1. Kubernetes Overview
Kubernetes (K8s) is an open-source container orchestration platform originally developed by Google, donated to the CNCF in 2014. Kubernetes automates deployment, scaling, and management of containerized applications.
Exam tip: KCNA Domain 1 accounts for 46% of the exam. Questions often ask "Which component is responsible for..." — memorize each component's role.
2. Kubernetes Architecture
A Kubernetes cluster consists of two types of nodes: Control Plane and Worker Node.
┌─────────────────────────────────────────────────────────┐
│ CONTROL PLANE │
│ ┌──────────────┐ ┌─────────┐ ┌────────────────────┐ │
│ │ kube-apiserver│ │ etcd │ │kube-controller-mgr │ │
│ │ (REST API) │ │(DB key- │ │ - Node Controller │ │
│ │ front door │ │ value) │ │ - ReplicaSet Ctrl │ │
│ └──────────────┘ └─────────┘ │ - Endpoints Ctrl │ │
│ ┌──────────────┐ └────────────────────┘ │
│ │kube-scheduler│ │
│ │ (assign node)│ │
│ └──────────────┘ │
└─────────────────────────────────────────────────────────┘
│ │ │
┌────────▼──────┐ ┌─────▼──────┐ ┌───▼────────────┐
│ WORKER NODE 1│ │WORKER NODE 2│ │ WORKER NODE 3 │
│ ┌──────────┐ │ │ ┌────────┐ │ │ ┌──────────┐ │
│ │ kubelet │ │ │ │kubelet │ │ │ │ kubelet │ │
│ │kube-proxy│ │ │ │k-proxy │ │ │ │kube-proxy│ │
│ │ Pod Pod │ │ │ │Pod Pod │ │ │ │ Pod Pod │ │
│ └──────────┘ │ │ └────────┘ │ │ └──────────┘ │
└───────────────┘ └────────────┘ └────────────────┘
3. Control Plane Components
| Component | Role | Exam keywords |
|---|---|---|
| kube-apiserver | The sole entry point of the cluster, handling REST API requests. All communication goes through it. | "single point of truth", "REST API", "authentication & authorization" |
| etcd | Key-value store that holds all cluster state. The database of Kubernetes. | "cluster state", "consistent", "distributed key-value" |
| kube-scheduler | Watches for Pods without assigned nodes and selects a suitable node based on resources and constraints. | "schedule", "assign node", "resource fit" |
| kube-controller-manager | Runs multiple controller loops: Node, ReplicaSet, Endpoints, ServiceAccount, etc. | "reconciliation loop", "desired state", "controller" |
| cloud-controller-manager | Integrates with cloud provider APIs (AWS, GCP, Azure) — optional. | "cloud integration", "LoadBalancer provisioning" |
4. Worker Node Components
| Component | Role | Exam keywords |
|---|---|---|
| kubelet | Agent running on each node; receives PodSpecs from the apiserver and ensures containers are running correctly. | "node agent", "PodSpec", "container health" |
| kube-proxy | Manages network rules (iptables/IPVS) for Services. Enables network communication to Pods. | "networking", "iptables", "Service load balancing" |
| Container Runtime | Software that runs containers: containerd, CRI-O. Docker has been deprecated. | "CRI", "containerd", "run containers" |
Exam tip: kubelet is the only component that doesn't run inside a container — it runs as a systemd service directly on the node. If kubelet crashes, the node becomes NotReady.
5. Core Kubernetes Objects
Everything in Kubernetes is an object — declarative resources stored in etcd.
| Object | Description | Scope |
|---|---|---|
| Pod | Smallest unit, contains 1+ containers sharing network and storage | Namespaced |
| Namespace | Virtual cluster for resource isolation | Cluster-wide |
| Node | Worker machine (VM or physical) | Cluster-wide |
| Deployment | Manages stateless app replicas with rolling updates | Namespaced |
| Service | Stable network endpoint for Pods | Namespaced |
| ConfigMap / Secret | Configuration data | Namespaced |
| PersistentVolume | Storage resource | Cluster-wide |
6. Cheat Sheet — Component → Responsibility
| Question | Answer |
|---|---|
| Where is the cluster state stored? | etcd |
| Which component selects a node for a Pod? | kube-scheduler |
| Which component runs on each worker and manages Pods? | kubelet |
| Which component handles all API calls? | kube-apiserver |
| Which component manages network rules for Services? | kube-proxy |
| Which component watches and reconciles desired state? | kube-controller-manager |
7. Practice Questions
Q1: Which Kubernetes control plane component is responsible for watching newly created Pods that have no node assigned, and selecting a node for them?
- A) kube-apiserver
- B) kube-scheduler ✓
- C) kube-controller-manager
- D) kubelet
Explanation: kube-scheduler watches for unscheduled Pods and assigns them to suitable nodes based on resource requirements, affinity rules, and constraints.
Q2: Where does Kubernetes store all cluster configuration and state?
- A) kube-apiserver memory
- B) /etc/kubernetes/ on each node
- C) etcd ✓
- D) kubelet database
Explanation: etcd is the consistent, highly-available key-value store that serves as the backing store for all Kubernetes cluster data. Backing up etcd = backing up the entire cluster.
Q3: Which component on a Worker Node is responsible for ensuring containers described in PodSpecs are running and healthy?
- A) kube-proxy
- B) Container runtime
- C) kubelet ✓
- D) kube-controller-manager
Explanation: kubelet is the node agent that receives PodSpecs from kube-apiserver and ensures the described containers are running. It reports node/Pod status back to the control plane.