Chuyển đến nội dung chính

Bài 2: Jobs, CronJobs & Resource Management

Jobs (batch tasks), CronJobs (scheduled tasks). Resource requests và limits, LimitRange, ResourceQuota. QoS classes cho CKAD exam.

Jobs và CronJobs — completions, parallelism, concurrencyPolicy

1. Jobs

Một Job tạo một hoặc nhiều Pods và đảm bảo chúng hoàn thành thành công. Khi Job hoàn thành, Pods không bị xóa (cho log inspection).

apiVersion: batch/v1
kind: Job
metadata:
  name: data-processor
spec:
  completions: 3       # Run 3 successful completions
  parallelism: 2       # Run 2 pods at a time
  backoffLimit: 4      # Retry up to 4 times on failure
  template:
    spec:
      restartPolicy: Never  # OnFailure or Never (required for Job)
      containers:
      - name: processor
        image: busybox
        command: ['sh', '-c', 'echo Processing; sleep 5']
FieldÝ nghĩaDefault
completionsSố lần phải hoàn thành1
parallelismSố Pods chạy concurrent1
backoffLimitSố lần retry khi fail6
activeDeadlineSecondsTimeout tổng thể của JobUnlimited

Exam tip: Job Pods phải có restartPolicy: Never hoặc OnFailure. Không thể dùng Always (default cho regular Pods). CKAD hay test việc tạo Job và kiểm tra completion status.

2. CronJobs

apiVersion: batch/v1
kind: CronJob
metadata:
  name: nightly-backup
spec:
  schedule: "0 2 * * *"  # Cron syntax: minute hour day month weekday
  concurrencyPolicy: Forbid  # Allow | Forbid | Replace
  successfulJobsHistoryLimit: 3
  failedJobsHistoryLimit: 1
  jobTemplate:
    spec:
      template:
        spec:
          restartPolicy: OnFailure
          containers:
          - name: backup
            image: backup-tool:1.0
            command: ['./backup.sh']
concurrencyPolicyHành vi
AllowCho phép Jobs chạy concurrent (default)
ForbidSkip new Job nếu previous chưa xong
ReplaceCancel previous Job, start new one

3. Resource Requests & Limits

spec:
  containers:
  - name: app
    image: myapp
    resources:
      requests:
        cpu: "250m"      # 0.25 CPU core (minimum guaranteed)
        memory: "128Mi"  # 128 MiB minimum
      limits:
        cpu: "500m"      # Max 0.5 CPU core
        memory: "256Mi"  # Max 256 MiB (OOM if exceeded)
QoS Classes (dựa trên requests/limits):

Guaranteed:  requests == limits (both CPU and memory)
             → Last to be evicted under pressure

Burstable:   requests < limits (or only one set)
             → Middle priority for eviction

BestEffort:  NO requests, NO limits
             → First to be evicted under pressure

Exam tip: Để Pod có QoS class Guaranteed: phải set cả cpu và memory trong cả requests và limits, và chúng phải bằng nhau. Mỗi container trong Pod đều phải thỏa mãn điều kiện này.

4. LimitRange & ResourceQuota

ObjectScopeMục đích
LimitRangeNamespaceSet default requests/limits cho Pods/Containers trong namespace
ResourceQuotaNamespaceGiới hạn tổng resources namespace được dùng
ResourceQuota example:
apiVersion: v1
kind: ResourceQuota
metadata:
  name: dev-quota
  namespace: development
spec:
  hard:
    requests.cpu: "4"
    requests.memory: "8Gi"
    limits.cpu: "8"
    limits.memory: "16Gi"
    pods: "20"

5. Cheat Sheet

Câu hỏi examĐáp án
Job cần restartPolicy gì?Never hoặc OnFailure
CronJob mỗi 5 phút?*/5 * * * *
Container bị OOM Kill do gì?Vượt limits.memory
QoS Guaranteed cần gì?requests == limits (cả CPU và Memory)
Giới hạn resources của namespace?ResourceQuota

6. Practice Questions

Q1: A Job is configured with completions: 5 and parallelism: 2. How does it execute?

  • A) Creates 5 Pods simultaneously until all complete
  • B) Runs 2 Pods at a time, creating new ones as old ones complete, until 5 total completions ✓
  • C) Runs 5 Pods sequentially one by one
  • D) Creates 2 Pods, each completing 2.5 times

Explanation: completions=5 means 5 PODs must exit successfully. parallelism=2 means at most 2 run at once. As each Pod completes, a new one starts until completion count is reached. Total Pods created could be more if some fail.

Q2: A Pod has no resource requests or limits set. What QoS class is it assigned and how does this affect eviction?

  • A) Guaranteed — it will be last to be evicted
  • B) Burstable — it has medium eviction priority
  • C) BestEffort — it will be first to be evicted under resource pressure ✓
  • D) NoQoS — it has no eviction priority

Explanation: Pods with no resource requests or limits get BestEffort QoS class. When nodes face resource pressure, Kubernetes evicts BestEffort Pods first to free resources for higher-priority workloads.

Q3: A CronJob is scheduled every hour. A previous job is still running when the next scheduled time arrives. With concurrencyPolicy: Forbid, what happens?

  • A) The running job is cancelled; the new one starts
  • B) Both jobs run concurrently
  • C) The new job is skipped; the running job continues ✓
  • D) The CronJob is suspended until the running job completes

Explanation: Forbid policy prevents a new job from starting if the previous job is still running. The scheduled run is skipped. Use Allow to permit concurrent runs or Replace to cancel the old and start the new one.