Karpenter Mechanics: Provisioners / NodePools, NodeClaims, bypassing ASGs to talk directly to the EC2 fleet API.
Optimization: Workload consolidation, Spot instance orchestration, graceful termination handling.
π οΈ Job-Essential Exercises
Passwordless Workload Identity (IRSA):
Create an AWS S3 bucket. Create an IAM Role with read access. Associate this role with a K8s ServiceAccount. Deploy a Python pod using this ServiceAccount and verify it can list the S3 bucket without any AWS keys in the environment variables.
Karpenter Spot Scaling:
Install Karpenter. Create a NodePool configured to use AWS Spot Instances (t3.medium, c5.large). Deploy a pod deployment with 0 replicas. Scale it to 30 replicas. Watch Karpenter instantly spin up precisely sized EC2 Spot instances.
Cost Consolidation:
With the 30 replicas running across multiple nodes, scale the deployment back down to 2 replicas. Watch Karpenter's logs as it intelligently cordons, drains, and terminates the empty nodes to eliminate cloud waste.