Chuyển đến nội dung chính

Bài 1: Kubernetes Architecture & Core Components

Control plane vs Worker node. kube-apiserver, etcd, kube-scheduler, controller-manager, kubelet, kube-proxy. Kubernetes objects overview.

Kubernetes Architecture — Control Plane và Worker Node components

1. Tổng quan Kubernetes

Kubernetes (K8s) là nền tảng orchestration container mã nguồn mở do Google phát triển, tặng cho CNCF năm 2014. Kubernetes tự động hóa việc triển khai, scaling và quản lý containerized applications.

Exam tip: KCNA Domain 1 chiếm 46% đề thi. Câu hỏi thường hỏi "Which component is responsible for..." — học thuộc vai trò từng component.

2. Kiến trúc Kubernetes

Cluster Kubernetes gồm hai loại node: Control Plane và Worker Node.

┌─────────────────────────────────────────────────────────┐
│                    CONTROL PLANE                        │
│  ┌──────────────┐  ┌─────────┐  ┌────────────────────┐ │
│  │ kube-apiserver│  │  etcd   │  │kube-controller-mgr │ │
│  │  (REST API)  │  │(DB key- │  │ - Node Controller  │ │
│  │  front door  │  │ value)  │  │ - ReplicaSet Ctrl  │ │
│  └──────────────┘  └─────────┘  │ - Endpoints Ctrl   │ │
│  ┌──────────────┐               └────────────────────┘ │
│  │kube-scheduler│                                       │
│  │ (assign node)│                                       │
│  └──────────────┘                                       │
└─────────────────────────────────────────────────────────┘
         │              │              │
┌────────▼──────┐ ┌─────▼──────┐ ┌───▼────────────┐
│  WORKER NODE 1│ │WORKER NODE 2│ │  WORKER NODE 3 │
│  ┌──────────┐ │ │ ┌────────┐ │ │  ┌──────────┐  │
│  │ kubelet  │ │ │ │kubelet │ │ │  │ kubelet  │  │
│  │kube-proxy│ │ │ │k-proxy │ │ │  │kube-proxy│  │
│  │ Pod Pod  │ │ │ │Pod Pod │ │ │  │ Pod Pod  │  │
│  └──────────┘ │ │ └────────┘ │ │  └──────────┘  │
└───────────────┘ └────────────┘ └────────────────┘

3. Control Plane Components

ComponentVai tròTừ khóa exam
kube-apiserverCổng vào duy nhất của cluster, xử lý REST API. Mọi communication đều qua đây."single point of truth", "REST API", "authentication & authorization"
etcdKey-value store lưu trữ toàn bộ cluster state. Là database của Kubernetes."cluster state", "consistent", "distributed key-value"
kube-schedulerXem xét Pod chưa có node và chọn node phù hợp dựa trên resources, constraints."schedule", "assign node", "resource fit"
kube-controller-managerChạy nhiều controller loops: Node, ReplicaSet, Endpoints, ServiceAccount, v.v."reconciliation loop", "desired state", "controller"
cloud-controller-managerTích hợp với cloud provider API (AWS, GCP, Azure) — tùy chọn."cloud integration", "LoadBalancer provisioning"

4. Worker Node Components

ComponentVai tròTừ khóa exam
kubeletAgent chạy trên mỗi node, nhận PodSpec từ apiserver và đảm bảo containers chạy đúng."node agent", "PodSpec", "container health"
kube-proxyQuản lý network rules (iptables/IPVS) cho Services. Cho phép network communication đến Pods."networking", "iptables", "Service load balancing"
Container RuntimeSoftware chạy containers: containerd, CRI-O. Docker đã bị deprecated."CRI", "containerd", "run containers"

Exam tip: kubelet là component duy nhất không chạy trong container — nó là systemd service trực tiếp trên node. Nếu kubelet crash, node sẽ NotReady.

5. Kubernetes Objects Cơ Bản

Mọi thứ trong Kubernetes là object — declarative resources được lưu trong etcd.

ObjectMô tảScope
PodUnit nhỏ nhất, chứa 1+ containers chia sẻ network và storageNamespaced
NamespaceVirtual cluster, isolate resourcesCluster-wide
NodeWorker machine (VM hoặc physical)Cluster-wide
DeploymentManage stateless app replicas với rolling updateNamespaced
ServiceStable network endpoint cho PodsNamespaced
ConfigMap / SecretConfiguration dataNamespaced
PersistentVolumeStorage resourceCluster-wide

6. Cheat Sheet — Component → Nhiệm vụ

Câu hỏiTrả lời
Lưu cluster state ở đâu?etcd
Component nào chọn node cho Pod?kube-scheduler
Component nào chạy trên mỗi worker, quản lý Pods?kubelet
Component nào xử lý tất cả API calls?kube-apiserver
Component nào manage network rules cho Services?kube-proxy
Component nào watch và reconcile desired state?kube-controller-manager

7. Practice Questions

Q1: Which Kubernetes control plane component is responsible for watching newly created Pods that have no node assigned, and selecting a node for them?

  • A) kube-apiserver
  • B) kube-scheduler ✓
  • C) kube-controller-manager
  • D) kubelet

Explanation: kube-scheduler watches for unscheduled Pods and assigns them to suitable nodes based on resource requirements, affinity rules, and constraints.

Q2: Where does Kubernetes store all cluster configuration and state?

  • A) kube-apiserver memory
  • B) /etc/kubernetes/ on each node
  • C) etcd ✓
  • D) kubelet database

Explanation: etcd is the consistent, highly-available key-value store that serves as the backing store for all Kubernetes cluster data. Backing up etcd = backing up the entire cluster.

Q3: Which component on a Worker Node is responsible for ensuring containers described in PodSpecs are running and healthy?

  • A) kube-proxy
  • B) Container runtime
  • C) kubelet ✓
  • D) kube-controller-manager

Explanation: kubelet is the node agent that receives PodSpecs from kube-apiserver and ensures the described containers are running. It reports node/Pod status back to the control plane.