Pods (CKAD)
The smallest thing Kubernetes runs: what a pod is, how it starts, what restarts it, and what does not bring it back.
An interactive Kubernetes lesson: 20 steps, about 30 minutes, on a live simulation in your browser.
You have a cluster and a container image for the shop's web frontend: nginx:1.27. Your job is to get it running. One command does it: kubectl run web --image=nginx:1.27 --port=80.
Look at what appeared on the stage. Kubernetes did not start a container on its own. It created a pod called web, and the pod holds the container. A pod is the smallest thing Kubernetes knows how to create, place on a node and count.
What you will learn
Your first pod
- Run one container: Kubernetes never runs a bare container. It runs pods, and a pod wraps one or more containers.
- What is inside a pod: spec is what you asked for. status is what the cluster observed. Kubernetes works to make the second match the first.
- Every pod gets an IP: One pod, one IP. The containers inside share it, and any other pod can reach it directly.
From request to Running
- Take the scheduler away: A pod with no node is only a record in the API. It runs nowhere until the scheduler assigns it.
- Three programs, one pod: The API server records the pod, the scheduler assigns a node, the kubelet on that node runs it.
- Phase is not the STATUS column: Phase is one of five words about the whole pod. The STATUS column is kubectl's summary of what its containers are doing.
When the container dies
- The process inside crashes: A crashed container is restarted in place by the kubelet: same pod, same node, same IP, RESTARTS plus one.
- restartPolicy: Always, OnFailure, Never: restartPolicy is the kubelet's instruction for an exited container: Always restarts, OnFailure restarts only after an error, Never leaves it.
- Exit 0 under restartPolicy: Always: CrashLoopBackOff is a waiting state, not a cause: the container keeps exiting and the kubelet is pausing before the next restart.
- Break it: a real crash loop
Pods are mortal
- Delete the pod itself: A bare pod has no owner. Delete it, or lose its node, and nothing brings it back.
- Bring it back, with labels: Labels are tags you choose; selectors are queries over those tags. That pair is how everything in Kubernetes finds its pods.
- Why controllers exist: A pod is what runs. A controller is the reason it is still running tomorrow.
When it will not start
- Break it: a typo in the image tag: ImagePullBackOff means the node could not fetch the image: wrong name, wrong tag, or no permission. The pod's events say which.
- One order for every broken pod: STATUS names the layer, describe shows the events, logs give the process's own words. Read them in that order.
At exam speed
- Let kubectl write the YAML: Generate, then edit: kubectl writes the manifest, and you type only the part that is special.
- Drill: generate a manifest
- Drill: why did it crash?
Recap & playground
- Cheat sheet
- Playground