Kubernetes Architecture & Components Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Kubernetes Architecture & Components flashcards as text
What is the Container Runtime Interface (CRI) in Kubernetes?
Answer: A plugin API that allows kubelet to use different container runtimes without recompilation
CRI is a plugin interface that enables kubelet to work with different container runtimes (like containerd or CRI-O) through a standard gRPC API.
Which Kubernetes object is used to expose a group of Pods as a network service with load balancing?
Answer: Service
A Service provides a stable virtual IP and DNS name for a set of Pods, load-balancing traffic across healthy Pod endpoints.
What does the term 'reconciliation loop' mean in the context of Kubernetes controllers?
Answer: Continuously comparing actual cluster state to desired state and making corrections
A reconciliation loop watches for changes and continuously drives the actual state of the cluster toward the declared desired state.
Which field in a Pod spec lets you specify that a Pod requires a node with a particular label?
Answer: nodeSelector
nodeSelector is the simplest node selection constraint; it restricts scheduling to nodes that have all the specified key-value label pairs.
What is a Kubernetes Taint used for?
Answer: Repelling Pods from a node unless the Pod has a matching Toleration
Taints allow nodes to repel a set of Pods; only Pods with matching Tolerations can be scheduled onto a tainted node.
Which Kubernetes component is responsible for serving the Kubernetes API, including authentication and authorization of requests?
Answer: kube-apiserver
The kube-apiserver is the front-end of the control plane, validating and processing all REST requests, enforcing authentication, authorization, and admission control.
What is the purpose of a Kubernetes ServiceAccount?
Answer: To provide an identity for processes running in Pods to authenticate with the Kubernetes API
ServiceAccounts provide an identity for Pod processes, allowing them to authenticate to the API server and be granted permissions via RBAC.