Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Appendix E: Kubernetes Master Concept Map

TL;DR: Kubernetes is a rich ecosystem of declarative APIs. This master diagram illustrates how every major resource covered in this book interconnects across compute, networking, configuration, storage, security, observability, and deployment pipelines.


The Master Architecture & Resource Graph

graph TD
    subgraph "Workloads & Compute (Ch 3, 4, 11, 14)"
        D[Deployment] -->|manages| RS[ReplicaSet]
        RS -->|manages| P[Pod]
        STS[StatefulSet] -->|manages| P
        DS[DaemonSet] -->|manages 1 per node| P
        Job[Job / CronJob] -->|runs to completion| P
        HPA[HPA Autoscaler] -->|scales replicas| D
    end

    subgraph "Networking & Traffic (Ch 5, 6)"
        Ing[Ingress / Gateway API] -->|routes HTTP traffic| Svc[Service / ClusterIP]
        Svc -->|selects via labels| P
        NP[NetworkPolicy] -->|isolates traffic to/from| P
    end

    subgraph "Configuration & Storage (Ch 7, 8)"
        CM[ConfigMap] -->|injects env / files| P
        Sec[Secret] -->|mounts sensitive keys| P
        PVC[PersistentVolumeClaim] -->|requests storage for| P
        SC[StorageClass] -->|dynamically provisions| PV[PersistentVolume]
        PV -->|binds to| PVC
    end

    subgraph "Identity & Security (Ch 9, 15)"
        SA[ServiceAccount] -->|authenticates| P
        Role[Role / ClusterRole] -->|grants API verbs| CRB[RoleBinding / ClusterRoleBinding]
        CRB -->|binds permissions to| SA
        PSA[Pod Security Admission] -->|enforces Baseline/Restricted on| P
    end

    subgraph "Operations & GitOps (Ch 12, 13, 16)"
        Git[Git Repository] -->|monitored by| Argo[ArgoCD / GitOps]
        Helm[Helm / Kustomize] -->|templates manifests for| Argo
        Argo -->|reconciles desired state to| D
        Prom[Prometheus & Metrics Server] -->|scrapes metrics from| P
        Prom -->|feeds metrics to| HPA
        Prom -->|visualized in| Graf[Grafana Dashboards]
    end

Resource Relationship Quick Reference

ResourceInteracts WithRelationship Description
DeploymentReplicaSet, Pod, HPAManages declarative rolling updates and replica counts.
ServicePod, Ingress, CoreDNSProvides a stable virtual IP and DNS name across ephemeral pod endpoints.
Ingress / GatewayService, Secret (TLS)Routes external HTTP/HTTPS host and path traffic to backend services.
ConfigMap & SecretPod, DeploymentExternalizes configuration and credentials without rebuilding container images.
PVC & StorageClassPersistentVolume, PodRequests durable, persistent block or file storage that survives pod destruction.
ServiceAccount & RBACPod, RoleBindingAssigns an identity to pods for interacting with the Kubernetes API server securely.
NetworkPolicyPod, NamespaceActs as a distributed firewall enforcing ingress/egress allowlists.
Prometheus & HPAPod, DeploymentCollects CPU, memory, and custom metrics to automatically scale workloads.
ArgoCD & GitDeployment, Service, etc.Continuously reconciles cluster state to match the Git repository source of truth.