Skip to content
BytePatterns

Design a Deployment on Kubernetes

Docker & Kubernetes for Interviews: lesson 12 of 12

Walk the request path, then name the failure each piece is there for.

Lesson 12 of 12 · 8 min

Design a Deployment on Kubernetes

Step 1 of 13

The brief: a checkout API that stays up, scales with traffic, and updates safely. Start at the front door.

The Idea

The interview answer is a walk along the request path, then through the failures. An Ingress or Gateway routes to a Service, the Service to ready Pods of a Deployment spread across zones. Config comes from ConfigMaps and Secrets, state lives in a StatefulSet or a managed database, and every container declares requests, limits and probes.

Real-World Example

"Deploy a checkout API": at least three replicas spread by zone, an HPA on CPU, readiness on /ready, a PodDisruptionBudget of minAvailable: 2 so node drains never evict too many at once, and rolling updates with maxUnavailable: 0.

The Tradeoff

Every safety net costs something: spare capacity for surges, extra zones for spread. A PodDisruptionBudget covers only voluntary disruptions such as drains; a node crash still counts against it. Say which failure each piece handles.

Hands-On

# illustrative — two guards a checkout API adds
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata: { name: checkout }
spec:
  minAvailable: 2
  selector: { matchLabels: { app: checkout } }
---
# in the Deployment's Pod template
topologySpreadConstraints:
  - maxSkew: 1
    topologyKey: topology.kubernetes.io/zone
    whenUnsatisfiable: DoNotSchedule
    labelSelector: { matchLabels: { app: checkout } }

Your turn

Put the steps in the right order.

  1. The Service picks a ready checkout Pod
  2. The Ingress controller routes /checkout to the checkout Service
  3. The user's request reaches the cluster's load balancer
  4. The Pod reads its database password from a mounted Secret and queries the database

Mini quiz

1 / 3

A PodDisruptionBudget with minAvailable: 2 protects against:

Sources

New lessons land every few weeks

Leave an address and we will tell you when the next one is up. That is the only reason we will use it.

One address, stored so we can email you. Nothing else, ever.