Asterrr's Handbook

Domain 2 · Workloads and scheduling

15% of the exam. Rolling out and rolling back Deployments, injecting configuration, autoscaling, self-healing controllers, and controlling where Pods land and how much they may use.

Domain 2 tasks hand you a namespace and an app and ask you to change how it runs: ship a new image without downtime and undo it, feed it settings and credentials, scale it on load, keep it alive when containers or nodes fail, and pin it to (or keep it off) particular nodes. Most tasks are short, so they are cheap points if you know the exact field or command.

CompetencyWhat it's really askingPages
2.1 Deployments, rolling updates and rollbacksChange an image, tune maxSurge/maxUnavailable, read rollout history and undo to a named revisionDeployments and rollouts
2.2 ConfigMaps and SecretsCreate them from literals and files, consume them as env vars or volumes, and know when a change reaches the PodConfigMaps and Secrets
2.3 Workload autoscalingScale by hand, create an HPA that actually reports metrics, know what VPA and in-place resize doAutoscaling
2.4 Robust, self-healing deploymentsPick the right controller, add probes and restart policies, run sidecars and protect Pods with a PodDisruptionBudgetSelf-healing workloads
2.5 Pod admission and schedulingRequests and limits, QoS, LimitRange and ResourceQuota at admission; selectors, affinity, taints and spread at schedulingResources and quotas, Pod placement

What connects Domain 2 to the rest of the exam:

  • A Pod stuck in Pending or CrashLoopBackOff is usually a Domain 2 setting gone wrong. The diagnosis steps live in Troubleshooting applications.
  • The HPA depends on metrics-server, which you also use for kubectl top in Resource usage.
  • StatefulSets pair with per-replica volumes from Persistent volumes.
  • Draining a node during an upgrade respects the PodDisruptionBudgets you write here; see Cluster upgrades.

Editing the Pod instead of its owner

If a Pod belongs to a Deployment, ReplicaSet, StatefulSet or DaemonSet, edits to the Pod are lost when the controller replaces it, and most Pod spec fields can't be edited at all. Change the owner's template (kubectl edit deploy, kubectl set image deploy/...). Check metadata.ownerReferences when you aren't sure who owns a Pod.