Memory hook: Desired replicas, healthy pods, service discovery and ingress are separate checks.
Must remember
- A Kubernetes Deployment declares pod templates and rollout state; a Service supplies stable discovery/traffic selection; ConfigMaps and Secrets supply configuration with different intent. A Secret object is not a substitute for encryption, least privilege or external secret lifecycle.
- Match labels/selectors and container ports carefully. Readiness controls eligibility for traffic; liveness can restart a stuck container; startup probes protect slow startup from premature liveness failure. Incorrect probes can create a restart loop.
- Requests guide scheduling; limits constrain supported resource use. Pending pods may lack capacity or satisfy no node/affinity constraints. CrashLoopBackOff needs container logs/events and configuration/dependency checks, not only more replicas.
- ACR Tasks automate supported image builds/operations. Use immutable image versions/digests and scoped image-pull identity. Application identity is separate from registry pull permission; use supported workload identity for Azure API access.
- Container Apps revisions and KEDA-based rules support event-driven scaling. Define minimum/maximum replicas and suitable signals/credentials. Scaling on queue depth must account for processing time, retries and downstream capacity.
- Diagnose from ingress to service selectors/endpoints to ready pods to dependency DNS/network/authentication. Use logs/events and distributed traces. A successful image pull does not prove the application's listener or credentials work.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Pod runs but receives no traffic | Check readiness, labels/selectors and service endpoints. |
| Pod stays Pending | Inspect events, resources and scheduling constraints. |
| Queue load should drive replicas | A suitable KEDA/event scaling rule with bounded capacity. |
Traps
- Liveness and readiness are not interchangeable.
- A Kubernetes Secret can still be exposed through logs or broad RBAC.
- More replicas can overload the database.
Active recall
1. What does a Service selector match?
Pod labels identifying intended backends.
2. Why use a startup probe?
To allow slow initialisation before normal health enforcement.
3. What should be inspected for CrashLoopBackOff?
Previous/current logs, events, exit reasons, probes and configuration.
4. Does ACR pull permission grant Cosmos DB access?
No. Runtime data access uses separate identity/permissions.
5. Why cap event-driven scaling?
To bound cost and avoid overwhelming constrained dependencies.