1. Tổng quan Kubernetes
Kubernetes (K8s) là nền tảng orchestration container mã nguồn mở do Google phát triển, tặng cho CNCF năm 2014. Kubernetes tự động hóa việc triển khai, scaling và quản lý containerized applications.
Exam tip: KCNA Domain 1 chiếm 46% đề thi. Câu hỏi thường hỏi "Which component is responsible for..." — học thuộc vai trò từng component.
2. Kiến trúc Kubernetes
Cluster Kubernetes gồm hai loại node: Control Plane và Worker Node.
┌─────────────────────────────────────────────────────────┐
│ CONTROL PLANE │
│ ┌──────────────┐ ┌─────────┐ ┌────────────────────┐ │
│ │ kube-apiserver│ │ etcd │ │kube-controller-mgr │ │
│ │ (REST API) │ │(DB key- │ │ - Node Controller │ │
│ │ front door │ │ value) │ │ - ReplicaSet Ctrl │ │
│ └──────────────┘ └─────────┘ │ - Endpoints Ctrl │ │
│ ┌──────────────┐ └────────────────────┘ │
│ │kube-scheduler│ │
│ │ (assign node)│ │
│ └──────────────┘ │
└─────────────────────────────────────────────────────────┘
│ │ │
┌────────▼──────┐ ┌─────▼──────┐ ┌───▼────────────┐
│ WORKER NODE 1│ │WORKER NODE 2│ │ WORKER NODE 3 │
│ ┌──────────┐ │ │ ┌────────┐ │ │ ┌──────────┐ │
│ │ kubelet │ │ │ │kubelet │ │ │ │ kubelet │ │
│ │kube-proxy│ │ │ │k-proxy │ │ │ │kube-proxy│ │
│ │ Pod Pod │ │ │ │Pod Pod │ │ │ │ Pod Pod │ │
│ └──────────┘ │ │ └────────┘ │ │ └──────────┘ │
└───────────────┘ └────────────┘ └────────────────┘
3. Control Plane Components
| Component | Vai trò | Từ khóa exam |
|---|---|---|
| kube-apiserver | Cổng vào duy nhất của cluster, xử lý REST API. Mọi communication đều qua đây. | "single point of truth", "REST API", "authentication & authorization" |
| etcd | Key-value store lưu trữ toàn bộ cluster state. Là database của Kubernetes. | "cluster state", "consistent", "distributed key-value" |
| kube-scheduler | Xem xét Pod chưa có node và chọn node phù hợp dựa trên resources, constraints. | "schedule", "assign node", "resource fit" |
| kube-controller-manager | Chạy nhiều controller loops: Node, ReplicaSet, Endpoints, ServiceAccount, v.v. | "reconciliation loop", "desired state", "controller" |
| cloud-controller-manager | Tích hợp với cloud provider API (AWS, GCP, Azure) — tùy chọn. | "cloud integration", "LoadBalancer provisioning" |
4. Worker Node Components
| Component | Vai trò | Từ khóa exam |
|---|---|---|
| kubelet | Agent chạy trên mỗi node, nhận PodSpec từ apiserver và đảm bảo containers chạy đúng. | "node agent", "PodSpec", "container health" |
| kube-proxy | Quản lý network rules (iptables/IPVS) cho Services. Cho phép network communication đến Pods. | "networking", "iptables", "Service load balancing" |
| Container Runtime | Software chạy containers: containerd, CRI-O. Docker đã bị deprecated. | "CRI", "containerd", "run containers" |
Exam tip: kubelet là component duy nhất không chạy trong container — nó là systemd service trực tiếp trên node. Nếu kubelet crash, node sẽ NotReady.
5. Kubernetes Objects Cơ Bản
Mọi thứ trong Kubernetes là object — declarative resources được lưu trong etcd.
| Object | Mô tả | Scope |
|---|---|---|
| Pod | Unit nhỏ nhất, chứa 1+ containers chia sẻ network và storage | Namespaced |
| Namespace | Virtual cluster, isolate resources | Cluster-wide |
| Node | Worker machine (VM hoặc physical) | Cluster-wide |
| Deployment | Manage stateless app replicas với rolling update | Namespaced |
| Service | Stable network endpoint cho Pods | Namespaced |
| ConfigMap / Secret | Configuration data | Namespaced |
| PersistentVolume | Storage resource | Cluster-wide |
6. Cheat Sheet — Component → Nhiệm vụ
| Câu hỏi | Trả lời |
|---|---|
| Lưu cluster state ở đâu? | etcd |
| Component nào chọn node cho Pod? | kube-scheduler |
| Component nào chạy trên mỗi worker, quản lý Pods? | kubelet |
| Component nào xử lý tất cả API calls? | kube-apiserver |
| Component nào manage network rules cho Services? | kube-proxy |
| Component nào watch và reconcile desired state? | kube-controller-manager |
7. Practice Questions
Q1: Which Kubernetes control plane component is responsible for watching newly created Pods that have no node assigned, and selecting a node for them?
- A) kube-apiserver
- B) kube-scheduler ✓
- C) kube-controller-manager
- D) kubelet
Explanation: kube-scheduler watches for unscheduled Pods and assigns them to suitable nodes based on resource requirements, affinity rules, and constraints.
Q2: Where does Kubernetes store all cluster configuration and state?
- A) kube-apiserver memory
- B) /etc/kubernetes/ on each node
- C) etcd ✓
- D) kubelet database
Explanation: etcd is the consistent, highly-available key-value store that serves as the backing store for all Kubernetes cluster data. Backing up etcd = backing up the entire cluster.
Q3: Which component on a Worker Node is responsible for ensuring containers described in PodSpecs are running and healthy?
- A) kube-proxy
- B) Container runtime
- C) kubelet ✓
- D) kube-controller-manager
Explanation: kubelet is the node agent that receives PodSpecs from kube-apiserver and ensures the described containers are running. It reports node/Pod status back to the control plane.