⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 8 of 50 in Platform Engineering & IDP
Staff Platform Engineer Platform Engineering Control Planes & Kratix Kratix Architecture
🎯 Target Role / Context: Staff Platform Engineer Interview · Multi-Cluster Control Planes

Q: You deploy a Kratix Promise for a 'Redis-as-a-Service' capability on your Platform cluster. When a developer submits a Resource Request, the promise workflow pod errors with 'forbidden: cannot create customresourcedefinitions' and no destination cluster sync occurs. How do you triage Kratix multi-cluster reconciliation?

Triage and architectural resolution when a Kratix Promise fails to generate Destination resources across worker clusters due to pipeline pod RBAC errors.

#Platform Engineering #Kratix #Kubernetes #Multi-Cluster #Control Plane #DevEx
🎙️ Candidate Opening & Architectural Context
"Kratix splits operations into a Platform Cluster (where Promises and Resource Requests live) and Worker/Destination Clusters (where workloads actually run). When a Promise fails, the failure occurs either in the Promise configure pipeline pod, the WorkPlacements scheduling controller, or the GitOps/Knative StateStore sync mechanism."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Inspect Resource Request Status and Workflow Pipeline Pod

Check the status of the developer request and query the ephemeral workflow pod generated by Kratix in the `kratix-platform` namespace.

kubectl describe redis.marketplace.acme.com my-cache -n team-cart
# Find matching pipeline pod:
kubectl get pods -n kratix-platform -l kratix.io/promise-name=redis
kubectl logs -n kratix-platform <pipeline-pod-name> -c promise-workflow
2

Correct Pipeline Pod ServiceAccount RBAC Bindings

Kratix pipeline pods execute within a dedicated ServiceAccount. If the Promise pipeline requires reading Secrets or generating CRDs, bind a ClusterRole to the Promise's execution ServiceAccount in the platform cluster.

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: kratix-redis-promise-binding
subjects:
  - kind: ServiceAccount
    name: redis-promise-pipeline-sa
    namespace: kratix-platform
roleRef:
  kind: ClusterRole
  name: kratix-promise-pipeline-role
  apiGroup: rbac.authorization.k8s.io
Advertisement
3

Verify Kratix WorkPlacement and Destination StateStore Sync

Inspect the generated `Work` and `WorkPlacement` CRDs. Confirm that the StateStore (Git repo or S3 bucket) is receiving the output manifests and that the destination cluster's Flux/ArgoCD agent is pulling updates.

kubectl get works.platform.kratix.io -A
kubectl get workplacements.platform.kratix.io -A -o wide
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Kratix multi-cluster vending relies on ephemeral pipeline pods executing transformation scripts and writing WorkPlacements to StateStores. Verify pipeline pod RBAC and destination StateStore synchronization."
⚡ 60-Second Elevator Pitch Talking Points
  • Examine ephemeral pipeline pod logs in kratix-platform to capture raw container script execution errors.
  • Ensure ServiceAccounts assigned to the Promise have sufficient RBAC permissions to read platform secrets.
  • Validate WorkPlacements and Destination StateStore sync targets to confirm delivery to worker clusters.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →