Kubernetes and Cloud Native Associate (KCNA) flashcards
136 free flashcards. Tap a card to flip it.
Git-based Workflow
Flip cardA development practice where all code, configuration, and artifacts are managed and version-controlled within a Git repository, enabling collaboration, traceability, and automated processes.
- Serves as the single source of truth for all project assets.
- Facilitates collaboration through branching and merging.
- Provides a complete history of changes for auditing and rollback.
Memory trick: Git is the master scroll of all CI/CD changes.
Continuous Integration (CI)
Flip cardA development practice where developers frequently merge their code changes into a central repository, after which automated builds and tests are run. The primary goal of CI is to find and address integration bugs quicker.
- Frequent code merges (multiple times a day).
- Automated build and test processes.
- Early detection of integration issues.
- Maintains a consistently healthy and deployable codebase.
Memory trick: CI is the constant 'check-in' before the 'delivery' journey.
Continuous Deployment (CD)
Flip cardA software release process that uses automated testing to validate if changes are correct and stable, and if so, automatically deploys them to a production environment. It extends Continuous Delivery by removing the manual approval step for production releases.
- Every change that passes automated tests is automatically released to production.
- Requires a very high level of automation and confidence in testing.
- Minimizes lead time from commit to production.
- Differs from Continuous Delivery by removing the manual 'go/no-go' decision.
Memory trick: Continuous Deployment is the 'auto-pilot' for your releases.
Kubernetes Operator (Advanced)
Flip cardAn Operator is a software extension to Kubernetes that makes use of custom resources to manage applications and their components. Operators follow Kubernetes principles, notably the control loop, to automate Day-2 operations for complex, stateful applications.
- Automates Day-2 operations: upgrades, backups, scaling, recovery.
- Extends Kubernetes API with Custom Resource Definitions (CRDs).
- Continuously reconciles desired state with actual state.
- Essential for managing complex stateful workloads like databases or message queues.
Memory trick: Operators are the smart robots managing your complex apps.
Kubernetes Operator
Flip cardA method of packaging, deploying, and managing a Kubernetes application. Operators extend the Kubernetes API with custom resources and use custom controllers to automate operational tasks for complex applications.
- Encapsulates human operational knowledge for specific applications.
- Automates lifecycle management, upgrades, and scaling of stateful applications.
- Leverages Custom Resource Definitions (CRDs) and custom controllers.
Memory trick: The Operator is the brain for complex app operations.
Cloud-Provider Managed Registry
Flip cardA private container registry service offered and managed by a cloud provider (e.g., AWS ECR, GCR, ACR), deeply integrated with their platform's security, IAM, and networking services.
- Offers high availability and scalability without self-hosting overhead.
- Integrates with cloud IAM for granular access control.
- Often includes built-in vulnerability scanning and image signing.
- Optimized for use within the respective cloud ecosystem.
Memory trick: Cloud registries are the 'easy button' for secure image storage.
Helm for Application Packaging
Flip cardHelm serves as a package manager for Kubernetes, allowing developers to define, install, and upgrade even complex Kubernetes applications using 'charts' that bundle all necessary resources and configurations.
- Packages multiple Kubernetes resources (Deployment, Service, ConfigMap, etc.) into a single unit.
- Uses templates to allow customization via values.
- Simplifies repeatable deployments across different environments.
- Manages the lifecycle of applications on Kubernetes.
Memory trick: Helm is the 'all-in-one' builder for your Kubernetes apps.
Infrastructure as Code (IaC)
Flip cardThe practice of managing and provisioning computing infrastructure (e.g., networks, virtual machines, load balancers) using machine-readable definition files, rather than manual configuration or interactive tools.
- Treats infrastructure configuration like application code.
- Enables version control, automation, and repeatability.
- Promotes consistency and reduces configuration drift.
Memory trick: IaC builds your cloud empire from a blueprint.
GitOps
Flip cardGitOps is an operational framework that uses Git as the single source of truth for declarative infrastructure and applications, enabling automated deployment and continuous reconciliation.
- Git is the single source of truth for desired state.
- Declarative specifications for infrastructure and applications.
- Automated reconciliation of actual state to desired state.
- Uses familiar Git tools (PRs, commits) for operations.
Memory trick: GitOps is like a 'Git-powered autopilot' for your Kubernetes cluster.
Helm Charts
Flip cardHelm Charts are packages of pre-configured Kubernetes resources, allowing users to easily deploy, manage, and upgrade applications on a Kubernetes cluster.
- Defines Kubernetes applications as a collection of files.
- Simplifies deployment and management of complex applications.
- Uses Go template language for parameterization.
Memory trick: Helm guides the ship of your app through Kubernetes waters.
Container Image Push
Flip cardThe action of uploading a built and tagged container image to a container registry, making it available for storage, distribution, and subsequent deployment to runtime environments.
- Stores the immutable image in a centralized repository.
- Enables versioning and tracking of images.
- Makes images accessible to Kubernetes clusters and other deployment tools.
- Often requires authentication to the registry.
Memory trick: After building your image, 'push' it to the cloud library.
Operator with CRDs
Flip cardKubernetes Operators, built upon Custom Resource Definitions (CRDs), extend the Kubernetes API to automate the management of complex stateful applications by encoding operational knowledge into software.
- CRDs define new API objects for custom resources.
- Operators provide the intelligence to manage these custom resources.
- Automate complex tasks like provisioning, scaling, backup, and recovery.
- Integrate deeply with Kubernetes control plane.
Memory trick: CRDs are blueprints, Operators are the builders for your custom K8s apps.
Private Container Registry
Flip cardA private container registry is a secure, isolated repository for storing and managing container images, typically used by organizations with specific security, compliance, or network requirements.
- Offers enhanced security and access control.
- Facilitates compliance with regulatory standards.
- Can be self-hosted or managed by a cloud provider within a private context.
Memory trick: For banking, keep images in your own vault, not the public square.
Shift-Left Security
Flip cardThe practice of integrating security measures and testing earlier in the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.
- Reduces cost and effort of fixing security issues.
- Involves security testing in design, development, and build phases.
- Applies to code, dependencies, and container images.
Memory trick: Build secure, deploy secure, run secure.
Secrets Consumption Methods
Flip cardDifferent ways applications can access sensitive data stored in Kubernetes Secrets, each with varying security implications.
- Environment variables: easy to use, but prone to leakage via process introspection.
- Volume mounts (files): generally more secure, limits visibility to filesystem access.
- External secret managers: best practice for reducing Kubernetes' role in secret storage.
Memory trick: Files hide secrets better than loud variables.
Image Signing & Verification
Flip cardA security practice where container images are cryptographically signed by trusted entities (e.g., CI/CD pipelines) and then verified before deployment to ensure their authenticity and integrity.
- Uses digital signatures to prove image origin.
- Ensures images have not been tampered with.
- Prevents supply chain attacks via malicious images.
Memory trick: Sign your images, verify your trust, prevent the bust!
Pod Security Admission (PSA)
Flip cardA built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) on Pods at the namespace level, ensuring Pods adhere to predefined security policies before being admitted to the cluster.
- Replaces Pod Security Policies (PSPs).
- Enforces 'priviliged', 'baseline', or 'restricted' profiles.
- Operates at the admission control phase.
- Configured per namespace using labels.
Memory trick: PSA secures Pod admission.
Kubernetes Role (RBAC)
Flip cardAn RBAC resource in Kubernetes that defines a set of permissions (verbs on resources) within a specific namespace, used to grant access to users, groups, or ServiceAccounts.
- Namespace-scoped: permissions apply only within a single namespace.
- Defines allowed actions (verbs) on specific resources (e.g., 'get', 'list', 'create' on 'pods').
- Bound to subjects using a RoleBinding.
Memory trick: Roles for namespaces, ClusterRoles for clusters.
Kubernetes Secret
Flip cardA Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys, securely within the cluster.
- Stores sensitive data in base64 encoded format (not encrypted by default at rest).
- Can be mounted as files in pods or exposed as environment variables.
- Access control is managed via RBAC.
Memory trick: Secrets secure your sensitive stuff.
Validating Admission Webhooks
Flip cardAn out-of-process admission controller that sends API requests to an external HTTP service for validation, allowing for custom and dynamic policy enforcement.
- Intercepts API requests before persistence.
- Can reject requests if they violate custom policies.
- Used with policy engines (e.g., OPA Gatekeeper, Kyverno).
- Enables flexible, dynamic, and complex policy enforcement.
Memory trick: Webhooks are the custom policy police for your API.
Secrets Encryption at Rest (etcd)
Flip cardThe practice of encrypting sensitive data stored in Kubernetes Secrets objects within the `etcd` key-value store, preventing unauthorized access even if `etcd` itself is compromised.
- By default, Secrets in `etcd` are only base64 encoded, not encrypted.
- Requires explicit configuration (e.g., using an EncryptionConfiguration) to encrypt.
- Protects sensitive data from adversaries with direct `etcd` access.
Memory trick: Etcd's secret is not safe without encryption.
Hardware-enforced Isolation (e.g., Kata, gVisor)
Flip cardAdvanced container runtimes that provide stronger workload isolation by running containers inside lightweight virtual machines (Kata Containers) or user-space kernels (gVisor), mitigating risks from compromised host kernels or container escapes.
- Increases isolation beyond standard Linux namespaces and cgroups.
- Protects against kernel exploits and container escapes.
- Offers a stronger security boundary between containers and the host.
- Useful for multi-tenant environments or highly sensitive workloads.
Memory trick: Kata and gVisor virtualize for safety.
Linux Namespaces
Flip cardA Linux kernel feature that partitions kernel resources such that one set of processes sees one set of resources, while another set of processes sees a different set. This provides the fundamental isolation for containers.
- Isolates process IDs, network interfaces, mount points, user IDs, etc.
- Each container gets its own isolated view of system resources.
- Crucial for preventing containers from interfering with each other or the host.
Memory trick: Namespaces grant each container its own isolated world.
External Secrets Management
Flip cardThe practice of using dedicated, external systems (like KMS or secret vaults) to store, manage, and distribute sensitive data, integrating them with Kubernetes via operators or controllers to provision secrets into the cluster.
- Centralizes secret storage and lifecycle management.
- Integrates with enterprise KMS solutions.
- Provides features like secret rotation, auditing, and fine-grained access control.
- Reduces the security burden on Kubernetes itself.
Memory trick: External secrets, central control.
Seccomp (Secure Computing mode)
Flip cardA Linux kernel feature that allows a process to restrict the set of system calls it can make, thereby reducing the attack surface and enhancing security.
- Filters system calls to whitelist or blacklist specific ones.
- Can be applied to containers to limit their kernel interaction.
- Significantly reduces vulnerability to kernel exploits.
Memory trick: Seccomp secures your container's system calls.
Runtime Security Monitoring
Flip cardThe continuous observation and analysis of container and host behavior during execution to detect and respond to security threats and policy violations in real-time.
- Monitors process execution, file access, network activity, system calls.
- Detects anomalies, policy violations, and known attack patterns.
- Provides real-time alerts and can often enforce policies.
Memory trick: Runtime security watches your containers in action.
Pod SecurityContext
Flip cardA field in a Pod or Container specification that defines privilege and access control settings for a Pod or Container, such as user ID, group ID, and capabilities.
- Applies security settings at Pod or Container level.
- Controls user/group IDs, filesystem permissions, capabilities.
- Helps enforce least privilege and isolation.
Memory trick: SecurityContext is the container's rulebook for how it can run.
Trusted Platform Module (TPM)
Flip cardA secure cryptoprocessor on a computer's motherboard that stores cryptographic keys and provides hardware-level security functions, often used for secure boot and measured boot.
- Provides a hardware root of trust.
- Used for secure boot, measured boot, and disk encryption.
- Ensures integrity and authenticity of system components from boot.
- Crucial for host-level security in cloud-native environments.
Memory trick: TPM measures your boot to ensure trust at the root.
Image Signing and Verification
Flip cardA cloud-native security practice that involves digitally signing container images to confirm their origin and integrity, and then verifying these signatures before deployment.
- Ensures images come from trusted sources.
- Verifies images have not been tampered with.
- Crucial for supply chain security.
Memory trick: Signed images sail safely.
Kubernetes Secrets
Flip cardA Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys. Secrets are designed to be more secure than plain text in ConfigMaps or Pod definitions.
- Stores sensitive data.
- Can be mounted as files or exposed as environment variables.
- Encrypted at rest in etcd (if configured).
Memory trick: ConfigMaps are for maps, Secrets are for keys.
Principle of Least Privilege (PoLP)
Flip cardA security principle that requires every user, program, and process to be granted only the minimum set of permissions necessary to perform its function, and no more.
- Minimizes potential damage from compromises.
- Reduces the attack surface.
- A cornerstone of secure system design.
Memory trick: Least privilege means only the keys you need.
Secrets Encryption At Rest
Flip cardThe practice of encrypting sensitive data, such as Kubernetes Secrets, when it is stored on persistent storage (e.g., etcd), protecting it from unauthorized access even if the storage medium is compromised.
- Protects data on disk, not just in transit or memory.
- Essential for sensitive data like API keys, passwords, certificates.
- Kubernetes can use KMS providers for etcd encryption.
Memory trick: Manage secrets carefully: encrypt, rotate, restrict.
Principle of Least Privilege
Flip cardA security best practice that dictates that users, processes, and programs should be granted only the minimum necessary permissions to perform their authorized functions, and no more.
- Minimizes the potential impact of a compromise.
- Reduces the attack surface.
- Applies to user accounts, service accounts, and system components.
- Crucial for Role-Based Access Control (RBAC) in Kubernetes.
Memory trick: Least Privilege: only what's needed.
Kubernetes NetworkPolicy
Flip cardA Kubernetes resource that controls traffic flow between pods and/or external networks based on labels, namespaces, and IP blocks.
- Applied to pods via `podSelector`.
- Default deny if no policies match for a pod.
- Supports `Ingress` (incoming) and `Egress` (outgoing) rules.
- Rules are additive; if any rule allows traffic, it's permitted.
Memory trick: Policies control traffic, Ingress, Egress, from and to.
Service Mesh for Security
Flip cardAn infrastructure layer that handles inter-service communication within a microservices architecture, providing features like traffic management, observability, and security (e.g., mutual TLS, access control) without modifying application code.
- Automates mutual TLS (mTLS) for encrypted communication.
- Enforces fine-grained access policies between services.
- Provides centralized control over network security.
Memory trick: Mesh your services for secure, effortless communication.
Kubernetes Admission Controllers
Flip cardComponents that intercept requests to the Kubernetes API server after authentication and authorization, but before persistence to the object store, to modify or validate objects.
- Can be Mutating (modify objects) or Validating (reject objects).
- Webhooks allow external services to implement custom admission logic.
- Crucial for enforcing security policies like image validation, resource quotas, etc.
Memory trick: Admission controllers are the bouncers for your API.
Kubernetes API Server Audit Logs
Flip cardDetailed records generated by the Kubernetes API Server that track all requests made to the cluster, including who made the request, when, from where, and what action was performed, crucial for security and compliance.
- Records all authenticated requests to the API Server.
- Captures user, timestamp, source IP, and resource accessed.
- Essential for security monitoring, forensic analysis, and compliance.
- Configurable with different logging policies (None, Metadata, Request, RequestResponse).
Memory trick: API Server logs every action.
Kubernetes API Server
Flip cardThe central component of the Kubernetes control plane that exposes the Kubernetes API. It is responsible for serving the API, authenticating requests, authorizing access, and validating data.
- Entry point for all cluster communication.
- Handles authentication and authorization.
- Validates and processes API requests.
Memory trick: The API Server is the brain and gatekeeper of the Kubernetes cluster.
Container Runtime Security
Flip cardThe practice of protecting containers during their execution phase by monitoring for suspicious activities, enforcing policies, and preventing unauthorized actions.
- Focuses on active threat detection.
- Monitors system calls, file access, network activity.
- Can enforce policies to stop malicious behavior.
Memory trick: Runtime security watches actively.
Shift-Left Security (SAST)
Flip cardA DevSecOps principle that advocates for integrating security practices and testing early in the software development lifecycle, such as using Static Application Security Testing (SAST) to analyze code for vulnerabilities.
- Identifies vulnerabilities in source code before execution.
- Helps developers fix issues early, reducing cost and effort.
- Part of a proactive security strategy in CI/CD.
Memory trick: Shift Left: Secure early, save headaches later.
Kubernetes Role-Based Access Control (RBAC)
Flip cardA method of regulating access to computer or network resources based on the roles of individual users within an enterprise. In Kubernetes, it uses Roles/ClusterRoles and RoleBindings/ClusterRoleBindings to grant permissions.
- Uses Roles to define permissions.
- Uses RoleBindings to grant Roles to subjects (users, service accounts).
- Enforces least privilege by granting only necessary access.
Memory trick: ServiceAccount is 'who', Role is 'what', RoleBinding is 'how they connect'.
Pod Security Standards (PSS)
Flip cardA set of predefined security policies in Kubernetes that define different levels of Pod isolation and restriction, from highly permissive to highly restrictive, to help users enforce security best practices.
- Three levels: Privileged, Baseline, Restricted.
- Enforced by Pod Security Admission (PSA).
- Helps prevent common security vulnerabilities in Pods.
Memory trick: Privileged is wide open, Baseline is good enough, Restricted is locked down tight.
Supply Chain Security (Configuration)
Flip cardExtending supply chain security principles to infrastructure and configuration management, ensuring that all changes to a system's desired state (e.g., Kubernetes manifests, policies) are version-controlled, reviewed, and traceable to prevent tampering or unauthorized modifications.
- Applies to infrastructure-as-code and configuration-as-code.
- Ensures integrity and authenticity of configuration files.
- Utilizes version control, peer review, and automated deployment.
- Mitigates risks from compromised configuration or malicious insiders.
Memory trick: GitOps secures the configuration chain.
Workload Identity
Flip cardA mechanism that allows Kubernetes Service Accounts to assume cloud provider IAM roles, enabling pods to access cloud resources without storing long-lived, static credentials.
- Uses short-lived tokens for authentication.
- Integrates Kubernetes RBAC with cloud IAM.
- Reduces the risk of credential compromise.
- Simplifies credential management and rotation.
Memory trick: IAM roles for service accounts: cloud and K8s together make access right.
Bulkhead Pattern
Flip cardA design pattern that isolates elements of a system into pools so that if one element fails, the others can continue to function. It's named after the compartments of a ship's hull.
- Prevents cascading failures due to resource exhaustion.
- Partitions resources (e.g., thread pools, connection pools).
- Increases system resilience and fault tolerance.
- Limits the blast radius of failures.
Memory trick: Bulkheads build barriers to block blast.
Continuous Delivery (CD)
Flip cardA software engineering approach where teams produce software in short cycles and ensure that the software can be reliably released at any time. It automates testing and deployment to non-production environments, with a manual step for production.
- Automates build, test, and staging deployment.
- Requires manual approval for production deployment.
- Ensures code is always release-ready.
Memory trick: Integrate, Deliver, Deploy: The software journey.
Service Mesh
Flip cardA service mesh is a dedicated infrastructure layer for handling service-to-service communication within a microservices architecture.
- Provides features like traffic management, security, and observability.
- Decouples networking concerns from application code.
- Typically implemented with sidecar proxies alongside each service.
Memory trick: Mesh Makes Microservices Manageable and Secure.
API Gateway
Flip cardA server that acts as a single entry point for a group of microservices. It routes requests, composes responses, and performs cross-cutting concerns like authentication, rate limiting, and logging.
- Single entry point for external clients.
- Handles request routing and composition.
- Manages cross-cutting concerns (auth, rate limiting).
- Decouples clients from microservice implementation details.
Memory trick: Gateway guards and guides gracefully.
Mutual TLS (mTLS) in Service Mesh
Flip cardA security feature in a service mesh that establishes encrypted and mutually authenticated connections between services, where both client and server verify each other's identity using TLS certificates.
- Provides strong identity for services.
- Encrypts all service-to-service traffic.
- Enforces authentication at the transport layer.
- Transparent to application code via sidecar proxies.
Memory trick: mTLS makes services mighty trustworthy.
Serverless Computing
Flip cardA cloud-native execution model where the cloud provider dynamically manages the allocation and provisioning of servers. Developers write and deploy code (functions) without managing any underlying infrastructure.
- No server management required.
- Automatic scaling based on demand.
- Pay-per-execution billing model.
- Ideal for event-driven architectures and variable workloads.
Memory trick: Compute: VMs for control, Containers for portability, Serverless for no ops, PaaS for platform.
Kubernetes ConfigMap
Flip cardA Kubernetes API object used to store non-confidential data in key-value pairs. It allows you to decouple configuration artifacts from image content to keep containerized applications portable.
- Stores non-sensitive configuration data.
- Data injected into pods as environment variables or files.
- Decouples config from application code/image.
- Managed as a Kubernetes object.
Memory trick: ConfigMap keeps config clean.
API Gateway Path-based Routing
Flip cardA feature of API Gateways that directs incoming client requests to specific backend services or endpoints based on the URL path in the request.
- Maps URL paths to backend services.
- Enables multiple services to share a single entry point.
- Supports versioning (e.g., /v1/users, /v2/products).
- Crucial for organizing microservices APIs.
Memory trick: The API Gateway is a smart bouncer, checking IDs, limiting guests, and directing them to the right room.
Circuit Breaking
Flip cardA resilience pattern in distributed systems that prevents a service from repeatedly invoking a failing remote service, thereby preventing cascading failures and allowing the failing service to recover.
- Prevents cascading failures.
- Opens a 'circuit' when failures exceed a threshold.
- Trips to 'half-open' state to re-test the service.
- Protects both the calling and called service.
Memory trick: Resilience patterns are like a doctor's toolkit for sick microservices.
Canary Deployment
Flip cardA deployment strategy where a new version of an application (the 'canary') is released to a small subset of users or servers first, then monitored. If successful, it's rolled out to the entire infrastructure; otherwise, it's rolled back.
- Gradual rollout to a small user base.
- Allows testing with live traffic.
- Enables quick rollback if issues arise.
- Minimizes risk of widespread impact.
Memory trick: Deploy smart: recreate, roll, canary, or blue/green.
Container Orchestration
Flip cardThe automated management, deployment, scaling, networking, and availability of containerized workloads and services.
- Manages container lifecycles.
- Handles scaling up/down based on demand.
- Ensures high availability and fault tolerance.
Memory trick: Cloud's core: containers orchestrated, accessed via API, meshed for comms, balanced for load.
Distributed Tracing
Flip cardAn observability technique used in microservices architectures to track a single request as it propagates through multiple services, providing a detailed view of the request's journey, latency, and any errors.
- Tracks individual requests across services.
- Provides end-to-end visibility.
- Helps identify performance bottlenecks and errors.
- Complements logs and metrics.
Memory trick: Observe with Logs, Metrics, and Traces.
GitOps Rollback
Flip cardThe process of reverting an application or infrastructure state to a previous version by manipulating the Git repository that defines the desired state.
- Git is the single source of truth.
- Rollbacks are performed by reverting Git commits.
- The GitOps operator detects the Git change and reconciles the cluster state.
- Ensures auditability and consistency.
Memory trick: GitOps: Code, Commit, Confirm, Cluster syncs.
Observability
Flip cardThe ability to infer the internal states of a system by examining its external outputs. In cloud-native, it typically relies on three pillars: metrics, logs, and traces, to understand complex distributed systems.
- Crucial for understanding distributed systems.
- Comprises metrics, logs, and traces.
- Enables proactive issue detection and debugging.
- Helps understand system behavior and performance.
Memory trick: O-L-M-T: Observe Logs, Metrics, Traces.
Circuit Breaker Pattern
Flip cardA design pattern used in distributed systems to prevent cascading failures. It wraps calls to potentially failing services, monitoring for failures and 'tripping' the circuit to prevent further calls when a threshold is met.
- Prevents repeated calls to failing services.
- Protects upstream services from being overwhelmed.
- Allows downstream services time to recover.
- Has states: Closed, Open, Half-Open.
Memory trick: Circuit Breaker cuts connections when current crashes.
Service Mesh Mutual TLS (mTLS)
Flip cardA security feature within a service mesh that establishes encrypted and mutually authenticated communication channels between services. Both the client and server services verify each other's identities using TLS certificates.
- Encrypts all inter-service traffic.
- Requires both client and server to authenticate.
- Enhances security posture within the service mesh.
- Often managed transparently by the mesh's sidecar proxies.
Memory trick: Mesh security: mTLS for mutual trust, policies for control.