs. VPA? HPA changes the number of replicas; VPA changes each Pod's CPU and memory requests. Autoscaling

Are Kubernetes Secrets encrypted? Not by default: they're base64-encoded, and encryption at rest in etcd must be configured. Restrict them with RBAC, or source them from an external manager. Secrets and Encryption at Rest

What is a PodDisruptionBudget? A limit on how many of a workload's Pods voluntary disruptions (drains, upgrades, autoscaler scale-downs) may take down at once. PodDisruptionBudgets

Next

Start with Core Concepts, or skip ahead to Quick Reference.