Memory hook: Render the intent, inspect the diff, verify the rollout.
Must remember
A Deployment rolling update replaces replicas according to surge/unavailability limits. Blue/green maintains distinct old/new environments and switches traffic. A canary exposes a limited share before wider promotion. Plain Kubernetes Services select matching Pods; precise percentage routing may require replica proportions or a capable ingress/service-mesh controller. A label alone does not implement weighted traffic.
Helm combines chart templates with values to create release resources. Inspect helm show values, helm template, release status/history and upgrade changes. A successful Helm command does not prove the application is healthy. Hooks and CRDs have lifecycle considerations; understand what uninstall retains. Avoid secrets in unprotected values files or command history.
Kustomize composes bases and overlays with patches, labels, image changes and generated configuration. kubectl kustomize PATH renders; kubectl apply -k PATH applies. Keep environment differences small and explicit. Do not hand-edit rendered output and assume the next render preserves it.
Before applying, verify context/namespace, intended image and the rendered diff. After applying, inspect rollout status, readiness, Service endpoints and an actual application request. Rollback restores workload configuration, not an incompatible database migration or deleted external data.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Preview Helm output | helm template with the intended values. |
| Maintain small environment variations | Kustomize base plus overlays. |
| Reduce exposure to a new release | Canary with measurable success and a real traffic-control mechanism. |
Traps
- Switching a tag does not prove every node runs the intended digest.
- Rollback needs data/schema compatibility.
Active recall
1. What does Helm manage?
Packaged templated Kubernetes resources as releases.
2. What does Kustomize avoid?
Copying entire manifests merely to express small environment differences.
3. Blue/green versus rolling?
Switch between distinct environments versus incrementally replace replicas.
4. Why render before applying?
To inspect the actual resources after values and patches resolve.
5. What proves successful delivery?
Healthy rollout and correct behavior through the intended application path.