Kubernetes and Cloud Native Associate (KCNA) flashcards
136 free flashcards. Tap a card to flip it.
`kubectl set image`
Flip cardA `kubectl` command used to update the image of a container in a Pod, Deployment, or other workload resource. It initiates a rolling update to apply the change.
- Used for updating container images.
- Triggers a rolling update for Deployments.
- Syntax: `kubectl set image <resource_type>/<name> <container_name>=<new_image>`.
Memory trick: Set Image for Smooth Sailing.
Role-Based Access Control (RBAC)
Flip cardA method of regulating access to Kubernetes API resources based on the roles of individual users and ServiceAccounts, defining permissions on specific resources.
- Controls access to Kubernetes API.
- Uses Roles/ClusterRoles and RoleBindings/ClusterRoleBindings.
- Applies to users and ServiceAccounts.
Memory trick: RBAC: Roles Bind Access Control!
Kubernetes ClusterIP Service
Flip cardA Kubernetes Service type that exposes the Service on an internal IP address within the cluster. It is only reachable from within the cluster and provides a stable internal DNS name for communication.
- Default Service type.
- Provides a stable internal IP and DNS name.
- Not exposed to external traffic.
Memory trick: Cluster for internal, Node for node-level, LoadBalancer for cloud, External for external.
Kubernetes Node Affinity
Flip cardA set of rules used by the Kubernetes scheduler to determine which nodes a Pod can be scheduled on, based on node labels.
- Can be 'required' (must match) or 'preferred' (try to match).
- Uses `nodeSelectorTerms` and `matchExpressions` to specify label requirements.
- Complements `nodeSelector` for more flexible scheduling.
Memory trick: Node Affinity 'attracts' Pods to specific node types, like a magnet.
`kubectl version`
Flip cardThe `kubectl version` command is used to display the version of the Kubernetes client (`kubectl`) and the Kubernetes server components.
- Shows client (kubectl) version.
- Shows server (kube-apiserver, kubelet, etc.) versions.
- Useful for debugging compatibility issues.
Memory trick: To know the 'Version', just ask for 'Version'.
`kubectl describe`
Flip cardA `kubectl` command used to show detailed information about a specific Kubernetes resource, including its current state, events, and related objects.
- Provides a comprehensive overview.
- Includes events, labels, selectors, and status.
- Useful for debugging and understanding resource configurations.
Memory trick: Get for General, Describe for Details, Logs for Living history, Exec for Entry.
Pod restartPolicy
Flip cardThe `restartPolicy` field in a Pod's specification defines how Kubernetes handles container restarts after they terminate.
- Can be 'Always', 'OnFailure', or 'Never'.
- Defaults to 'Always' for Deployments and DaemonSets.
- Defaults to 'OnFailure' for Jobs.
- Applies to all containers in the Pod.
Memory trick: Always Restart, On Failure, or Never - it's a Policy!
kubectl cordon
Flip cardA `kubectl` command that marks a Kubernetes node as 'unschedulable', preventing new Pods from being placed on it.
- Existing Pods on the node continue to run.
- Used as a preliminary step for node maintenance.
- Can be reversed with `kubectl uncordon`.
Memory trick: Cordon off the node, no new friends allowed!
`kubectl apply`
Flip cardA `kubectl` command used to create or update Kubernetes resources from a file (e.g., YAML). It is idempotent and performs declarative updates, comparing the desired state in the file with the current state in the cluster.
- Recommended for declarative management.
- Creates resources if they don't exist, updates if they do.
- Idempotent, safe to run multiple times.
Memory trick: Apply for All changes, Create for New, Run for Quick Pods, Patch for Precise edits.
Pod `restartPolicy`
Flip cardA field in a Pod's specification that defines the restart behavior for all containers within the Pod.
- Can be 'Always', 'OnFailure', or 'Never'.
- 'Always' is the default for Deployments, ReplicaSets, etc.
- 'OnFailure' is common for Jobs to retry failed tasks.
- 'Never' is used for one-off tasks that should not restart.
Memory trick: Restart policy dictates the container's 'second chance'.
Pod 'Pending' State
Flip cardA Pod in the 'Pending' state means it has been accepted by the Kubernetes cluster but one or more of its containers has not been created or started yet. This often indicates a scheduling issue.
- Common causes: insufficient resources (CPU/memory) on nodes.
- Also caused by unbound PVCs, node selectors/affinity not matching.
- Use `kubectl describe pod <pod-name>` to get scheduler events and reasons.
Memory trick: Pending Pods Ponder Placement Problems
ImagePullBackOff
Flip cardAn 'ImagePullBackOff' status in Kubernetes indicates that a container image specified in a Pod's manifest could not be pulled from the container registry.
- Common causes: incorrect image name/tag, private registry access issues, registry down.
- Node repeatedly tries to pull the image.
- Check `kubectl describe pod <pod-name>` for more details on the pull error.
Memory trick: Pulling Problems Prevent Pods from Proceeding
Container `command` and `args`
Flip cardFields in a Kubernetes container specification that define the entrypoint and arguments for the container, overriding image defaults.
- `command` overrides the `ENTRYPOINT` in the Dockerfile.
- `args` overrides the `CMD` in the Dockerfile (if `command` is also specified, `args` becomes arguments to `command`).
- Used for customizing container execution behavior.
Memory trick: Command and Args are like giving direct instructions to your container.
HorizontalPodAutoscaler (HPA)
Flip cardA Kubernetes API resource that automatically scales the number of Pod replicas in a Deployment or ReplicaSet based on observed CPU utilization or other select metrics.
- Automatically adjusts Pod count.
- Targets Deployments or ReplicaSets.
- Uses CPU utilization or custom metrics.
Memory trick: HPA: 'How Pods Auto-scale'
kubectl version
Flip cardA `kubectl` command used to display the version information of both the `kubectl` client and the Kubernetes API server.
- Shows client and server versions.
- Includes Git commit and build date.
- Essential for compatibility checks and troubleshooting.
Memory trick: To know the versions, just ask for the 'version'!
Kubernetes DaemonSet
Flip cardA Kubernetes object that ensures a copy of a specific Pod runs on all (or some) nodes in a cluster, typically used for cluster-level services like log collection or monitoring agents.
- One Pod instance per node (or selected nodes).
- Ideal for node-level agents.
- Ensures continuous presence on nodes.
Memory trick: DaemonSet: Demons on every node!