>DevOps Interview KB

Kubernetes Interview Questions — All Categories

169 questions tagged with Kubernetes as a technology, across every category it appears in

How would you design network-level segmentation between the control plane and worker nodes, beyond what Kubernetes' own RBAC and NetworkPolicy provide?

AdvancedKubernetes7 min

Enforcing readOnlyRootFilesystem across all pods breaks several applications that write temp files — how do you roll this out without breaking them?

IntermediateKubernetes6 min

You already enforce preventive admission policies (Kyverno/Gatekeeper) — why would you also need runtime security tooling like Falco?

AdvancedKubernetesFalco6 min

What does a seccomp profile actually add on top of SecurityContext's capability restrictions, and when do you need one?

AdvancedKubernetes6 min

How would you audit which pods across a cluster consume a specific Secret, before rotating it, to know what needs restarting?

IntermediateKubernetes6 min

How would you design a workflow so a ConfigMap change automatically triggers a rolling restart of the Deployments that depend on it?

AdvancedKubernetes7 min

A pod doesn't pick up a ConfigMap change after it's updated — why, and how would you make the app actually reload it?

IntermediateKubernetes6 min

A ConfigMap has grown to hold a large multi-file config bundle — what's the practical size limit, and what would you do instead if you hit it?

IntermediateKubernetes5 min

What's the difference between envFrom and individually listing env entries sourced from a ConfigMap/Secret, and when does it matter?

BeginnerKubernetes5 min

How would you manage Secrets across dev/staging/prod without committing plaintext to Git, while staying GitOps-declarative?

AdvancedKubernetes8 min

A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?

AdvancedKubernetes7 min

An app reads an env var from a Secret, but after rotating the Secret's value, the running pod still uses the old one — why?

IntermediateKubernetes5 min

What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?

IntermediateKubernetes6 min

Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?

BeginnerKubernetes5 min

Why should a CRD's status be a separate subresource from spec, and what belongs in status versus spec?

IntermediateKubernetes6 min

A custom resource is stuck in Terminating status indefinitely after being deleted — what's a finalizer, and how does it cause this?

AdvancedKubernetes7 min

How does an operator's reconciliation loop actually work, and why is it designed to be idempotent and level-triggered rather than event-driven?

IntermediateKubernetes6 min

Custom resources are being created and updated, but the operator managing them appears to have silently stopped reconciling — how do you diagnose it?

AdvancedKubernetes8 min

For distributing a complex application, when would you package it as a Helm chart versus building a dedicated operator for it?

AdvancedKubernetesHelm7 min

A custom resource is deleted, but the Deployments and Services an operator created for it are left orphaned in the cluster — why doesn't Kubernetes clean them up automatically?

IntermediateKubernetes6 min

How would you test a custom operator's reconcile logic without needing a full live cluster for every test run?

AdvancedKubernetes7 min

A CRD needs a breaking schema change, but existing custom resources and consumers depend on the old shape — how do you version a CRD safely?

ExpertKubernetes8 min

What's actually different about a CustomResourceDefinition versus a built-in Kubernetes resource like a Deployment?

BeginnerKubernetes5 min

A team wants to automate a repetitive operational task with a custom Kubernetes operator — when is that actually the right tool versus overkill?

AdvancedKubernetes7 min