Reference
Glossary
Every term introduced across the course, in the order you'd meet it in a lesson's module. Search by name or by what it does.
64 of 64 terms
- API server Module 1
- The single front door to a Kubernetes cluster. Every other component β kubectl, the scheduler, the kubelet β talks to the cluster exclusively through this HTTP API; nothing accesses etcd directly.
- AWS Load Balancer Controller Module 15
- Provisions a real NLB/ALB on EKS from a Service (type=LoadBalancer) or Ingress with the right annotations β the production equivalent of this course's local Traefik-on-ClusterIP setup.
- Cluster Autoscaler / Karpenter Module 14
- Add nodes when pods can't be scheduled. Cluster Autoscaler is node-group/count-driven; Karpenter is genuinely pod-driven, bin-packing-aware, and is what you'd typically use on EKS.
- ConfigMap Module 5
- Externalized, non-sensitive configuration consumed by pods as env vars or mounted files β lets you change config without rebuilding an image.
- Control plane Module 1
- The management layer of a cluster (API server, etcd, scheduler, controller manager) β decides where things run and remembers what you asked for, but doesn't run your application.
- Controller manager Module 1
- Runs the reconciliation loops that keep actual cluster state converging toward desired state β one loop per resource type (Deployments, Nodes, Jobs, ...).
- CoreDNS Module 4
- The cluster's internal DNS server, giving every Service a resolvable name (<service>.<namespace>.svc.cluster.local). Pods point at it via /etc/resolv.conf.
- CrashLoopBackOff Module 2
- A pod status meaning a container keeps exiting and Kubernetes keeps restarting it with increasing delay. Diagnose with kubectl describe (Last State/Exit Code) and kubectl logs --previous.
- CronJob Module 9
- A Job template run on a schedule (cron syntax).
- DaemonSet Module 9
- Runs exactly one pod per matching node automatically β no replica count to manage. kube-proxy and the CNI's node agent are both DaemonSets.
- Deployment Module 3
- Declares desired image, replica count, and update strategy for a stateless workload. Manages a ReplicaSet, which manages the actual Pods.
- Desired state Module 1
- What you declared should exist, stored in etcd via the API server β not something Kubernetes does once, but something it continuously works toward.
- EKS Pod Identity Module 15
- The newer, simpler EKS-specific mechanism for the same goal as IRSA (a pod assuming an IAM role), now AWS's default recommendation for new workloads over IRSA (IRSA is still required for Fargate).
- Endpoints / EndpointSlice Module 4
- The live list of pod IPs backing a Service. EndpointSlice is the current, non-deprecated API (replacing v1 Endpoints as of Kubernetes 1.33) β a Service with zero ready addresses here means its selector doesn't match any pods.
- etcd Module 1
- The cluster's single source of truth: a small, consistent key-value store holding every object you've created. If etcd is gone, the cluster's memory is gone.
- Gateway API Module 8
- The structured, role-oriented successor to Ingress (GatewayClass/Gateway/HTTPRoute), expressing routing as portable typed fields instead of controller-specific annotations.
- Helm Module 12
- A templating, packaging, and release-lifecycle tool for bundles of manifests β Chart.yaml/values.yaml/templates, with install/upgrade/rollback/uninstall and its own release revision history.
- HorizontalPodAutoscaler (HPA) Module 14
- Scales a Deployment's replica count based on observed metrics against resource requests (autoscaling/v2) β needs requests set to compute a percentage against, and metrics-server to read from.
- Ingress Module 8
- A resource describing host/path-based HTTP(S) routing into the cluster from one entry point. Does nothing on its own β an Ingress controller (e.g. Traefik) is what implements the rules.
- Ingress controller Module 8
- The component (Traefik, formerly commonly ingress-nginx β retired by its maintainers in March 2026) that watches Ingress objects and actually configures routing/load balancing.
- IRSA Module 15
- IAM Roles for Service Accounts β OIDC federation letting a Kubernetes ServiceAccount assume a real AWS IAM role via an annotation + trust policy.
- Job Module 9
- A run-to-completion workload β unlike a Deployment's pods, a Job's pods are supposed to finish. Governed by completions, parallelism, and backoffLimit.
- kube-proxy Module 1
- The per-node component that programs the network rules Services rely on to route traffic to the right pods.
- kubelet Module 1
- The agent running on every node that takes instructions from the control plane and talks to the local container runtime to actually start and stop containers.
- Kustomize Module 12
- A patch-based alternative to Helm with no templating language: a base manifest set plus overlays that patch it (e.g. per-environment), built into kubectl via apply -k.
- Label Module 2
- An arbitrary key-value tag on an object. Carries no built-in meaning β controllers find what they're responsible for by querying labels via selectors.
- Liveness probe Module 6
- Checked periodically by the kubelet; failing it gets the container restarted. Use for 'is this process still alive and functioning,' not 'is it ready for traffic.'
- maxUnavailable / maxSurge Module 3
- Rolling update settings controlling how many pods below (maxUnavailable) or above (maxSurge) the desired count are tolerated during a rollout.
- metrics-server Module 13
- A cluster add-on providing point-in-time CPU/memory metrics (kubectl top, HPA) β separate from the API server and not installed by default.
- Namespace Module 2
- A way to divide a cluster's objects into non-overlapping groups for naming, access control, and quotas. Not a network or scheduling boundary by itself.
- NetworkPolicy Module 11
- Firewall rules for pod-to-pod traffic, matched by label selectors. Only enforced if the cluster's CNI supports it (this course's kind cluster runs Calico specifically so it does β the default kindnet CNI accepts but never enforces these).
- Node Module 1
- A worker machine (VM or physical) that runs your containers via a kubelet and container runtime.
- Node affinity Module 10
- A more expressive nodeSelector β preferred or required rules for which nodes a pod can land on, based on node labels.
- OOMKilled Module 6
- The Linux kernel's out-of-memory killer terminated a container for exceeding its memory limit (a cgroup enforcement action, not a crash in the app's own code).
- PersistentVolume (PV) Module 7
- A piece of real storage in the cluster, either provisioned ahead of time or dynamically by a StorageClass.
- PersistentVolumeClaim (PVC) Module 7
- A request for storage that binds to a PV meeting its size/access-mode/class requirements. Stuck Pending means nothing available satisfies the request β kubectl describe pvc says exactly why.
- Pod Module 2
- The smallest deployable unit in Kubernetes: one or more containers that always share a node, a network namespace (one IP), and optionally storage.
- Pod affinity / anti-affinity Module 10
- Schedule a pod relative to other pods β co-locate it with something, or keep it away from something (e.g. its own other replicas).
- Pod Security Standards Module 11
- Privileged/Baseline/Restricted levels enforced at admission time via pod-security.kubernetes.io/enforce namespace labels β the successor to the long-removed PodSecurityPolicy.
- QoS class Module 6
- Guaranteed (requests==limits on every container), Burstable (requests set but not equal to limits), or BestEffort (neither set) β determines eviction order under node pressure.
- Readiness probe Module 6
- Checked periodically; failing it removes the pod from Service endpoints without restarting it. The usual cause of a healthy-looking pod that isn't receiving traffic.
- Reconciliation loop Module 1
- A controller's continuous, never-stopping cycle of comparing desired state against actual state and acting whenever they differ β the core mechanism behind almost everything in Kubernetes.
- ReplicaSet Module 3
- Watches over a set of identical Pods via a label selector and keeps the running count matching its desired replica count. Usually managed by a Deployment, not created directly.
- Resource limits Module 6
- The ceiling a container can't exceed. Over the CPU limit, it's throttled; over the memory limit, it's OOMKilled.
- Resource requests Module 6
- What a container is guaranteed and what the scheduler uses to decide which node has room β not a ceiling, a reservation.
- Revision (rollout) Module 3
- A snapshot of a Deployment's pod template, kept (as a scaled-to-zero ReplicaSet) up to revisionHistoryLimit so kubectl rollout undo has something to roll back to.
- Role / ClusterRole Module 11
- A set of permissions (verb + resource + apiGroup) β Role is namespaced, ClusterRole is cluster-scoped.
- RoleBinding / ClusterRoleBinding Module 11
- Grants a Role/ClusterRole's permissions to a specific user, group, or ServiceAccount.
- Rolling update Module 3
- Replacing old Pods with new ones gradually, governed by maxUnavailable and maxSurge, so enough healthy old Pods keep serving traffic throughout.
- Scheduler Module 1
- The control plane component that watches for pods with no node assigned yet and binds each one to a suitable node based on resources, constraints, and policy.
- Secret Module 5
- Like a ConfigMap, but for sensitive values. Stored base64-encoded (encoding, not encryption) β anyone with API read access can trivially decode it; real protection comes from RBAC and encryption-at-rest.
- Selector Module 2
- A query over labels (e.g. app=web) that Services, ReplicaSets, and NetworkPolicies use to find the objects they apply to, re-evaluated continuously.
- Service Module 4
- A stable virtual IP and DNS name that routes to a changing set of Pods matched by a label selector. Types: ClusterIP (internal only), NodePort (a port on every node), LoadBalancer (provisions an external LB, cloud-only).
- ServiceAccount Module 11
- A pod's identity for talking to the Kubernetes API. Every pod has one (default, unless you specify otherwise).
- Startup probe Module 6
- Gates liveness/readiness checks until a slow-starting container is actually up, preventing premature liveness-triggered restarts during a long boot.
- StatefulSet Module 7
- Like a Deployment, but for workloads needing stable identity: predictable ordinal pod names and a stable per-pod PVC via volumeClaimTemplates, preserved across restarts.
- StorageClass Module 7
- A template for dynamically provisioning PVs on demand β provisioner, parameters, reclaimPolicy, and volumeBindingMode (notably WaitForFirstConsumer vs Immediate).
- Structured debugging method Module 13
- Symptom β ownership chain β the specific broken layer β smallest fix β re-check. The explicit version of the process this course's break-fix labs have been teaching since Module 2.
- Taint Module 10
- A node-level repellent: pods are kept off a tainted node unless they carry a matching toleration. The opposite direction from a nodeSelector.
- Toleration Module 10
- A pod-level declaration that it's willing to be scheduled on a node with a specific taint.
- Topology spread constraints Module 10
- The modern, precise way to express 'spread evenly across nodes/zones' β generally preferable to podAntiAffinity for that specific job.
- VerticalPodAutoscaler (VPA) Module 14
- Recommends/sets a pod's resource requests automatically based on observed usage β changes pod size, not count, and doesn't combine cleanly with HPA on the same metric.
- Volume Module 7
- Storage attached to a Pod. Ephemeral types (like emptyDir) live and die with the Pod; PersistentVolumeClaims survive independently of any one Pod.
- VPC CNI Module 15
- EKS's default networking plugin β every pod gets a real routable VPC IP from the subnet's ENI pool, unlike the overlay networks (Calico/kindnet) used locally. Makes small-subnet IP exhaustion a real production concern.