Q: Describe the pod lifecycle from `kubectl apply` to the app serving traffic.
1. API server receives the pod spec, validates it, stores it in etcd. Pod status: Pending.
#Kubernetes #Advanced Scenarios #L3 #Container Orchestration #K8s #etcd
🎙️ Candidate Opening & Architectural Context
""In our production Kubernetes clusters running microservices on EKS/AKS, this was a classic operational challenge. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
- API server receives the pod spec, validates it, stores it in etcd. Pod status:
Pending. - kube-scheduler notices the unscheduled pod, runs filtering + scoring, writes the
nodeNameto the pod spec. - kubelet on the chosen node watches for pods assigned to it. Sees the new pod.
- kubelet calls the CRI (Container Runtime Interface — containerd/CRI-O) to pull the image.
- Init containers run sequentially to completion.
2️⃣
Remediation & Permanent Safeguards
Execute the resolution runbook and verify workload health:
- Main containers start.
postStartlifecycle hook runs if defined. - Liveness and readiness probes start (after
initialDelaySeconds). - Once readiness probe passes, kube-proxy adds the pod IP to the Service endpoints.
- Traffic flows to the pod.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: API server receives the pod spec, validates it, stores it in etcd. Pod status: Pending.."
⚡ 60-Second Elevator Pitch Talking Points
- API server receives the pod spec, validates it, stores it in etcd. Pod status: Pending.
- kube-scheduler notices the unscheduled pod, runs filtering + scoring, writes the nodeName to the ...
- kubelet on the chosen node watches for pods assigned to it. Sees the new pod.
Advertisement