Skip to content

Phase 4: Kubernetes & Fleet Scaling

πŸ“– Deep-Dive Index

1. Kubernetes Architecture & Identity

  • Control Plane vs Data Plane: API Server, etcd, Kubelet, Kube-Proxy.
  • Networking: VPC CNI (AWS IP assignment to Pods) vs Overlay Networks.
  • Authentication: IAM Roles for Service Accounts (IRSA). Tying a Kubernetes ServiceAccount to an AWS IAM Role via OIDC.

2. Auto-Scaling (Karpenter)

  • Cluster Autoscaler limitations: Slow scaling, static node groups.
  • Karpenter Mechanics: Provisioners / NodePools, NodeClaims, bypassing ASGs to talk directly to the EC2 fleet API.
  • Optimization: Workload consolidation, Spot instance orchestration, graceful termination handling.

πŸ› οΈ Job-Essential Exercises

  1. Passwordless Workload Identity (IRSA):
  2. Create an AWS S3 bucket. Create an IAM Role with read access. Associate this role with a K8s ServiceAccount. Deploy a Python pod using this ServiceAccount and verify it can list the S3 bucket without any AWS keys in the environment variables.
  3. Karpenter Spot Scaling:
  4. Install Karpenter. Create a NodePool configured to use AWS Spot Instances (t3.medium, c5.large). Deploy a pod deployment with 0 replicas. Scale it to 30 replicas. Watch Karpenter instantly spin up precisely sized EC2 Spot instances.
  5. Cost Consolidation:
  6. With the 30 replicas running across multiple nodes, scale the deployment back down to 2 replicas. Watch Karpenter's logs as it intelligently cordons, drains, and terminates the empty nodes to eliminate cloud waste.