Home/Labs/Cluster Anatomy Explorer
All 280 Labs
INTERACTIVE LAB☸️

Kubernetes Core Concepts Lab (Interactive)

Crash a pod, watch ReplicaSet reconciliation reissue a new IP, and route traffic through the Service abstraction you pick. Explore control-plane components, ephemeral pod IPs, kube-proxy iptables versus IPVS, and ClusterIP through Ingress exposure.

Cluster Anatomy: Control Plane, Pods, Services & Ingress

Crash a pod, watch the ReplicaSet reconciliation diff, and route 120 QPS through the Service abstraction you choose.

Deployment replicas:3
CONTROL PLANEkube-apiserver (sole etcd writer · RBAC · webhooks)etcd ×3 (Raft, tolerates 1 failure)scheduler (filter → score)controller-managerReplicaSet: desired=3 actual=3 diff=0
node-a (10.0.1.10)kubelet · 1/3 slots
0-110.244.1.540 rps Ready
node-b (10.0.1.11)kubelet · 1/3 slots
1-110.244.2.1240 rps Ready
node-c (10.0.1.12)kubelet · 1/3 slots
2-110.244.3.1940 rps Ready

route: 120 QPS → https://api.example.com/orders → ClusterIP VIP

Layer 7 host/path routing with TLS termination (cert-manager) on ONE NGINX/Envoy controller fan-out to many Services.

EndpointSlice: 3 ready backends · traffic even → 40 rps/pod

IPVS: kernel hash-table O(1) · per-packet lookup 0.004 ms · Constant latency at 10k+ Services

How It Works Under the Hood

Kubernetes reconciles a declarative desired state: kube-apiserver is the sole gatekeeper to the Raft-backed etcd store, the scheduler filters and scores nodes, and controller-manager loops drive actual toward declared. Pods are ephemeral, so when one dies the ReplicaSet controller recreates it with a brand new IP, which is exactly why Services exist. A Service pins a stable virtual IP and DNS name and load-balances to healthy endpoints tracked by EndpointSlices. NodePort, LoadBalancer and Ingress then decide how much of the cluster is exposed, and kube-proxy in IPVS mode uses kernel hash tables to route at scale.

Core Architectural Principles

  • Only kube-apiserver reads/writes etcd; scheduler and controllers communicate exclusively through the API server.
  • A crashed pod is replaced with a new IP; the Service VIP and EndpointSlice keep the network identity durable.
  • IPVS gives O(1) kernel-hash routing while iptables rule chains degrade O(N) as service count explodes.
Interview Round Script

Frame Services as the answer to ephemeral pod IPs: a Deployment keeps replica count, but IPs churn on every restart, so clients hit a ClusterIP VIP backed by EndpointSlices. Walk the control plane top-down: apiserver as stateless hub, etcd as Raft consensus source of truth, scheduler filtering then scoring, controllers reconciling. Distinguish ClusterIP, NodePort, LoadBalancer and Layer-7 Ingress to show you can design traffic ingress, and cite IPVS for large clusters.

Key Trade-Offs

Declarative self-healing and unified scheduling erase ClickOps errors, at the price of real complexity across RBAC, CNI, and control-plane operations.

Related Curriculum Chapter

Kubernetes Core Concepts: Pods, Nodes, Services, & Ingress

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs