KubeScopeKubernetes, made visible

Learn at your own level

Kubernetes can make sense—one layer at a time.

Start with a familiar port story, then gradually reveal objects, architecture, and production request mechanics. No Kubernetes background required.

  • 5guided flows
  • 13components
  • 0external dependencies
⎈Desired stateAPI-driven control loop
APINode NetworkData

Your learning path

How deep should we go?

Pick the language that feels comfortable. You can move between levels at any time; your choice is remembered on this device.

Foundation · 1 of 4For curious beginners and non-technical teammates

A familiar story

Imagine a busy shipping port

Your application is cargo that must stay available. Kubernetes is the port authority coordinating where it runs and replacing it when something fails.

One thing to rememberYou describe the result you want; Kubernetes keeps working to maintain it.
Explore this level

Plain words → Kubernetes words

Terminology bridge

Shared foundation

The 60-second mental model

You declare what should exist. Kubernetes continuously compares that desired state with reality and acts to close the gap.

01

Declare

Submit an object such as a Deployment through the Kubernetes API.

02

Store

The API server validates the request and persists cluster state in etcd.

03

Reconcile

Controllers and the scheduler decide which actions are needed.

04

Run & observe

Kubelets run Pods and report status. The loop never stops.

Architecture explorer

Who does what?

Select a component to see its responsibility, interactions, and a plain-language analogy.

Cluster edge & add-ons

Control plane · decides

Worker node · runs

Core component Add-on or implementation-dependent

Guided flows

Follow the signal

Choose a real cluster event, then step through the systems involved.

Step 1 of 6Control plane

You + kubectl

Submit desired state

Object relationships

From Deployment to traffic

These resources form a common stateless web application stack. Select an object for its job and lifecycle.

→ → ← ←
Workload controller

Deployment

⚿

Configuration

ConfigMap stores non-confidential settings. Secret stores sensitive data, but requires appropriate encryption and access controls.

▤

Persistent data

A PersistentVolumeClaim asks for storage. A compatible volume is bound and mounted into the Pod.

⌁

Networking

Services select Pods by labels. DNS provides stable names; NetworkPolicy can restrict allowed connections when supported by the network plugin.

↗

Scaling

HorizontalPodAutoscaler adjusts replica count from observed metrics. Resource requests matter because utilization is calculated against them.

Read the cluster

A small kubectl toolbox

Avoid confusion

Common misconceptions

“A Service runs my application.”

No. Pods run containers. A Service supplies a stable virtual endpoint and selects eligible Pods.

“Ingress works after I create the YAML.”

An Ingress resource needs an Ingress controller. For new designs, also evaluate the Kubernetes Gateway API.

“A Secret is automatically encrypted.”

Secret data is base64-encoded, not inherently encrypted. Configure encryption at rest and least-privilege RBAC.

“Kubernetes adds persistence to a container.”

Container filesystems are ephemeral. Stateful data needs an appropriate volume, claim, backup, and lifecycle plan.

Continue learning

Authoritative references

The explanations in this app are based on official Kubernetes documentation. Open these for precise behavior and current API guidance.