certslothcertsloth
AI-200/Topic 05

Azure / Associate

AKS Manifests and Container Scaling

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Desired replicas, healthy pods, service discovery and ingress are separate checks.

Must remember

  • A Kubernetes Deployment declares pod templates and rollout state; a Service supplies stable discovery/traffic selection; ConfigMaps and Secrets supply configuration with different intent. A Secret object is not a substitute for encryption, least privilege or external secret lifecycle.
  • Match labels/selectors and container ports carefully. Readiness controls eligibility for traffic; liveness can restart a stuck container; startup probes protect slow startup from premature liveness failure. Incorrect probes can create a restart loop.
  • Requests guide scheduling; limits constrain supported resource use. Pending pods may lack capacity or satisfy no node/affinity constraints. CrashLoopBackOff needs container logs/events and configuration/dependency checks, not only more replicas.
  • ACR Tasks automate supported image builds/operations. Use immutable image versions/digests and scoped image-pull identity. Application identity is separate from registry pull permission; use supported workload identity for Azure API access.
  • Container Apps revisions and KEDA-based rules support event-driven scaling. Define minimum/maximum replicas and suitable signals/credentials. Scaling on queue depth must account for processing time, retries and downstream capacity.
  • Diagnose from ingress to service selectors/endpoints to ready pods to dependency DNS/network/authentication. Use logs/events and distributed traces. A successful image pull does not prove the application's listener or credentials work.

Choose under exam pressure

Requirement Choice and reason
Pod runs but receives no traffic Check readiness, labels/selectors and service endpoints.
Pod stays Pending Inspect events, resources and scheduling constraints.
Queue load should drive replicas A suitable KEDA/event scaling rule with bounded capacity.

Traps

  • Liveness and readiness are not interchangeable.
  • A Kubernetes Secret can still be exposed through logs or broad RBAC.
  • More replicas can overload the database.

Active recall

1. What does a Service selector match?

Pod labels identifying intended backends.

2. Why use a startup probe?

To allow slow initialisation before normal health enforcement.

3. What should be inspected for CrashLoopBackOff?

Previous/current logs, events, exit reasons, probes and configuration.

4. Does ACR pull permission grant Cosmos DB access?

No. Runtime data access uses separate identity/permissions.

5. Why cap event-driven scaling?

To bound cost and avoid overwhelming constrained dependencies.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.