Kubernetes Pod, Deployment, and Ingress

The 3 objects

Kubernetes holds your application in a cluster. A pod is the basic unit of the cluster. A deployment controls a group of pods. An ingress gives persons on the Internet access to a service in the cluster. Each part gives the steps for a problem.

Pod

A pod holds one container or more containers.

Each pod has an IP address.

The pod has a phase.

The phase shows the state of the pod.

The cluster gives the pod a node.

You can delete the pod.

Deployment

A deployment controls a group of pods.

You set the number of pods in the manifest.

The deployment keeps the number at this value.

The deployment gives new pods to the cluster.

This change is a rollout.

A rollout replaces the pods one group at a time.

Ingress

An ingress gives persons on the Internet access to a service in the cluster.

The ingress has one or more rules.

Each rule has a host and a path.

The ingress sends the traffic to the correct service.

An ingress controller does the work.

The controller reads the rules of the ingress.

Words to know

pod
The pod is the unit of the cluster.
deployment
The deployment controls the pods.
ingress
The ingress gives access to the service.
manifest
The manifest is the file for the object.
event
The event shows a change in the cluster.
log
The log shows the output of the container.

Before you do a check

  1. Run the commands in a terminal.
  2. Replace the example names with your names.
  3. Add the name of your namespace to each command.
  4. Do one command at a time.

Pod problems

1

First, do a check of the pod state.

kubectl get pods -n <namespace>
2

Then, look at the events and the state of the pod.

kubectl describe pod <pod-name> -n <namespace>
3

Then, look at the logs of the container.

kubectl logs <pod-name> -n <namespace>

Read the items that follow.

Pending state

The cluster does not start the pod.

Do a check of the events.

The node does not have sufficient CPU or memory.

The image is not available.

CrashLoopBackOff state

The container stops again and again.

Look at the logs of the container.

Correct the error in the application.

Then start the pod again.

ImagePullBackOff state

The cluster cannot get the image.

Do a check of the image name.

Do a check of the secret of the registry.

OOMKilled state

The container uses more memory than the limit.

Change the memory limit in the manifest.

Or make the application use less memory.

Not ready

The pod is not ready.

The readiness probe does not work.

Do a check of the probe path and the probe port.

Deployment problems

1

First, do a check of the deployment state.

kubectl get deployment <name> -n <namespace>
2

Then, look at the rollout state.

kubectl rollout status deployment/<name> -n <namespace>
3

Then, look at the events of the deployment.

kubectl describe deployment <name> -n <namespace>
4

Then, look at the replica sets.

kubectl get replicaset -n <namespace>

Read the items that follow.

Pods not ready

The pods are not ready.

Look at the pod problems.

Rollout stops

The rollout does not move.

Do a check of the events.

The image is not available.

Or the image name is not correct.

No pods

The deployment does not create pods.

Do a check of the events.

The service account does not have sufficient access.

Memory use

The pods use too much memory.

Change the memory limit in the manifest.

Ingress problems

1

First, do a check of the ingress state.

kubectl get ingress -n <namespace>
2

Then, look at the events of the ingress.

kubectl describe ingress <name> -n <namespace>
3

Then, do a check of the service and the endpoints.

kubectl get service,endpoints -n <namespace>
4

Then, do a check of the ingress controller.

kubectl get pods -n ingress-nginx

Read the items that follow.

400 code

The ingress gives a 400 code.

The request is not correct.

Do a check of the request of the client.

401 code

The ingress gives a 401 code.

The request has no token.

Do a check of the token in the request.

403 code

The ingress gives a 403 code.

The role does not give access.

Do a check of the role of the token.

404 code

The ingress gives a 404 code.

The host or the path is not correct.

Compare the host in the ingress with the host in your request.

Compare the path in the ingress with the path in the service.

500 code

The ingress gives a 500 code.

The container has an error.

Look at the logs of the container.

502 code

The ingress gives a 502 code.

The port of the service is not correct.

Do a check of the target port.

503 code

The ingress gives a 503 code.

The endpoint is not available.

Do a check of the endpoints of the service.

504 code

The ingress gives a 504 code.

The pod is too slow.

Look at the logs of the pod.

No address

The ingress has no address.

The ingress controller is not available.

Or the controller does not have a load balancer.

Do a check of the controller pods.

Wrong host

The host is not correct.

Add the host to your DNS record.

Or use the IP address of the load balancer.

The request path

A request moves from left to right.

Each part checks the request.

If all parts work, the ingress gives a 200 code.

Person
makes the request
→
Ingress
checks the host and the path
→
Service
has the port
→
Pod
has the container
200
all parts

The request works.

400
at the ingress

The request is not correct.

401
at the ingress

The request has no token.

403
at the ingress

The role does not give access.

404
at the ingress

The host or the path is not correct.

500
at the pod

The container has an error.

502
at the service

The port of the service is not correct.

503
at the pod

The endpoint is not available.

504
at the pod

The pod is too slow.

Find the code in the response. Then do the steps for the code.

A safe change

CAUTION: Do not change the production manifest without a copy.

An incorrect change can stop the service.

Make a copy of the manifest before you change it.

  1. Change one item at a time.
  2. Do a check of the result after each change.
  3. Look at the events before you look at the logs.
  4. Keep the manifest until the new pods work.