Kubernetes Interview Questions — All Categories
169 questions tagged with Kubernetes as a technology, across every category it appears in
Related categories:Argo CDAWSAzureCI/CDCloud ArchitectureContainersDockerGitOpsHelmJenkinsKubernetesLinuxNetworkingSystem DesignYAML
How would you design network-level segmentation between the control plane and worker nodes, beyond what Kubernetes' own RBAC and NetworkPolicy provide?
AdvancedKubernetes7 min
Enforcing readOnlyRootFilesystem across all pods breaks several applications that write temp files — how do you roll this out without breaking them?
IntermediateKubernetes6 min
You already enforce preventive admission policies (Kyverno/Gatekeeper) — why would you also need runtime security tooling like Falco?
AdvancedKubernetesFalco6 min
What does a seccomp profile actually add on top of SecurityContext's capability restrictions, and when do you need one?
AdvancedKubernetes6 min
How would you audit which pods across a cluster consume a specific Secret, before rotating it, to know what needs restarting?
IntermediateKubernetes6 min
How would you design a workflow so a ConfigMap change automatically triggers a rolling restart of the Deployments that depend on it?
AdvancedKubernetes7 min
A pod doesn't pick up a ConfigMap change after it's updated — why, and how would you make the app actually reload it?
IntermediateKubernetes6 min
A ConfigMap has grown to hold a large multi-file config bundle — what's the practical size limit, and what would you do instead if you hit it?
IntermediateKubernetes5 min
What's the difference between envFrom and individually listing env entries sourced from a ConfigMap/Secret, and when does it matter?
BeginnerKubernetes5 min
How would you manage Secrets across dev/staging/prod without committing plaintext to Git, while staying GitOps-declarative?
AdvancedKubernetes8 min
A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?
AdvancedKubernetes7 min
An app reads an env var from a Secret, but after rotating the Secret's value, the running pod still uses the old one — why?
IntermediateKubernetes5 min
What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?
IntermediateKubernetes6 min
Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?
BeginnerKubernetes5 min
Why should a CRD's status be a separate subresource from spec, and what belongs in status versus spec?
IntermediateKubernetes6 min
A custom resource is stuck in Terminating status indefinitely after being deleted — what's a finalizer, and how does it cause this?
AdvancedKubernetes7 min
How does an operator's reconciliation loop actually work, and why is it designed to be idempotent and level-triggered rather than event-driven?
IntermediateKubernetes6 min
Custom resources are being created and updated, but the operator managing them appears to have silently stopped reconciling — how do you diagnose it?
AdvancedKubernetes8 min
For distributing a complex application, when would you package it as a Helm chart versus building a dedicated operator for it?
AdvancedKubernetesHelm7 min
A custom resource is deleted, but the Deployments and Services an operator created for it are left orphaned in the cluster — why doesn't Kubernetes clean them up automatically?
IntermediateKubernetes6 min
How would you test a custom operator's reconcile logic without needing a full live cluster for every test run?
AdvancedKubernetes7 min
A CRD needs a breaking schema change, but existing custom resources and consumers depend on the old shape — how do you version a CRD safely?
ExpertKubernetes8 min
What's actually different about a CustomResourceDefinition versus a built-in Kubernetes resource like a Deployment?
BeginnerKubernetes5 min
A team wants to automate a repetitive operational task with a custom Kubernetes operator — when is that actually the right tool versus overkill?
AdvancedKubernetes7 min