Play through all 11 layers of a Kubernetes cluster, from Client & Access and the Control Plane to Autoscaling and Hardening. Drag-and-drop levels, boss battles and typed recall.
Client & Access
How humans and tools talk to the cluster
kubectl — The command-line tool for talking to your cluster
Kubernetes Dashboard — A web-based UI for viewing and managing the cluster
CI/CD Pipeline — Automation that deploys your code to the cluster
Control Plane
The cluster's brain — decides and remembers everything
kube-apiserver — The front door to the cluster — every request goes through it
etcd — The cluster's single source of truth
kube-scheduler — Decides which node a new pod should run on
kube-controller-manager — Runs the control loops that enforce your desired state
cloud-controller-manager — Connects the cluster to your cloud provider's infrastructure
Workloads
What you actually deploy and run
Pod — The smallest deployable unit in Kubernetes
ReplicaSet — Keeps a fixed number of identical pod replicas running
Deployment — Manages rolling updates and rollbacks of stateless apps
StatefulSet — Runs pods that need stable identity and storage
DaemonSet — Runs exactly one copy of a pod on every node
Job — Runs a pod to completion, once
CronJob — Runs a Job on a repeating schedule
Networking & Service Discovery
How traffic finds your workloads
Service — A stable network address for a set of pods
Ingress — HTTP(S) routing rules from outside the cluster to Services
Ingress Controller — The actual software that implements Ingress rules
CoreDNS — Cluster-internal DNS so pods can find Services by name
NetworkPolicy — A firewall for which pods can talk to which
Node & Container Runtime
The worker machines, and the software on them that runs your containers
Node — A worker machine — physical or virtual — in the cluster
kubelet — The agent on every node that keeps pods running
kube-proxy — Implements Service networking rules on each node
Container Runtime — The engine that actually runs containers (e.g. containerd)
Storage & Configuration
Config and secrets you declare, storage you claim, and how it gets provisioned
ConfigMap — Non-secret configuration data, decoupled from your image
Secret — Sensitive data like passwords, tokens and keys
PersistentVolume (PV) — A piece of real storage in the cluster, provisioned in advance
PersistentVolumeClaim (PVC) — A pod's request to 'rent' some persistent storage
StorageClass — A template for dynamically provisioning storage on demand
Governance & Security
The foundation: boundaries, permissions and limits
Namespace — A virtual cluster-within-a-cluster for organizing resources
RBAC (Roles & Bindings) — Who is allowed to do what, on which resources
ResourceQuota — Caps total resource usage within a namespace
ServiceAccount — An identity for pods and processes, not humans
Scheduling & Placement
Where pods land, how they stay apart, and what protects them under pressure
Node Affinity — Rules that attract (or repel) pods toward certain nodes
Pod Affinity & Anti-Affinity — Rules about which pods should — or should not — run near each other
Taints & Tolerations — Nodes that repel pods — unless the pod says it is okay
Topology Spread Constraints — Evenly spreads pods across zones, nodes, or racks
Pod Priority & Preemption — Lets critical pods evict less important ones when resources are tight
Pod Disruption Budget (PDB) — Guarantees a minimum number of pods stay up during voluntary disruptions
Autoscaling & Resilience
Growing, shrinking and right-sizing your workloads and cluster automatically
Horizontal Pod Autoscaler (HPA) — Automatically adds or removes pod replicas based on load
Vertical Pod Autoscaler (VPA) — Automatically right-sizes a container's CPU/memory requests
Cluster Autoscaler — Automatically adds or removes entire Nodes from the cluster
Metrics Server — Collects CPU/memory usage from every node and pod, cluster-wide
Extending Kubernetes
Teaching the cluster new tricks
Custom Resource Definition (CRD) — Lets you define your own Kubernetes object types
Operator Pattern — A controller that automates operating a specific application
Admission Webhook — An external gatekeeper the API server calls before saving any object
CNI Plugin — The pluggable software that actually wires up pod networking
CSI Plugin — The pluggable software that connects Kubernetes to a specific storage backend
Hardening & Observability
Locking it down and watching it closely
Pod Security Admission — Cluster-wide enforcement of baseline pod security rules
Audit Logging — A tamper-evident record of every request made to the API server
Secrets Encryption at Rest — Encrypts Secret data inside etcd itself, not just base64
Kubernetes Events — A stream of what is happening to your objects, in plain language
Node-Pressure Eviction — Kubelet's last resort to protect a node running low on resources