>DevOps Interview KB

Kubernetes Interview Questions

128 questions

The most extensive topic on this site: RBAC and security context, storage (PV/PVC/StorageClass), workloads and controllers (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs), autoscaling (HPA/VPA), scheduling and affinity, networking, cluster architecture, CRDs and operators, admission control, and cluster security hardening. Every question is a realistic production scenario — a pod stuck Pending, a webhook silently breaking scheduling, a StatefulSet rollout behaving unexpectedly — not a bare definition.

Kubernetes has built-in admission controllers compiled into the API server, separate from webhook-based ones — what's the actual difference and when does it matter?

IntermediateKubernetes5 min

How would you design and roll out a policy blocking :latest image tags cluster-wide, without breaking every existing deployment on day one?

IntermediateKubernetes7 min

How do OPA Gatekeeper and Kyverno actually differ as policy engines for Kubernetes admission control, and which would you choose?

IntermediateKubernetesOpaKyverno6 min

What's the difference between a validating and a mutating admission webhook, and in what order do they actually run?

IntermediateKubernetes6 min

For enforcing a new policy, when does it belong in a cluster admission webhook versus a CI-time check before deployment even happens?

IntermediateKubernetes6 min

What's the difference between kube-apiserver, kube-scheduler, and kube-controller-manager, and what breaks if each is unavailable?

IntermediateKubernetes6 min

How would you design a highly-available control plane, and what breaks with only one control-plane node?

IntermediateKubernetes7 min

How does etcd's quorum requirement affect control-plane node count, and why is an even number a bad choice?

IntermediateKubernetesEtcd6 min

How would you safely drain and remove a node without disrupting running workloads?

IntermediateKubernetes6 min

What's the difference between a static pod and a normal pod, and why does the control plane often run as static pods?

IntermediateKubernetes5 min

What's the difference between HPA scaling on CPU utilization versus a custom metric like queue depth, and when is CPU actually the wrong signal?

IntermediateKubernetes6 min

How does HPA's scaling decision actually get computed from raw metrics — walk through what happens between a CPU spike and a new replica appearing?

IntermediateKubernetes6 min

Why might an HPA be unable to scale a Deployment even with plenty of spare CPU capacity on existing nodes?

IntermediateKubernetes6 min

A workload is constantly OOMKilled despite having an HPA configured — why doesn't horizontal scaling fix this, and what should you actually do?

IntermediateKubernetes6 min

What does running kube-bench against a cluster actually check, and how would you prioritize the findings rather than trying to fix everything at once?

IntermediateKubernetes6 min

Enforcing readOnlyRootFilesystem across all pods breaks several applications that write temp files — how do you roll this out without breaking them?

IntermediateKubernetes6 min

How would you audit which pods across a cluster consume a specific Secret, before rotating it, to know what needs restarting?

IntermediateKubernetes6 min

A pod doesn't pick up a ConfigMap change after it's updated — why, and how would you make the app actually reload it?

IntermediateKubernetes6 min

A ConfigMap has grown to hold a large multi-file config bundle — what's the practical size limit, and what would you do instead if you hit it?

IntermediateKubernetes5 min

An app reads an env var from a Secret, but after rotating the Secret's value, the running pod still uses the old one — why?

IntermediateKubernetes5 min

What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?

IntermediateKubernetes6 min

Why should a CRD's status be a separate subresource from spec, and what belongs in status versus spec?

IntermediateKubernetes6 min

How does an operator's reconciliation loop actually work, and why is it designed to be idempotent and level-triggered rather than event-driven?

IntermediateKubernetes6 min

A custom resource is deleted, but the Deployments and Services an operator created for it are left orphaned in the cluster — why doesn't Kubernetes clean them up automatically?

IntermediateKubernetes6 min