>DevOps Interview KB

Kubernetes Interview Questions

128 questions

The most extensive topic on this site: RBAC and security context, storage (PV/PVC/StorageClass), workloads and controllers (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs), autoscaling (HPA/VPA), scheduling and affinity, networking, cluster architecture, CRDs and operators, admission control, and cluster security hardening. Every question is a realistic production scenario — a pod stuck Pending, a webhook silently breaking scheduling, a StatefulSet rollout behaving unexpectedly — not a bare definition.

Why might an HPA be unable to scale a Deployment even with plenty of spare CPU capacity on existing nodes?

IntermediateKubernetes6 min

An HPA scales up rapidly during a spike, then flaps up and down repeatedly for the next hour — what's causing it, and how do you fix it?

AdvancedKubernetes7 min

Users report increasing latency under load, but the HPA isn't scaling the Deployment at all — how do you figure out why?

AdvancedKubernetes8 min

Why does setting only limits (no requests) on a container break HPA's CPU-based scaling calculation?

BeginnerKubernetes5 min

A workload is constantly OOMKilled despite having an HPA configured — why doesn't horizontal scaling fix this, and what should you actually do?

IntermediateKubernetes6 min

A Deployment's pods get evicted during scale-up because new nodes take too long to become ready — how would you close that gap?

ExpertKubernetes8 min

How would you design autoscaling for a workload with a sharp, predictable daily spike versus one with genuinely unpredictable bursty traffic?

AdvancedKubernetes7 min

A security scan flags the API server's anonymous authentication as enabled — what does that actually expose, and how would you harden it safely?

AdvancedKubernetes7 min

What does running kube-bench against a cluster actually check, and how would you prioritize the findings rather than trying to fix everything at once?

IntermediateKubernetes6 min

Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.

ExpertKubernetes8 min

How would you design a Kubernetes audit logging policy that's actually useful for a security investigation, without drowning in log volume?

AdvancedKubernetes7 min

How would you design a policy requiring every image deployed to a cluster be cryptographically signed, and what does that actually protect against?

ExpertKubernetes8 min

A security scan found the kubelet's API port reachable without authentication on some nodes — what can an attacker actually do with that, and how do you fix it?

ExpertKubernetes8 min

How would you design network-level segmentation between the control plane and worker nodes, beyond what Kubernetes' own RBAC and NetworkPolicy provide?

AdvancedKubernetes7 min

Enforcing readOnlyRootFilesystem across all pods breaks several applications that write temp files — how do you roll this out without breaking them?

IntermediateKubernetes6 min

You already enforce preventive admission policies (Kyverno/Gatekeeper) — why would you also need runtime security tooling like Falco?

AdvancedKubernetesFalco6 min

What does a seccomp profile actually add on top of SecurityContext's capability restrictions, and when do you need one?

AdvancedKubernetes6 min

How would you audit which pods across a cluster consume a specific Secret, before rotating it, to know what needs restarting?

IntermediateKubernetes6 min

How would you design a workflow so a ConfigMap change automatically triggers a rolling restart of the Deployments that depend on it?

AdvancedKubernetes7 min

A pod doesn't pick up a ConfigMap change after it's updated — why, and how would you make the app actually reload it?

IntermediateKubernetes6 min

A ConfigMap has grown to hold a large multi-file config bundle — what's the practical size limit, and what would you do instead if you hit it?

IntermediateKubernetes5 min

What's the difference between envFrom and individually listing env entries sourced from a ConfigMap/Secret, and when does it matter?

BeginnerKubernetes5 min

How would you manage Secrets across dev/staging/prod without committing plaintext to Git, while staying GitOps-declarative?

AdvancedKubernetes8 min

A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?

AdvancedKubernetes7 min