πŸ“– Read-only preview β€” lessons, diagrams, and quizzes only. The hands-on labs, live grading, and progress tracking require running the real course locally against a Kubernetes cluster.Run it locally β†’

Reference

Glossary

Every term introduced across the course, in the order you'd meet it in a lesson's module. Search by name or by what it does.

64 of 64 terms

API server
Module 1
The single front door to a Kubernetes cluster. Every other component β€” kubectl, the scheduler, the kubelet β€” talks to the cluster exclusively through this HTTP API; nothing accesses etcd directly.
AWS Load Balancer Controller
Module 15
Provisions a real NLB/ALB on EKS from a Service (type=LoadBalancer) or Ingress with the right annotations β€” the production equivalent of this course's local Traefik-on-ClusterIP setup.
Cluster Autoscaler / Karpenter
Module 14
Add nodes when pods can't be scheduled. Cluster Autoscaler is node-group/count-driven; Karpenter is genuinely pod-driven, bin-packing-aware, and is what you'd typically use on EKS.
ConfigMap
Module 5
Externalized, non-sensitive configuration consumed by pods as env vars or mounted files β€” lets you change config without rebuilding an image.
Control plane
Module 1
The management layer of a cluster (API server, etcd, scheduler, controller manager) β€” decides where things run and remembers what you asked for, but doesn't run your application.
Controller manager
Module 1
Runs the reconciliation loops that keep actual cluster state converging toward desired state β€” one loop per resource type (Deployments, Nodes, Jobs, ...).
CoreDNS
Module 4
The cluster's internal DNS server, giving every Service a resolvable name (<service>.<namespace>.svc.cluster.local). Pods point at it via /etc/resolv.conf.
CrashLoopBackOff
Module 2
A pod status meaning a container keeps exiting and Kubernetes keeps restarting it with increasing delay. Diagnose with kubectl describe (Last State/Exit Code) and kubectl logs --previous.
CronJob
Module 9
A Job template run on a schedule (cron syntax).
DaemonSet
Module 9
Runs exactly one pod per matching node automatically β€” no replica count to manage. kube-proxy and the CNI's node agent are both DaemonSets.
Deployment
Module 3
Declares desired image, replica count, and update strategy for a stateless workload. Manages a ReplicaSet, which manages the actual Pods.
Desired state
Module 1
What you declared should exist, stored in etcd via the API server β€” not something Kubernetes does once, but something it continuously works toward.
EKS Pod Identity
Module 15
The newer, simpler EKS-specific mechanism for the same goal as IRSA (a pod assuming an IAM role), now AWS's default recommendation for new workloads over IRSA (IRSA is still required for Fargate).
Endpoints / EndpointSlice
Module 4
The live list of pod IPs backing a Service. EndpointSlice is the current, non-deprecated API (replacing v1 Endpoints as of Kubernetes 1.33) β€” a Service with zero ready addresses here means its selector doesn't match any pods.
etcd
Module 1
The cluster's single source of truth: a small, consistent key-value store holding every object you've created. If etcd is gone, the cluster's memory is gone.
Gateway API
Module 8
The structured, role-oriented successor to Ingress (GatewayClass/Gateway/HTTPRoute), expressing routing as portable typed fields instead of controller-specific annotations.
Helm
Module 12
A templating, packaging, and release-lifecycle tool for bundles of manifests β€” Chart.yaml/values.yaml/templates, with install/upgrade/rollback/uninstall and its own release revision history.
HorizontalPodAutoscaler (HPA)
Module 14
Scales a Deployment's replica count based on observed metrics against resource requests (autoscaling/v2) β€” needs requests set to compute a percentage against, and metrics-server to read from.
Ingress
Module 8
A resource describing host/path-based HTTP(S) routing into the cluster from one entry point. Does nothing on its own β€” an Ingress controller (e.g. Traefik) is what implements the rules.
Ingress controller
Module 8
The component (Traefik, formerly commonly ingress-nginx β€” retired by its maintainers in March 2026) that watches Ingress objects and actually configures routing/load balancing.
IRSA
Module 15
IAM Roles for Service Accounts β€” OIDC federation letting a Kubernetes ServiceAccount assume a real AWS IAM role via an annotation + trust policy.
Job
Module 9
A run-to-completion workload β€” unlike a Deployment's pods, a Job's pods are supposed to finish. Governed by completions, parallelism, and backoffLimit.
kube-proxy
Module 1
The per-node component that programs the network rules Services rely on to route traffic to the right pods.
kubelet
Module 1
The agent running on every node that takes instructions from the control plane and talks to the local container runtime to actually start and stop containers.
Kustomize
Module 12
A patch-based alternative to Helm with no templating language: a base manifest set plus overlays that patch it (e.g. per-environment), built into kubectl via apply -k.
Label
Module 2
An arbitrary key-value tag on an object. Carries no built-in meaning β€” controllers find what they're responsible for by querying labels via selectors.
Liveness probe
Module 6
Checked periodically by the kubelet; failing it gets the container restarted. Use for 'is this process still alive and functioning,' not 'is it ready for traffic.'
maxUnavailable / maxSurge
Module 3
Rolling update settings controlling how many pods below (maxUnavailable) or above (maxSurge) the desired count are tolerated during a rollout.
metrics-server
Module 13
A cluster add-on providing point-in-time CPU/memory metrics (kubectl top, HPA) β€” separate from the API server and not installed by default.
Namespace
Module 2
A way to divide a cluster's objects into non-overlapping groups for naming, access control, and quotas. Not a network or scheduling boundary by itself.
NetworkPolicy
Module 11
Firewall rules for pod-to-pod traffic, matched by label selectors. Only enforced if the cluster's CNI supports it (this course's kind cluster runs Calico specifically so it does β€” the default kindnet CNI accepts but never enforces these).
Node
Module 1
A worker machine (VM or physical) that runs your containers via a kubelet and container runtime.
Node affinity
Module 10
A more expressive nodeSelector β€” preferred or required rules for which nodes a pod can land on, based on node labels.
OOMKilled
Module 6
The Linux kernel's out-of-memory killer terminated a container for exceeding its memory limit (a cgroup enforcement action, not a crash in the app's own code).
PersistentVolume (PV)
Module 7
A piece of real storage in the cluster, either provisioned ahead of time or dynamically by a StorageClass.
PersistentVolumeClaim (PVC)
Module 7
A request for storage that binds to a PV meeting its size/access-mode/class requirements. Stuck Pending means nothing available satisfies the request β€” kubectl describe pvc says exactly why.
Pod
Module 2
The smallest deployable unit in Kubernetes: one or more containers that always share a node, a network namespace (one IP), and optionally storage.
Pod affinity / anti-affinity
Module 10
Schedule a pod relative to other pods β€” co-locate it with something, or keep it away from something (e.g. its own other replicas).
Pod Security Standards
Module 11
Privileged/Baseline/Restricted levels enforced at admission time via pod-security.kubernetes.io/enforce namespace labels β€” the successor to the long-removed PodSecurityPolicy.
QoS class
Module 6
Guaranteed (requests==limits on every container), Burstable (requests set but not equal to limits), or BestEffort (neither set) β€” determines eviction order under node pressure.
Readiness probe
Module 6
Checked periodically; failing it removes the pod from Service endpoints without restarting it. The usual cause of a healthy-looking pod that isn't receiving traffic.
Reconciliation loop
Module 1
A controller's continuous, never-stopping cycle of comparing desired state against actual state and acting whenever they differ β€” the core mechanism behind almost everything in Kubernetes.
ReplicaSet
Module 3
Watches over a set of identical Pods via a label selector and keeps the running count matching its desired replica count. Usually managed by a Deployment, not created directly.
Resource limits
Module 6
The ceiling a container can't exceed. Over the CPU limit, it's throttled; over the memory limit, it's OOMKilled.
Resource requests
Module 6
What a container is guaranteed and what the scheduler uses to decide which node has room β€” not a ceiling, a reservation.
Revision (rollout)
Module 3
A snapshot of a Deployment's pod template, kept (as a scaled-to-zero ReplicaSet) up to revisionHistoryLimit so kubectl rollout undo has something to roll back to.
Role / ClusterRole
Module 11
A set of permissions (verb + resource + apiGroup) β€” Role is namespaced, ClusterRole is cluster-scoped.
RoleBinding / ClusterRoleBinding
Module 11
Grants a Role/ClusterRole's permissions to a specific user, group, or ServiceAccount.
Rolling update
Module 3
Replacing old Pods with new ones gradually, governed by maxUnavailable and maxSurge, so enough healthy old Pods keep serving traffic throughout.
Scheduler
Module 1
The control plane component that watches for pods with no node assigned yet and binds each one to a suitable node based on resources, constraints, and policy.
Secret
Module 5
Like a ConfigMap, but for sensitive values. Stored base64-encoded (encoding, not encryption) β€” anyone with API read access can trivially decode it; real protection comes from RBAC and encryption-at-rest.
Selector
Module 2
A query over labels (e.g. app=web) that Services, ReplicaSets, and NetworkPolicies use to find the objects they apply to, re-evaluated continuously.
Service
Module 4
A stable virtual IP and DNS name that routes to a changing set of Pods matched by a label selector. Types: ClusterIP (internal only), NodePort (a port on every node), LoadBalancer (provisions an external LB, cloud-only).
ServiceAccount
Module 11
A pod's identity for talking to the Kubernetes API. Every pod has one (default, unless you specify otherwise).
Startup probe
Module 6
Gates liveness/readiness checks until a slow-starting container is actually up, preventing premature liveness-triggered restarts during a long boot.
StatefulSet
Module 7
Like a Deployment, but for workloads needing stable identity: predictable ordinal pod names and a stable per-pod PVC via volumeClaimTemplates, preserved across restarts.
StorageClass
Module 7
A template for dynamically provisioning PVs on demand β€” provisioner, parameters, reclaimPolicy, and volumeBindingMode (notably WaitForFirstConsumer vs Immediate).
Structured debugging method
Module 13
Symptom β†’ ownership chain β†’ the specific broken layer β†’ smallest fix β†’ re-check. The explicit version of the process this course's break-fix labs have been teaching since Module 2.
Taint
Module 10
A node-level repellent: pods are kept off a tainted node unless they carry a matching toleration. The opposite direction from a nodeSelector.
Toleration
Module 10
A pod-level declaration that it's willing to be scheduled on a node with a specific taint.
Topology spread constraints
Module 10
The modern, precise way to express 'spread evenly across nodes/zones' β€” generally preferable to podAntiAffinity for that specific job.
VerticalPodAutoscaler (VPA)
Module 14
Recommends/sets a pod's resource requests automatically based on observed usage β€” changes pod size, not count, and doesn't combine cleanly with HPA on the same metric.
Volume
Module 7
Storage attached to a Pod. Ephemeral types (like emptyDir) live and die with the Pod; PersistentVolumeClaims survive independently of any one Pod.
VPC CNI
Module 15
EKS's default networking plugin β€” every pod gets a real routable VPC IP from the subnet's ENI pool, unlike the overlay networks (Calico/kindnet) used locally. Makes small-subnet IP exhaustion a real production concern.