Kubernetes (K8s) is the de facto operating system of modern cloud-native infrastructure. It automates the deployment, scaling, service discovery, and self-healing of containerized applications across clusters of compute nodes.
This guide demystifies the Kubernetes architecture, examining how control plane components and worker nodes coordinate to maintain the desired cluster state.
1. The Control Plane: Cluster Brain
kube-apiserver: The central REST gateway. All cluster operations, CLI kubectl commands, and controller interactions pass through and are validated by the API server.
etcd: A distributed, consistent key-value store using the Raft consensus algorithm. etcd stores the authoritative state of the entire cluster.
kube-scheduler: Evaluates resource requests, node affinities, taints/tolerations, and topology constraints to assign unassigned Pods to optimal worker nodes.
kube-controller-manager: Runs continuous control loops (DeploymentController, ReplicaSetController, NodeController) comparing the actual cluster state with the desired state.
2. Worker Node Components: Workload Execution
kubelet: The node agent that communicates with the API server, ensures containers described in PodSpecs are running and healthy via the Container Runtime Interface (CRI, e.g. containerd).
kube-proxy: Maintains network rules on nodes (using iptables or IPVS) to route traffic from Kubernetes Services (ClusterIP, NodePort) to target Pod IPs.
Container Network Interface (CNI): Plugins (Calico, Cilium, Flannel) that assign unique, routable IP addresses to every Pod in the cluster.
3. The Pod Lifecycle and Self-Healing
Pods transition through defined lifecycle phases: Pending -> Running -> Succeeded/Failed -> CrashLoopBackOff.
Liveness and Readiness probes allow Kubernetes to monitor container health. If a Liveness probe fails, the kubelet restarts the container; if a Readiness probe fails, the Pod is removed from Service traffic endpoints until it recovers.
Frequently Asked Questions
What is the difference between a Deployment and a StatefulSet?
Deployments manage stateless applications where pods are interchangeable and have dynamic IPs. StatefulSets manage stateful applications (databases like PostgreSQL or Kafka) requiring persistent storage identifiers, ordered rollouts, and stable network identities.
Why is etcd critical for high-availability Kubernetes clusters?
etcd holds the entire cluster configuration and status. In production, etcd is deployed across an odd number of control plane nodes (3 or 5) to tolerate node failures while maintaining Raft quorum.
Written by Priyanka Verma
Technical contributor and subject matter specialist at PrimerPrep. Dedicated to breaking down complex systems into transparent, verified engineering principles.
Ready to test your knowledge?
Put these concepts into action with our independently reviewed practice questions and coding challenges.
Start practicing free