Kubernetes and Cloud Native Associate (KCNA) flashcards
136 free flashcards. Tap a card to flip it.
Microservices
Flip cardAn architectural style that structures an application as a collection of loosely coupled, independently deployable services, organized around business capabilities.
- Small, autonomous services.
- Communicate via APIs.
- Independent deployment and scaling.
- Owned by small, dedicated teams.
Memory trick: Microservices are like LEGO bricks, each doing one job, building a big structure.
Serverless Computing
Flip cardA cloud-native execution model where the cloud provider dynamically manages the allocation and provisioning of servers. Developers write and deploy code (functions) without managing any underlying infrastructure.
- No server management required.
- Automatic scaling based on demand.
- Pay-per-execution billing model.
- Ideal for event-driven architectures and variable workloads.
Memory trick: Compute: VMs for control, Containers for portability, Serverless for no ops, PaaS for platform.
API Gateway Path-based Routing
Flip cardA feature of API Gateways that directs incoming client requests to specific backend services or endpoints based on the URL path in the request.
- Maps URL paths to backend services.
- Enables multiple services to share a single entry point.
- Supports versioning (e.g., /v1/users, /v2/products).
- Crucial for organizing microservices APIs.
Memory trick: The API Gateway is a smart bouncer, checking IDs, limiting guests, and directing them to the right room.
Circuit Breaking
Flip cardA resilience pattern in distributed systems that prevents a service from repeatedly invoking a failing remote service, thereby preventing cascading failures and allowing the failing service to recover.
- Prevents cascading failures.
- Opens a 'circuit' when failures exceed a threshold.
- Trips to 'half-open' state to re-test the service.
- Protects both the calling and called service.
Memory trick: Resilience patterns are like a doctor's toolkit for sick microservices.
Container Orchestration
Flip cardThe automated management, deployment, scaling, networking, and availability of containerized workloads and services.
- Manages container lifecycles.
- Handles scaling up/down based on demand.
- Ensures high availability and fault tolerance.
Memory trick: Cloud's core: containers orchestrated, accessed via API, meshed for comms, balanced for load.
Observability
Flip cardThe ability to infer the internal states of a system by examining its external outputs. In cloud-native, it typically relies on three pillars: metrics, logs, and traces, to understand complex distributed systems.
- Crucial for understanding distributed systems.
- Comprises metrics, logs, and traces.
- Enables proactive issue detection and debugging.
- Helps understand system behavior and performance.
Memory trick: O-L-M-T: Observe Logs, Metrics, Traces.
PersistentVolumeClaim (PVC)
Flip cardA request for storage by a user or application within a Kubernetes cluster.
- Abstracts the underlying storage details from the user.
- Binds to an available PersistentVolume (PV) that satisfies its requirements.
- Can be specified in Pod definitions to mount storage.
Memory trick: PVC is like a 'Claim check' for your persistent storage 'luggage'.
Kubernetes LoadBalancer Service
Flip cardA Kubernetes Service type that exposes a Service externally using a cloud provider's load balancer.
- Automatically provisions an external IP address.
- Distributes external traffic across the backend Pods.
- Requires integration with a cloud provider (e.g., AWS ELB, GCP Load Balancer).
Memory trick: LoadBalancer is the 'big truck' that brings 'traffic' from the 'internet' to your 'app'.
Kubernetes nodeSelector
Flip cardA Pod scheduling property that constrains a Pod to only run on nodes that have specific labels.
- Allows specific hardware or environment requirements to be met.
- Node labels are typically set by administrators or automatically by cloud providers.
- A Pod will only be scheduled if all `nodeSelector` labels match a node's labels.
Memory trick: NodeSelector is like a 'VIP pass' for your Pod to get into the 'right node'.
Kubernetes Service Selector
Flip cardA mechanism used by Kubernetes Services to identify a group of Pods that provide a specific functionality.
- Based on key-value label pairs assigned to Pods.
- Allows Services to dynamically route traffic to healthy Pods.
- Ensures loose coupling between Service definitions and Pod lifecycles.
Memory trick: Services select Pods like a 'selector switch' connects to the right 'power outlet'.
Kubernetes Pod
Flip cardThe smallest and most fundamental deployable unit in Kubernetes, representing a single instance of a running process in a cluster.
- Encapsulates one or more containers (e.g., Docker containers).
- Shares network namespace, IP address, and storage volumes among its containers.
- Designed to run co-located, co-managed applications.
Memory trick: Pods are the 'peas' in the Kubernetes 'pod' – smallest and most essential.
Kubernetes Deployment
Flip cardA Kubernetes API object that manages a replicated application by declaratively defining its desired state, handling updates and scaling.
- Manages ReplicaSets to control the number of Pods.
- Enables declarative updates and rollbacks of applications.
- Suitable for stateless applications.
Memory trick: Deployments 'deploy' your app with 'updates' and 'scaling' handled.
Kubernetes hostPort
Flip cardA configuration in a Pod's container definition that maps a container port to a specific port on the host (Node) machine's network interface.
- Makes the container directly accessible via the Node's IP address and the specified `hostPort`.
- Can lead to port conflicts if multiple Pods on the same Node try to use the same `hostPort`.
- Generally discouraged in production in favor of Services (NodePort, LoadBalancer) or Ingress for better abstraction and load balancing.
Memory trick: `hostPort` is like giving your Pod a 'direct line' to the 'host's phone'.
Kubernetes Namespace
Flip cardA mechanism to logically partition a single Kubernetes cluster into multiple virtual clusters.
- Provides scope for names (e.g., two Pods named 'my-app' can exist in different namespaces).
- Can be used for resource quotas and access control (RBAC).
- Most Kubernetes objects belong to a Namespace, except cluster-wide objects like Nodes or PersistentVolumes.
Memory trick: Namespaces are like 'rooms' in a 'cluster house' – each has its own space.
`kubectl get` command
Flip cardA fundamental `kubectl` command used to retrieve and display information about Kubernetes resources.
- Provides a quick, tabular summary by default.
- Can be used with various resource types (pods, services, deployments, nodes, etc.).
- Supports output formats like YAML, JSON, and wide (`-o wide`) for more details.
Memory trick: To 'get' a quick 'list', use `kubectl get` to 'see' everything.
kube-apiserver
Flip cardThe central component of the Kubernetes control plane that exposes the Kubernetes API.
- Processes REST requests and provides the front-end to the cluster's shared state.
- Validates and configures data for API objects (Pods, Services, etc.).
- Is the only component that communicates directly with `etcd` for state persistence.
Memory trick: API server is the 'receptionist' for all 'Kubernetes calls'.
`kubectl logs` command
Flip cardA `kubectl` command used to fetch logs from a container running in a Pod.
- Retrieves `stdout` and `stderr` streams of containers.
- Can specify a container name if a Pod has multiple containers (`-c <container-name>`).
- Supports `follow` mode (`-f`) for real-time log streaming and `tail` (`--tail=N`) for last N lines.
Memory trick: To 'log' in, use `kubectl logs` to 'see' what's happening.
Kibana
Flip cardThe 'K' in ELK stack, Kibana is an open-source data visualization and exploration tool designed to work with Elasticsearch.
- Provides interactive dashboards and charts.
- Enables real-time analysis of time-series data.
- Used for logs, metrics, and other data types stored in Elasticsearch.
Memory trick: ELK: Elasticsearch stores, Logstash processes, Kibana visualizes.
Prometheus High Cardinality
Flip cardA condition in Prometheus where a metric has an excessive number of unique label combinations, leading to high memory usage, increased disk I/O, and degraded query performance.
- Caused by labels that change frequently or have many unique values.
- Can lead to resource exhaustion and instability in Prometheus.
- Mitigated by relabeling, aggregation, or using external storage solutions like Thanos.
Memory trick: Too many labels make Prometheus slow, so clean them up!
Log Shipper
Flip cardA software agent that collects, parses, transforms, and forwards log data from various sources to a centralized logging system for storage and analysis.
- Runs as a daemonset or sidecar in Kubernetes.
- Handles log collection from container stdout/stderr, files, etc.
- Often performs filtering, parsing, and enrichment before forwarding.
Memory trick: Logs from containers need a ship to the cloud.
Kubernetes `/metrics` Endpoints
Flip cardStandard HTTP endpoints exposed by Kubernetes control plane components (and often by applications) that provide internal performance and operational metrics in a Prometheus-compatible text format.
- Each core Kubernetes component (apiserver, scheduler, controller-manager) has one.
- Allows Prometheus to scrape detailed health and performance data.
- Essential for monitoring the health of the Kubernetes control plane itself.
Memory trick: The control plane has its own metrics language, `/metrics`.
Black-box Monitoring
Flip cardObserving a system's behavior from an external perspective, typically by interacting with its public interfaces and measuring its responses, without insight into its internal workings.
- Focuses on user experience and external availability.
- Often involves synthetic transactions or API calls.
- Complements white-box monitoring by verifying end-to-end functionality.
Memory trick: Is the box black (external) or white (internal)?
Prometheus
Flip cardAn open-source monitoring and alerting toolkit designed for reliability and scalability, especially suited for dynamic cloud-native environments.
- Collects time-series data via a pull model (scraping HTTP endpoints).
- Stores data in a local on-disk time series database.
- Offers a powerful query language, PromQL, for analyzing metrics.
- Integrates with Alertmanager for alert notification.
Memory trick: Prometheus pulls and plots historical performance.
Thanos
Flip cardAn open-source project that extends Prometheus to enable global query views, high availability, and long-term historical data storage across multiple Prometheus instances, typically using object storage.
- Solves multi-cluster monitoring challenges for Prometheus.
- Provides a single pane of glass for all Prometheus metrics.
- Handles long-term storage and downsampling of metrics.
Memory trick: Thanos collects all the Prometheus gems for a global view.
Federated Metrics (Global Monitoring)
Flip cardA monitoring strategy where metrics from multiple independent monitoring systems (e.g., Prometheus instances) are aggregated into a central system to provide a unified, global view of infrastructure and application health.
- Essential for multi-cluster or multi-region deployments.
- Enables global dashboards and alerts.
- Often implemented using solutions like Thanos or Cortex for Prometheus.
Memory trick: Federated Metrics give you a Full, Global view.
Fluent Bit
Flip cardA lightweight and high-performance log processor, forwarder, and aggregator for various data sources, including containers and Kubernetes.
- Part of the Fluentd ecosystem.
- Designed for minimal resource consumption.
- Supports numerous input and output plugins.
- Often deployed as a DaemonSet in Kubernetes to collect node-level logs.
Memory trick: Fluent Bit filters and forwards logs efficiently.
Four Golden Signals (Traffic)
Flip cardOne of the 'four golden signals' of monitoring, 'Traffic' measures the demand being placed on a system, typically quantified as requests per second or throughput.
- Indicates the amount of work a service is doing.
- Essential for understanding service load and scaling needs.
- Often measured as RPS for web services or bytes/second for network services.
Memory trick: LET'S monitor: Latency, Errors, Traffic, Saturation.
Profiling (Observability)
Flip cardAn observability technique that analyzes the execution characteristics of a program, such as CPU usage, memory allocation, and function call times, to identify performance bottlenecks.
- Provides granular, in-code visibility.
- Helps identify exact functions or lines of code causing issues.
- Often used in conjunction with other observability pillars.
Memory trick: Profiling provides a deep dive into your Code's Performance.
Network Flow Monitoring
Flip cardThe process of collecting, analyzing, and visualizing network traffic metadata to understand network usage, performance, and security.
- Captures metadata (e.g., NetFlow, sFlow) not full packets.
- Identifies traffic patterns, top talkers, and anomalies.
- Essential for network security, capacity planning, and troubleshooting.
Memory trick: Network needs Flows to know where everything goes.
Structured Logging
Flip cardLogging where each log entry is formatted as a consistent, machine-readable data structure (e.g., JSON, key-value pairs), enabling powerful querying, filtering, and analysis.
- Easier to parse and query than unstructured text logs.
- Allows for adding rich context (e.g., user ID, transaction ID, service version).
- Essential for effective log analysis in distributed systems.
Memory trick: Structured logs are like organized files, easy to find specific info.
Elasticsearch
Flip cardA distributed, open-source search and analytics engine built on Apache Lucene, commonly used for log and event data storage and analysis.
- Part of the 'E' in the ELK stack (Elasticsearch, Logstash, Kibana).
- Provides powerful full-text search, near real-time analytics, and schema-free JSON document storage.
- Scalable horizontally to handle large volumes of data.
- Often used as a backend for log management systems.
Memory trick: Elasticsearch stores and searches logs with ease.
Distributed Tracing (Asynchronous)
Flip cardThe application of distributed tracing to track the lifecycle of a message or event through asynchronous components like message queues and event buses.
- Requires propagating trace context (trace ID, span ID) with messages.
- Helps visualize the entire asynchronous flow.
- Identifies bottlenecks and failures in event-driven architectures.
Memory trick: Traces follow the Thread of your message, even when it's not direct.
Prometheus Counter
Flip cardA Prometheus metric type that represents a single, monotonically increasing cumulative value, which can only be incremented or reset to zero on restart.
- Used for tracking counts of events (e.g., requests served, errors encountered).
- Cannot decrease its value (except on restart).
- Often combined with `rate()` or `irate()` functions in PromQL for per-second rates.
Memory trick: Count the events, Gauge the current, Histogram the distribution.
Alerting
Flip cardThe process of detecting anomalous or undesirable conditions in a system, typically by monitoring metrics or logs against predefined thresholds, and notifying relevant personnel or automated systems.
- Aims for timely detection of issues.
- Often integrates with communication tools (e.g., PagerDuty, Slack).
- Requires carefully defined thresholds to avoid alert fatigue.
Memory trick: Observe, then Alert, to keep things stable.
Grafana
Flip cardAn open-source platform for monitoring and observability, allowing users to query, visualize, alert on, and explore metrics, logs, and traces.
- Supports multiple data sources (e.g., Prometheus, Elasticsearch).
- Creates interactive dashboards.
- Widely used for visualizing time-series data.
Memory trick: G for Graphs, Grafana for visualization.
Kubernetes Audit Logs
Flip cardA stream of chronologically ordered records of API server requests, used for security auditing, compliance, and forensic analysis within a Kubernetes cluster.
- Records who, what, when, and from where for API server interactions.
- Can be configured for different levels of verbosity (e.g., metadata, request, response).
- Essential for security and regulatory compliance in production clusters.
Memory trick: Audit logs are the security camera for the API server.
Prometheus Recording Rules
Flip cardRules defined in Prometheus that allow pre-calculating frequently needed or computationally expensive expressions and storing their result as new time series.
- Reduces query load by pre-calculating results.
- Can be used to reduce metric cardinality by aggregating labels.
- Improves dashboard load times and alert evaluation.
Memory trick: Recording Rules Reduce Redundancy and make Queries Quicker.
OpenTelemetry
Flip cardA vendor-neutral set of APIs, SDKs, and tools for instrumenting, generating, collecting, and exporting telemetry data (metrics, logs, and traces).
- Consolidates metrics, logs, and traces into a single standard.
- Enables vendor independence for observability backends.
- Supports various programming languages and frameworks.
Memory trick: OpenTelemetry is the Standard for all your Telemetry.
Continuous Profiling
Flip cardA technique for continuously collecting and analyzing application performance profiles in production, identifying resource-intensive code paths (hot spots) like CPU usage, memory allocations, or I/O operations.
- Provides granular, function-level insights into resource consumption.
- Helps optimize code performance and reduce resource overhead.
- Often uses sampling to minimize overhead in production environments.
Memory trick: Profiling is like a detailed MRI for your code.
Fluentd
Flip cardAn open-source data collector for unified logging, designed to collect, parse, transform, and store data.
- Supports over 1000 plugins for various sources and destinations.
- Often used in conjunction with Elasticsearch and Kibana (ELK stack).
- Ideal for collecting logs from containerized environments.
Memory trick: Fluentd makes logs Flow from source to destination.
Alertmanager
Flip cardThe Prometheus ecosystem component that handles alerts sent by client applications like the Prometheus server, managing deduplication, grouping, and routing.
- Receives alerts from Prometheus.
- Groups similar alerts to reduce noise.
- Routes alerts to various integrations (email, Slack, PagerDuty).
Memory trick: Alertmanager Manages your alerts, like a traffic cop.
Context Propagation
Flip cardThe mechanism in distributed tracing that passes trace identifiers (trace ID, span ID) and other relevant context between services, including across process boundaries, network calls, and asynchronous message queues, to reconstruct the full path of a request.
- Essential for end-to-end visibility in microservices and event-driven architectures.
- Typically involves injecting and extracting headers or message attributes.
- Standardized by initiatives like W3C Trace Context.
Memory trick: Context is the thread that connects the scattered pieces of a trace.
kube-scheduler
Flip cardA Kubernetes control plane component that watches for newly created Pods that have no assigned node, and selects a node for them to run on. It considers resource requirements, hardware/software/policy constraints, affinity/anti-affinity specifications, and data locality.
- Assigns Pods to Nodes.
- Considers various constraints and requirements.
- Crucial for Pod placement and resource utilization.
Memory trick: API for Access, Scheduler for Spots, Controller for Consistency, Kubelet for Kicking off.
etcd
Flip cardetcd is a distributed, consistent, and highly available key-value store used by Kubernetes to store all cluster data.
- Stores cluster state, configuration, and metadata.
- Crucial for Kubernetes control plane operation.
- Requires high availability for cluster resilience.
- Communicates with `kube-apiserver`.
Memory trick: API is the front, Scheduler picks, Controller acts, etcd stores it all.
Node Selector
Flip cardA field in a Pod's specification that specifies a map of key-value pairs. For the Pod to be eligible to run on a node, the node must have each of the indicated key-value pairs as labels.
- Constrains Pods to specific nodes.
- Uses node labels for matching.
- Simple, hard requirement.
Memory trick: Selector selects the perfect node!
Container command field
Flip cardThe `command` field in a Kubernetes container specification allows overriding the `ENTRYPOINT` defined in the Docker image, specifying the executable to run.
- Overrides the image's `ENTRYPOINT`.
- Corresponds to the `CMD` instruction if `ENTRYPOINT` is not set.
- Should be an array of strings (executable and its fixed arguments).
- `args` field provides additional arguments.
Memory trick: Command the Entrypoint, Args for the CMD.
Pod `image` field
Flip cardThe `image` field within a container's specification (`spec.containers[].image`) in a Kubernetes Pod manifest, used to define the Docker image to be pulled and run for that container.
- Located under `spec.containers`.
- Specifies the image name and optional tag (e.g., `myrepo/myimage:v1.0`).
- Crucial for defining the application's executable component.
Memory trick: Containers Contain Images and Names.
Kubernetes NodePort Service
Flip cardA Kubernetes Service type that exposes the Service on a static port (the NodePort) on each of the cluster's worker Nodes. This makes the Service accessible from outside the cluster by hitting <NodeIP>:<NodePort>.
- Exposes Service on a static port on each Node.
- Allows external access to internal services.
- Often used for development, testing, or exposing a small number of services.
Memory trick: NodePort for Node Access, ClusterIP for Internal, LoadBalancer for Cloud.
kubectl apply
Flip cardThe `kubectl apply` command is used for applying changes to Kubernetes resources defined in a file. It creates the resource if it doesn't exist or updates it if it does, based on the file's content.
- Idempotent: running it multiple times has the same effect.
- Uses server-side apply (or client-side apply) to merge changes.
- Preferred method for declarative configuration management.
Memory trick: Apply Always Adapts
Pod hostNetwork
Flip cardA Pod configuration that allows its containers to use the network namespace of the host node, effectively bypassing the Kubernetes network model.
- Pod shares host's network stack.
- Bypasses CNI plugin networking.
- Pod's ports are directly on the host's IP.
Memory trick: HostNetwork: Pod's network is the Host's network!
`kubectl cordon`
Flip cardA `kubectl` command used to mark a Kubernetes node as 'unschedulable', preventing the scheduler from placing new Pods on it while allowing existing Pods to continue running.
- Marks node unschedulable.
- New Pods won't be scheduled.
- Existing Pods are unaffected.
Memory trick: Cordon off the node, but don't kick out the current guests!
Kubernetes StatefulSet
Flip cardA Kubernetes workload API object used to manage stateful applications, providing stable network identities, ordered deployment/scaling, and persistent storage.
- Ensures stable, unique network identifiers for Pods (e.g., `web-0`, `web-1`).
- Guarantees ordered, graceful deployment and scaling.
- Often used with PersistentVolumes for stable storage.
Memory trick: StatefulSets give your Pods a 'stable state' and 'identity'.
kube-controller-manager
Flip cardA control plane component that runs various controller processes, continuously monitoring the cluster's actual state and attempting to move it towards the desired state.
- Runs multiple controllers.
- Monitors actual vs. desired state.
- Reconciles discrepancies (e.g., in Deployments, ReplicaSets).
Memory trick: Controllers manage the cluster's desired state!
Pod restartPolicy: OnFailure
Flip cardThe `OnFailure` restart policy specifies that a container will only be restarted if it exits with a non-zero exit code, indicating an error.
- Container is restarted if it fails.
- Container is NOT restarted if it succeeds (exit code 0).
- Commonly used for Jobs or other batch-like processes.
- Can be set at the Pod level.
Memory trick: Restart On Failure, but Never if it's Always successful.
Kubernetes `nfs` Volume
Flip cardA Kubernetes Volume type that allows an existing Network File System (NFS) share to be mounted into a Pod. It provides shared and persistent storage that can be accessed by multiple Pods, typically across different Nodes.
- Mounts an existing NFS share.
- Provides shared and persistent storage.
- Requires an NFS server to be available.
Memory trick: Host for Node, Empty for Ephemeral, NFS for Network, Config for Configs.
Pod `metadata.labels`
Flip cardA field within a Kubernetes Pod's `metadata` section that defines a set of key-value pairs. These labels are used by Services and other controllers to identify and select specific Pods.
- Used for identifying and grouping Kubernetes objects.
- Crucial for Service-to-Pod mapping via selectors.
- Part of `metadata` at the top level of the resource.
Memory trick: Metadata Makes Labels Link.
Container `command` field
Flip cardThe `command` field in a Kubernetes container specification allows users to override the default `ENTRYPOINT` defined in the Docker image.
- Overrides the Docker image's `ENTRYPOINT`.
- If `args` are also specified, they become the arguments to this `command`.
- Defined as a list of strings.
Memory trick: Command sets the 'C'ore 'C'ode to run.
Kubernetes Job
Flip cardA Kubernetes object that creates one or more Pods and ensures that a specified number of them successfully terminate, suitable for one-time or batch tasks.
- Runs Pods to completion.
- Designed for batch processing.
- Does not restart completed Pods by default.
Memory trick: Job's job is to run and finish!
`kubectl set image`
Flip cardA `kubectl` command used to update the image of a container in a Pod, Deployment, or other workload resource. It initiates a rolling update to apply the change.
- Used for updating container images.
- Triggers a rolling update for Deployments.
- Syntax: `kubectl set image <resource_type>/<name> <container_name>=<new_image>`.
Memory trick: Set Image for Smooth Sailing.
Role-Based Access Control (RBAC)
Flip cardA method of regulating access to Kubernetes API resources based on the roles of individual users and ServiceAccounts, defining permissions on specific resources.
- Controls access to Kubernetes API.
- Uses Roles/ClusterRoles and RoleBindings/ClusterRoleBindings.
- Applies to users and ServiceAccounts.
Memory trick: RBAC: Roles Bind Access Control!