1. Pod — Đơn vị nhỏ nhất
Một Pod là nhóm 1 hoặc nhiều containers chia sẻ cùng network namespace (cùng IP, port space) và storage volumes. Pod là đơn vị scheduling trong Kubernetes.
┌─────────────────────────────────────┐
│ POD │
│ IP: 10.244.1.5 │
│ ┌────────────┐ ┌───────────────┐ │
│ │ Container │ │ Sidecar │ │
│ │ (app) │ │ (log-agent) │ │
│ └────────────┘ └───────────────┘ │
│ Shared Volume: /var/log │
└─────────────────────────────────────┘
Pod Lifecycle
| Phase | Ý nghĩa | Debug hint |
|---|---|---|
| Pending | Chưa được schedule hoặc đang pull image | Check events: kubectl describe pod |
| Running | Đang chạy, ít nhất 1 container đang active | Normal state |
| Succeeded | Tất cả containers thoát với code 0 | Job completed |
| Failed | Ít nhất 1 container thoát với lỗi | kubectl logs --previous |
| Unknown | Không liên lạc được với node | Node network issue |
| CrashLoopBackOff | Container liên tục crash và restart | kubectl logs -p |
Exam tip: CrashLoopBackOff không phải Pod phase chính thức — nó là Container state trong Waiting. Câu hỏi hay hỏi "pod phase" vs "container state".
2. Workload Controllers
| Controller | Dùng khi | Đặc điểm nổi bật |
|---|---|---|
| Deployment | Stateless apps (web server, API) | Rolling update, rollback, ReplicaSet management |
| ReplicaSet | Đảm bảo N replicas (thường dùng qua Deployment) | Label selector, ít dùng trực tiếp |
| StatefulSet | Stateful apps (database, Kafka, Elasticsearch) | Stable pod names (web-0, web-1), stable storage, ordered deployment |
| DaemonSet | Agent chạy trên mọi node (logging, monitoring, network) | 1 Pod/node, auto-deploy khi node mới join |
| Job | Batch task chạy đến khi hoàn thành | completions, parallelism, backoffLimit |
| CronJob | Periodic batch tasks | cron syntax, concurrencyPolicy, schedule |
Deployment vs StatefulSet
DEPLOYMENT (Stateless) STATEFULSET (Stateful)
───────────────────── ────────────────────────
Pod names: web-a1b2c3 Pod names: web-0, web-1, web-2
Any order scale up/down Ordered: web-0 first, then web-1...
Shared or no storage Each Pod gets its own PVC
Pod replaced = new identity Pod replaced = same identity
Examples: nginx, api-server Examples: MySQL, MongoDB, Kafka
3. Labels, Selectors & Annotations
| Concept | Dùng để | Ví dụ |
|---|---|---|
| Labels | Tag resources để select và group | app: frontend, env: prod |
| Selectors | Query resources theo labels | selector: {app: frontend} |
| Annotations | Metadata không dùng để select (build info, contact) | maintainer: [email protected] |
Exam tip: Service tìm Pods qua selector matching Pod labels. Nếu selector không match, Service sẽ có empty Endpoints → traffic không đến được Pod.
4. DaemonSet Use Cases
NODE 1 NODE 2 NODE 3
┌──────┐ ┌──────┐ ┌──────┐
│fluentd│ │fluentd│ │fluentd│ ← Log collector DaemonSet
│ Pod │ │ Pod │ │ Pod │
├──────┤ ├──────┤ ├──────┤
│calico│ │calico│ │calico│ ← CNI network plugin DaemonSet
│ Pod │ │ Pod │ │ Pod │
└──────┘ └──────┘ └──────┘
DaemonSets thường dùng cho: Fluentd/Filebeat (log collection), Prometheus Node Exporter (metrics), kube-proxy (networking), CNI plugins (Calico, Cilium).
5. Cheat Sheet
| Câu hỏi exam | Đáp án |
|---|---|
| Stateful app, cần stable identity? | StatefulSet |
| 1 Pod per node (monitoring agent)? | DaemonSet |
| Stateless app với rolling update? | Deployment |
| One-time batch processing? | Job |
| Scheduled batch (nightly backup)? | CronJob |
| Pod naming pattern cho StatefulSet? | name-0, name-1, name-2 |
6. Practice Questions
Q1: A company needs to deploy a MySQL database on Kubernetes with stable network identity and dedicated storage per replica. Which workload type should they use?
- A) Deployment with PersistentVolumeClaim
- B) StatefulSet ✓
- C) DaemonSet
- D) ReplicaSet
Explanation: StatefulSet provides stable Pod names (mysql-0, mysql-1), ordered deployment/scaling, and each Pod gets its own PVC via volumeClaimTemplates. These properties are essential for databases.
Q2: Which workload ensures exactly one Pod runs on every node in the cluster, including future nodes that join?
- A) Deployment with replicas matching node count
- B) ReplicaSet with nodeSelector
- C) DaemonSet ✓
- D) StatefulSet
Explanation: DaemonSet automatically deploys one Pod per node and watches cluster membership — when a new node joins, the DaemonSet controller immediately creates a Pod on it.
Q3: A Pod is in 'Pending' state. What is the MOST likely cause?
- A) The container application crashed
- B) No node satisfies the scheduling requirements ✓
- C) The liveness probe failed
- D) The container image is corrupted
Explanation: Pending means the Pod has been accepted but hasn't started. Most common reasons: insufficient CPU/memory on nodes, unsatisfied node affinity/taints, or PVC not bound. Check kubectl describe pod events.