Before EKS, before Kubernetes, before orchestration β there are containers. The course frames their value through five Twelve-Factor-style properties: portable, cloud deployable, scalable, continuously deployable, and declarative. Each property is what makes containers a good substrate for microservices.
Animation Β· Scale out and scale in
What does it mean that containers are portable?
Containers run on any OS that supports the containerization platform. You can also run multiple versions of the same app, each with its own dependencies, side-by-side. Analogy: shipping containers ride on trucks, trains and ships unchanged.
What makes containers cloud deployable?
Containers are lightweight and self-contained, so they fit naturally into managed cloud platforms. On AWS that means Amazon EC2, AWS Lambda, Amazon ECS, Amazon EKS, and AWS App Runner β each runs containerized apps with a different operational model.
What does scalable mean for containers?
Because containers are small and start fast, you can scale out by adding more copies and scale in by removing them β without changing your build tools, architecture, or development workflow. Scaling is just "add another instance," not "rebuild the app."
Why are containers good for continuous deployment?
A container image is identical in dev, QA, and prod β only the host OS and infrastructure change. That minimises divergence between environments and integrates cleanly with automated build β test β deploy pipelines.
What is a declarative format?
You describe the result you want, not the steps to produce it. Drawing a rectangle imperatively means drawLineΓ4; declaratively it's { shape: "rect", w: 300, h: 100 }. Kubernetes manifests are declarative β you say "I want 4 replicas" and let the controller reconcile.
TOPIC 2 Microservices & container orchestration
The five properties above make containers a natural fit for microservices: each service ships independently, scales independently, and uses only what it needs. But once you have tens or hundreds of containers across many hosts, you need orchestration β automated scheduling, networking, scaling, health, and recovery.
Monolith vs microservices β what's the structural difference?
A monolith is one program that does everything: UI, business logic, data. Each app duplicates shared concerns (order history, mailing). A microservice architecture splits the app into many small, independently-deployable services β e.g., one ordering service, one reporting service β each owning its own concerns.
Why are containers a good fit for microservices?
Microservices need to be independently deployable, independently scalable, and portable across environments. Those are exactly the properties containers give you out of the box.
When do containers stop being simple to manage?
Running 1β2 containers on one host is trivial. Once you move to dozens of hosts and hundreds of containers β let alone production with thousands β you can no longer place, monitor, or restart them manually. That's the problem orchestration solves.
What does a container orchestration tool automate?
Scheduling & placement Β· cloud integration Β· networking Β· load balancing Β· storage Β· security Β· monitoring Β· logging. You declare desired state; the orchestrator makes the cluster match it.
What does Kubernetes add on top of containers?
All the orchestration concerns β scheduling, scaling, load balancing, deployments β plus a strong community and a declarative API. Kubernetes is the substrate; EKS is the AWS-managed flavour.
TOPIC 3 Pods & Services
Pods are Kubernetes' smallest deployable unit β a group of one or more containers that share the same IP and storage. Pods are ephemeral (their IPs change), so apps don't talk to Pods directly β they talk to Services, which give a stable address that routes to whichever Pods are currently alive.
Animation Β· Pods communicate through a Service
What is a Pod?
A group of one or more containers that share the same network namespace (IP, port space) and can share storage. The smallest deployable unit in Kubernetes β and the basic building block for deployment, scaling and replication.
What's a PodSpec?
The YAML specification that describes how to run the containers in a Pod β image, ports, env, volumes. Stored declaratively and submitted to the API server.
How do containers inside the same Pod talk to each other?
They share a network namespace, so they can talk via localhost and shared volumes. They're co-scheduled to the same node and live and die together.
How do containers in different Pods talk to each other?
Each Pod gets its own cluster IP. Pods can hit each other directly by IP β but those IPs change when Pods restart, so you almost always go through a Service instead.
What is a Kubernetes Service?
A logical collection of Pods plus a stable way to reach them. The Service has its own IP and port; it's continuously updated with the set of Pod IPs that currently match its selector, so callers never need to track individual Pods.
Why can't apps just call Pods by IP?
Pod IPs are ephemeral. A Pod crashes β it gets recreated with a new IP. A Service IP is stable and load-balances across whichever Pods currently match its label selector.
What's a node? How does it relate to a Pod?
A node is a machine (VM or physical) that runs Pods. A Kubernetes cluster is the set of nodes. Pods are always scheduled to exactly one node β containers within a Pod cannot be split across nodes.
How do nodes relate to Availability Zones?
In EKS, nodes live in AWS subnets, which live in specific AZs (e.g., us-east-1a, us-east-1b). Spreading nodes across multiple AZs is how you survive an AZ failure. The scheduler can place Pods AZ-aware via topology spread & affinity rules.
TOPIC 4 Cluster anatomy β control plane & data plane
A Kubernetes cluster splits into two roles. The control plane makes global decisions (what should run, where, when). The data plane actually runs your containers. They talk via the API server, and every controller is a tiny loop comparing current state to desired state.
Animation Β· The controller control loop
Animation Β· Control plane & data plane working together
What is the control plane?
The set of components that manage the cluster: schedule Pods, detect failures, react to events. Components: API server, etcd, scheduler, controller manager, cloud controller.
What is the data plane?
The set of worker nodes that actually run your containerized applications. Each node runs a container runtime, kubelet, and kube-proxy.
What is a controller?
A loop that compares desired state (from your manifests) to current state (what's actually running). If they differ, the controller acts to make them match. If they match, it does nothing.
What does the API server do?
It's the front door of the cluster. Everything β kubectl, kubelet, controllers β talks to the API server. It validates and persists cluster state to etcd, and is the only component that reads/writes etcd.
What is etcd?
A consistent, distributed key-value store. It holds the entire cluster state β every Pod spec, every config, every secret. Lose etcd and you lose the cluster's memory.
What does the scheduler do?
When a new Pod is created without a node assignment, the scheduler picks one. It uses predicates to filter ineligible nodes and priorities to score the survivors. The highest-scoring node wins.
What does the controller manager do?
It runs many built-in controllers in one process β Deployment controller, ReplicaSet controller, Node controller, Endpoint controller, Job controller, and others. Each runs its own control loop.
What does the cloud controller do?
A controller that integrates with the underlying cloud provider: it manages cloud-specific resources like load balancers, routes, and volumes (on AWS: ELB, EBS attachments, route tables) on behalf of the cluster.
What is the kubelet?
The primary node agent. It watches the API server for Pods assigned to its node, then asks the container runtime to start them. It also reports node and Pod health back to the control plane.
What is kube-proxy?
A small per-node process that programs networking rules (iptables / IPVS) so that traffic to a Service IP gets routed to one of its backing Pods. Without it, Services wouldn't actually route traffic.
What is the container runtime?
The software that actually starts, stops, and isolates containers on a node. Kubernetes supports several via the CRI interface; EKS uses containerd by default since Kubernetes v1.24 (Docker Engine is deprecated).
How does the control plane talk to the data plane?
Through the API server. The kubelet on each node watches the API server for Pods assigned to its node. There is no direct controllerβkubelet channel β everything is mediated by the API server, which is the cluster's single source of truth.
TOPIC 5 Pod scheduling β predicates & priorities
Scheduling is a two-phase process. Predicates are filters that exclude nodes a Pod cannot run on (not enough CPU, wrong AZ, missing volume). Priorities are scores that rank the surviving nodes (most free capacity, best topology spread). The highest-scoring node wins.
Animation Β· Taints and tolerations β scheduling repulsion
Predicates vs priorities β what's the difference?
Predicates are filters: "can this Pod possibly run here?" If no, the node is excluded. Priorities are scores: "of the survivors, which is the best home?" Highest score wins.
What is a requests setting on a container?
The minimum guaranteed CPU and memory a container will get. The scheduler uses requests to pick a node with enough free capacity. Example: cpu: 400m, memory: 600Mi.
What is a limits setting on a container?
The maximum a container is allowed to use. CPU above the limit is throttled; memory above the limit gets the container OOMKilled. Limits are enforced at runtime; requests influence scheduling.
What is a taint?
A property of a node that repels Pods. Only Pods that explicitly tolerate the taint can be scheduled there. Example taint: spot=true:NoSchedule means "don't schedule unless you tolerate spot instances."
What is a toleration?
A property of a Pod that lets it ignore matching taints. Tolerations don't force placement β they only permit it. Pairs with affinity to actually attract.
What is node affinity?
A Pod rule that attracts the Pod to nodes matching labels. requiredDuringSchedulingβ¦ is a hard filter (no match β no schedule). preferredDuringSchedulingβ¦ is a soft score (boost matching nodes but don't require them).
How is a volume requirement a predicate?
An EBS volume in us-east-1a can't attach to a node in us-east-1b. So the volume binding effectively constrains which nodes are even eligible for the Pod. Similarly, a Pod needing a volume already mounted on node X must go to node X.
When you combine taints/tolerations with affinity β what do you get?
Dedicated nodes. Taint a node so generic workloads avoid it; add a matching toleration + affinity to specific Pods so only they land there. Classic use: GPU nodes, spot pools, system add-ons.
TOPIC 6 kubectl β the CLI
kubectl is just an HTTP client for the API server. Every command becomes an HTTP request the API server validates against RBAC. The same tool can talk to any cluster β you select which one via a kubeconfig context.
What is kubectl?
The command-line interface for communicating with the Kubernetes API server. It runs on your laptop, your CI agent, anywhere β it just needs network access to a cluster and a kubeconfig.
How does kubectl know which cluster to talk to?
Through a kubeconfig file, by default at ~/.kube/config. Override the path with the KUBECONFIG env var. Within a file, multiple contexts let you switch clusters with kubectl config use-context.
What does kubectl get pods do?
Lists Pods in the current namespace (default: default). Add -n my-ns to target a different namespace, or -A to see Pods across all namespaces.
What does kubectl apply -f file.yaml do?
Sends the manifest to the API server, which creates or updates the matching object to match the file. Idempotent: running it twice is safe; controllers reconcile to the new desired state.
How do you create a namespace from the CLI?
kubectl create namespace my-ns Imperative shortcut. The declarative equivalent is a one-line YAML manifest applied with kubectl apply.
If you deploy into my-ns but run kubectl get pods, what happens?
You'll see "No resources found in default namespace" β because get pods defaults to default. Run kubectl get pods -n my-ns instead, or set the context's namespace.
A Kubernetes object is a record of intent in etcd. The cluster works continuously to make reality match those records. The most basic objects beyond Pods are Namespaces (logical isolation), ConfigMaps (non-secret config), and Secrets (sensitive data).
What is a Namespace?
A virtual cluster inside a physical cluster. Names must be unique within a namespace, but the same name can exist in different namespaces. Combined with RBAC, namespaces give multi-tenant isolation.
When are Namespaces especially useful?
When multiple teams or projects share a cluster. Each team gets its own namespace; RBAC controls who can read/write it. Resource quotas can also be applied per namespace.
What is a ConfigMap?
An API object storing non-confidential configuration as key-value pairs. Pods mount it as files or read it as env vars. Lets the same container image run in dev and prod with different config.
What is a Secret?
Same shape as a ConfigMap but for sensitive data (passwords, tokens, keys). Values are stored base64-encoded in the data field β note that base64 is encoding, not encryption. At-rest encryption requires enabling etcd encryption.
Why separate config from the container image?
So the same image runs unchanged from dev to prod. The image is the artifact; ConfigMaps and Secrets are the environment-specific overlay. This is the Twelve-Factor "config in the environment" principle.
How does a Pod consume a ConfigMap?
Two common ways: (1) mounted as files in a read-only volume (each key becomes a file); (2) injected as environment variables via envFrom.configMapRef. The Pod's container code reads them like any other file or env var.
What is a Custom Resource (CR)?
A user-defined object type, declared via a Custom Resource Definition (CRD). Extends the Kubernetes API. With a custom controller watching it, you get the same reconcile-loop pattern for your own domain β e.g., a Database CR that provisions RDS.
TOPIC 8 Workloads β the higher-level Pod managers
You rarely create bare Pods. Instead you create a workload β Deployment, StatefulSet, DaemonSet, Job, CronJob β and let its controller create and manage Pods for you. Each workload type encodes a different lifecycle pattern.
Animation Β· Deployment rolling update (Deployment β ReplicaSet β Pods)
Why use a workload instead of a bare Pod?
A bare Pod that dies stays dead. A workload controller re-creates Pods to match the desired count or schedule. Workloads also add features bare Pods don't have β rolling updates, fixed identity, scheduled execution.
What is a Job?
A workload that runs a Pod once to completion. Good for batch tasks (DB migration, one-shot data processing). The Job tracks success/failure and will retry failed Pods up to a limit.
What is a CronJob?
A workload that creates Jobs on a schedule, using cron syntax (*/1 * * * * = every minute). It's just a Job factory β each scheduled tick produces a fresh Job which produces a Pod.
What is a DaemonSet?
A workload that runs one Pod on every node (or every matching node). Used for node-level agents: log collector (Fluent Bit), metrics agent, CSI node plugin, kube-proxy itself. Not supported on AWS Fargate (Fargate has no notion of a shared node).
What is a ReplicaSet?
A workload that keeps a specific number of Pod replicas running. If a Pod dies, the ReplicaSet creates a new one. You rarely manage ReplicaSets directly β Deployments do it for you.
What is a Deployment?
A workload that owns and manages ReplicaSets. You declare a desired state β image version, replica count β and the Deployment controller rolls out changes at a controlled rate. The standard way to run stateless apps.
How does a Deployment perform a rolling update?
When you change the Pod template, the Deployment creates a new ReplicaSet for the new version. It scales the new RS up and the old RS down in lockstep, respecting maxSurge and maxUnavailable β never both at once. Old RS sticks around for rollback.
What is a StatefulSet?
A workload for stateful apps. Pods get stable, ordered identities (mysql-0, mysql-1, β¦) and stable PersistentVolume bindings. Pods are created, scaled, and updated in order. Pairs with PersistentVolumes for databases, queues, leader-elected systems.
How does a Deployment know which Pods it owns?
Through the selector field, which matches labels on Pods. The Deployment's template.metadata.labels must match its selector.matchLabels β otherwise the Deployment can't manage the Pods it just created.
Deployment vs StatefulSet β when to pick which?
Deployment: stateless, interchangeable Pods β web frontends, API servers, workers reading from a queue. StatefulSet: each Pod has identity that matters β databases, Kafka brokers, Zookeeper ensembles, anything that does leader election or stores local data.
TOPIC 9 Knowledge check
The two questions the course asks you, in flashcard form.
What is the basic unit of scaling and resiliency in Kubernetes?
Pods. Not containers (those live inside Pods), not Tasks (that's ECS terminology), not ReplicaSets (those manage Pods). Pods are the basic building block for deployment, scaling, and replication.
What is a Kubernetes Service?
A logical collection of Pods plus a means to access them. The Service is continuously updated with the current Pod IPs, so callers don't need to track individual Pods. (Not scheduling β that's the scheduler's job. Not DaemonSet β that's per-node. Not ReplicaSet β that's replica count.)