>DevOps Interview KB

Kubernetes Interview Questions

128 questions

The most extensive topic on this site: RBAC and security context, storage (PV/PVC/StorageClass), workloads and controllers (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs), autoscaling (HPA/VPA), scheduling and affinity, networking, cluster architecture, CRDs and operators, admission control, and cluster security hardening. Every question is a realistic production scenario — a pod stuck Pending, a webhook silently breaking scheduling, a StatefulSet rollout behaving unexpectedly — not a bare definition.

A security scan flags the API server's anonymous authentication as enabled — what does that actually expose, and how would you harden it safely?

AdvancedKubernetes7 min

What does running kube-bench against a cluster actually check, and how would you prioritize the findings rather than trying to fix everything at once?

IntermediateKubernetes6 min

Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.

ExpertKubernetes8 min

How would you design a Kubernetes audit logging policy that's actually useful for a security investigation, without drowning in log volume?

AdvancedKubernetes7 min

How would you design a policy requiring every image deployed to a cluster be cryptographically signed, and what does that actually protect against?

ExpertKubernetes8 min

A security scan found the kubelet's API port reachable without authentication on some nodes — what can an attacker actually do with that, and how do you fix it?

ExpertKubernetes8 min

How would you design network-level segmentation between the control plane and worker nodes, beyond what Kubernetes' own RBAC and NetworkPolicy provide?

AdvancedKubernetes7 min

Enforcing readOnlyRootFilesystem across all pods breaks several applications that write temp files — how do you roll this out without breaking them?

IntermediateKubernetes6 min

You already enforce preventive admission policies (Kyverno/Gatekeeper) — why would you also need runtime security tooling like Falco?

AdvancedKubernetesFalco6 min

What does a seccomp profile actually add on top of SecurityContext's capability restrictions, and when do you need one?

AdvancedKubernetes6 min