>DevOps Interview KB

Kubernetes Interview Questions

128 questions

The most extensive topic on this site: RBAC and security context, storage (PV/PVC/StorageClass), workloads and controllers (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs), autoscaling (HPA/VPA), scheduling and affinity, networking, cluster architecture, CRDs and operators, admission control, and cluster security hardening. Every question is a realistic production scenario — a pod stuck Pending, a webhook silently breaking scheduling, a StatefulSet rollout behaving unexpectedly — not a bare definition.

How would you audit which pods across a cluster consume a specific Secret, before rotating it, to know what needs restarting?

IntermediateKubernetes6 min

How would you design a workflow so a ConfigMap change automatically triggers a rolling restart of the Deployments that depend on it?

AdvancedKubernetes7 min

A pod doesn't pick up a ConfigMap change after it's updated — why, and how would you make the app actually reload it?

IntermediateKubernetes6 min

A ConfigMap has grown to hold a large multi-file config bundle — what's the practical size limit, and what would you do instead if you hit it?

IntermediateKubernetes5 min

What's the difference between envFrom and individually listing env entries sourced from a ConfigMap/Secret, and when does it matter?

BeginnerKubernetes5 min

How would you manage Secrets across dev/staging/prod without committing plaintext to Git, while staying GitOps-declarative?

AdvancedKubernetes8 min

A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?

AdvancedKubernetes7 min

An app reads an env var from a Secret, but after rotating the Secret's value, the running pod still uses the old one — why?

IntermediateKubernetes5 min

What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?

IntermediateKubernetes6 min

Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?

BeginnerKubernetes5 min