Kubernetes Interview Questions
128 questions
The most extensive topic on this site: RBAC and security context, storage (PV/PVC/StorageClass), workloads and controllers (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs), autoscaling (HPA/VPA), scheduling and affinity, networking, cluster architecture, CRDs and operators, admission control, and cluster security hardening. Every question is a realistic production scenario — a pod stuck Pending, a webhook silently breaking scheduling, a StatefulSet rollout behaving unexpectedly — not a bare definition.
An app reads an env var from a Secret, but after rotating the Secret's value, the running pod still uses the old one — why?
IntermediateKubernetes5 min
What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?
IntermediateKubernetes6 min
Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?
BeginnerKubernetes5 min
Why should a CRD's status be a separate subresource from spec, and what belongs in status versus spec?
IntermediateKubernetes6 min
A custom resource is stuck in Terminating status indefinitely after being deleted — what's a finalizer, and how does it cause this?
AdvancedKubernetes7 min
How does an operator's reconciliation loop actually work, and why is it designed to be idempotent and level-triggered rather than event-driven?
IntermediateKubernetes6 min
Custom resources are being created and updated, but the operator managing them appears to have silently stopped reconciling — how do you diagnose it?
AdvancedKubernetes8 min
For distributing a complex application, when would you package it as a Helm chart versus building a dedicated operator for it?
AdvancedKubernetesHelm7 min
A custom resource is deleted, but the Deployments and Services an operator created for it are left orphaned in the cluster — why doesn't Kubernetes clean them up automatically?
IntermediateKubernetes6 min
How would you test a custom operator's reconcile logic without needing a full live cluster for every test run?
AdvancedKubernetes7 min
A CRD needs a breaking schema change, but existing custom resources and consumers depend on the old shape — how do you version a CRD safely?
ExpertKubernetes8 min
What's actually different about a CustomResourceDefinition versus a built-in Kubernetes resource like a Deployment?
BeginnerKubernetes5 min
A team wants to automate a repetitive operational task with a custom Kubernetes operator — when is that actually the right tool versus overkill?
AdvancedKubernetes7 min
What's the actual difference between a Pod and a Deployment in Kubernetes, and why would you almost never create a bare Pod directly in production?
BeginnerKubernetes6 min
How does a Service-not-routing-traffic failure mode differ between a plain ClusterIP Service and one fronted by an Ingress controller?
IntermediateKubernetes7 min
How would you troubleshoot connectivity that works within a node but fails between pods on different nodes?
AdvancedKubernetes8 min
How would you design NetworkPolicies for a namespace using default-deny-all while still allowing necessary traffic?
IntermediateKubernetes7 min
What's the difference between Kubernetes Endpoints and EndpointSlices, and why did Kubernetes introduce EndpointSlices?
IntermediateKubernetes6 min
A headless Service behaves completely differently for DNS resolution — what's different, and when do you need it?
IntermediateKubernetes6 min
What's the difference between the older Ingress resource and the newer Gateway API, and when would you actually migrate?
IntermediateKubernetes6 min
A pod resolves a Service's DNS name intermittently but not consistently — how do you investigate CoreDNS itself?
AdvancedKubernetes8 min
How would you migrate a cluster from one CNI plugin to another without a full cluster rebuild — what's actually risky about it?
ExpertKubernetes8 min
What does a pod's ndots DNS setting default to, and how can it cause unexpectedly slow external DNS lookups?
AdvancedKubernetes7 min
A NetworkPolicy is applied but pods that should be blocked can still communicate — why might it not be enforced?
AdvancedKubernetes7 min