Deployments & Rollouts (CKAD)
Ship a new version with no downtime, and get back to the old one when it goes wrong.
An interactive Kubernetes lesson: 21 steps, about 32 minutes, on a live simulation in your browser.
Your shop's storefront is a container image, shop/web:1.0. The quickest way to get it serving is kubectl run: one pod called web, listening on port 8080.
Shoppers reach it through a Service, which forwards each request to a Ready pod carrying the label app=web. Services get their own lesson; here it is the thing that lets you see whether customers are being served. Every request comes back 200.
What you will learn
Who keeps the pods alive
- A shop on one pod
- Break it: delete the only pod: A bare pod is a one-off. Nothing in the cluster remembers that it should exist, so nothing replaces it.
- Write down what you want: a Deployment: A Deployment owns ReplicaSets; a ReplicaSet owns pods. You edit the Deployment and leave the other two alone.
- Selector, template labels and a hash: One pod template, one hash, one ReplicaSet. Change anything in the template and you get a new hash and a new ReplicaSet.
- Go around the Deployment: Every controller overwrites what it owns. Change the top of the chain, or your change is undone.
- Scale the Deployment instead
The rolling update
- Ship version 1.1: A rollout is two ReplicaSets trading places: the new one scales up as the old one scales down.
- maxSurge and maxUnavailable: maxSurge is how many extra pods you may borrow. maxUnavailable is how many you may be short. The rollout moves inside those two limits.
- maxUnavailable: 0: maxUnavailable: 0 means add first, remove second. Capacity never dips, at the cost of one extra pod's worth of room.
- The opposite: maxSurge: 0
When a release goes bad
- What is running, and what ran before
- Break it: a typo in the image tag: A rolling update only removes old pods as new ones turn Ready. A version that never gets Ready stalls the rollout and takes nothing down.
- Roll it back: A rollback is a roll forward to an old template. It gets a new revision number and follows the same surge and unavailable rules.
Steering a rollout
- Pause, change twice, resume
- Restart without changing anything: rollout restart is a rolling update that changes one annotation. Same image, every pod replaced, no dip in capacity.
Recreate and the small knobs
- Recreate: never two versions at once: Recreate is stop everything, then start everything. You buy "never two versions at once" with downtime.
- Three fields worth knowing
At exam speed
- Drill: ship a new image
- Drill: back to a known revision
Recap & playground
- Cheat sheet
- Playground