A familiar story
Imagine a busy shipping port
Your application is cargo that must stay available. Kubernetes is the port authority coordinating where it runs and replacing it when something fails.
Learn at your own level
Start with a familiar port story, then gradually reveal objects, architecture, and production request mechanics. No Kubernetes background required.
Your learning path
Pick the language that feels comfortable. You can move between levels at any time; your choice is remembered on this device.
A familiar story
Your application is cargo that must stay available. Kubernetes is the port authority coordinating where it runs and replacing it when something fails.
Plain words → Kubernetes words
Shared foundation
You declare what should exist. Kubernetes continuously compares that desired state with reality and acts to close the gap.
Submit an object such as a Deployment through the Kubernetes API.
The API server validates the request and persists cluster state in etcd.
Controllers and the scheduler decide which actions are needed.
Kubelets run Pods and report status. The loop never stops.
Architecture explorer
Select a component to see its responsibility, interactions, and a plain-language analogy.
Cluster edge & add-ons
Control plane · decides
Worker node · runs
Core component Add-on or implementation-dependent
Guided flows
Choose a real cluster event, then step through the systems involved.
You + kubectl
Object relationships
These resources form a common stateless web application stack. Select an object for its job and lifecycle.
ConfigMap stores non-confidential settings. Secret stores sensitive data, but requires appropriate encryption and access controls.
A PersistentVolumeClaim asks for storage. A compatible volume is bound and mounted into the Pod.
Services select Pods by labels. DNS provides stable names; NetworkPolicy can restrict allowed connections when supported by the network plugin.
HorizontalPodAutoscaler adjusts replica count from observed metrics. Resource requests matter because utilization is calculated against them.
Read the cluster
Avoid confusion
No. Pods run containers. A Service supplies a stable virtual endpoint and selects eligible Pods.
An Ingress resource needs an Ingress controller. For new designs, also evaluate the Kubernetes Gateway API.
Secret data is base64-encoded, not inherently encrypted. Configure encryption at rest and least-privilege RBAC.
Container filesystems are ephemeral. Stateful data needs an appropriate volume, claim, backup, and lifecycle plan.
Continue learning
The explanations in this app are based on official Kubernetes documentation. Open these for precise behavior and current API guidance.