Kubernetes Architecture Overview
A Kubernetes cluster has two parts:
- Control Plane (master): the brain. Makes decisions and stores cluster state.
- Worker Nodes: the muscle. Run your application containers.
flowchart TB
User["User / kubectl / CI-CD"] -->|HTTPS REST| API
subgraph CP["Control Plane"]
API["kube-apiserver"]
ETCD[("etcd")]
SCHED["kube-scheduler"]
CM["kube-controller-manager"]
CCM["cloud-controller-manager"]
API <--> ETCD
SCHED --> API
CM --> API
CCM --> API
end
subgraph W1["Worker Node 1"]
K1["kubelet"]
P1["kube-proxy"]
R1["Container Runtime"]
POD1["Pods"]
K1 --> R1 --> POD1
end
subgraph W2["Worker Node 2"]
K2["kubelet"]
P2["kube-proxy"]
R2["Container Runtime"]
POD2["Pods"]
K2 --> R2 --> POD2
end
API <--> K1
API <--> K2
Master componets:
Kube api-server:
- this responsible for communtion etcd.
- speak with api server by using kubectl
- this end point to access cluster via restapi over https
- this will handle auth methods, RBAC…etc
- stateless, so you can run multiple replicas
etcd
- data will store in etcd
- it distubution store type have data store in key-value pair
- back of cluster we need take snapshort etcd
metadata:
- name: fronent
kind: pod
container:
- name: webapp
image: nginx
tag: latest
volume: datasource
network: default
port: 80
- name: fronent
kind: deployment
container:
- name: webapp
image: nginx
tag: latest
volume: datasource
network: default
port: 80
- name: webapp
image: nginx
tag: latest
volume: datasource
network: default
port: 80
kube-scheduler:
- watches a new schedule pods in k8s nodes
- monitoring pods (cpu, memory, storage, networkwork , affinity)
kube-controller
- node control
- job control
- cronjob –> cronexpression –> job –> pod created
- replicas/deploymnet controller
- service account / Token controller
colud controller-manager
- this runing on only cloud managed clusters (EKS, AKS, GKE)
- it managed k8s apiserver by cloud-api provider , loadbalancer and routes
- not present local steps like kubadm, kind, minikube, k8s bare-meteal, rke2
Worker node componets:
kubelet
- this is agent which is runing in nodes
- watch pods and asign node to run container
- this agnet will speak and do work by api server inputs
- manage servers deployed in worker node
container Runtime
- software that runs container and pull images
- must be implement CRI
kube proxy:
- runs on every node
- implement the service networking
- manage ip address, tls rules , traffic , communtion.
