Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungWhy Claude Code keeps writing shell commands that fail on your Mac(20.09.2026 um 21:06 Uhr)
Sichere Programmierungllms.txt v2: What the Spec Says, and What 137,000 Domains Show(20.09.2026 um 21:17 Uhr)
Sicherheitslücken (CVE)NiceTryGPT: Less pattern matching. More actual hacking.(20.09.2026 um 21:19 Uhr)
IT Security VideoActivities BoF (kde2026)(20.09.2026 um 00:00 Uhr)
IT Security Toolsirdoc-app(20.09.2026 um 20:33 Uhr)
Sichere ProgrammierungWhy Claude Code keeps writing shell commands that fail on your Mac(20.09.2026 um 21:06 Uhr)
Sichere Programmierungllms.txt v2: What the Spec Says, and What 137,000 Domains Show(20.09.2026 um 21:17 Uhr)
Sicherheitslücken (CVE)NiceTryGPT: Less pattern matching. More actual hacking.(20.09.2026 um 21:19 Uhr)
IT Security VideoActivities BoF (kde2026)(20.09.2026 um 00:00 Uhr)
IT Security Toolsirdoc-app(20.09.2026 um 20:33 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

🤔 What Really Happens When You Run kubectl apply? Episode 3

Reagiere als Erste:r — dein Feedback zählt!

Follow the complete journey of a Kubernetes Deployment—from your terminal to a running container inside the cluster.

Most Kubernetes tutorials teach us how to create resources:

kubectl apply -f deployment.yaml

A few seconds later, Pods start running.

Simple, right?

But Kubernetes is doing far more work than most people realize.

Hola Amigos! Welcome to the third episode of K8s with Pravesh. Today, we're going to dive into the lifecycle of one of the most commonly used Kubernetes commands: kubectl apply.

Behind this simple command lies a chain of events involving the API Server, ETCD, Controller Manager, Scheduler, Kubelet, and Container Runtime.

Understanding this workflow is one of the biggest steps toward becoming a better Kubernetes engineer. In this article, we'll trace every step that occurs after running kubectl apply and see how Kubernetes transforms a YAML file into a running application.

So, without further ado, let's get started.

How Does the Information Flow?

Before we dive deep, let's first get ourselves familiar with kubectl.

kubectl is the command-line tool that helps us interact with a Kubernetes cluster. Whenever a user runs:

kubectl apply -f deployment.yaml

the YAML file is sent to the API Server, which acts as the front door of Kubernetes.

The API Server authenticates the request, validates the manifest, and processes Kubernetes objects such as Deployments, Services, Pods, ReplicaSets, and many others.

Once the API Server has the YAML, you might wonder:

"Does Kubernetes create the Pods immediately?"

The answer is No.

Instead of creating Pods right away, Kubernetes first stores the desired state of the resources inside ETCD.

ETCD acts as the primary database—and often the "brain"—of the Kubernetes cluster. Just like in GitOps, where Git serves as the single source of truth, ETCD is the single source of truth for the cluster. It stores the complete cluster state, configuration data, and metadata.

Now you might be wondering:

"Okay, the data is stored in ETCD... but who reads it?"

This is where the Controller Manager comes into the picture.

The Controller Manager is one of the core control plane components. It continuously watches the desired state stored in ETCD and compares it with the current state of the cluster. Whenever it detects a difference, it takes action to reconcile them.

This reconciliation loop is also what enables Kubernetes' self-healing capabilities. For example, if a Pod crashes unexpectedly, the Controller Manager notices the mismatch and automatically creates a replacement Pod to restore the desired state.

Inside our manifest, we only created a Deployment. We never explicitly created a ReplicaSet.

Kubernetes takes care of that for us.

The Deployment Controller automatically creates a ReplicaSet, and the ReplicaSet Controller ensures that the desired number of Pods are always running.

Now comes another important question:

"We have the Pods ready, but who decides where they'll run?"

This is the job of the Scheduler.

The Scheduler is responsible for assigning pending Pods to the most suitable node in the cluster.

It does this in two stages:

  • Filtering – Removes nodes that don't satisfy the Pod's requirements, such as available resources, taints, tolerations, affinity, or node selectors.
  • Scoring – Evaluates the remaining nodes and selects the best one based on Kubernetes' scheduling algorithms.

Once the Scheduler selects a node, the Kubelet—the primary node agent running on every worker node—takes over.

The Kubelet watches the API Server for Pods assigned to its node. Once it receives the instruction, it communicates with the container runtime (such as containerd) and ensures that the desired state is achieved.

Finally, the container runtime pulls the required container image (if it isn't already available), creates the container, and starts it.

And that's how a simple kubectl apply command works under the hood.

Kubernetes Is Not Magic

When beginners first start learning Kubernetes, it almost feels like magic.

kubectl apply -f deployment.yaml

...and boom! Your application is up and running in no time.

But in reality, Kubernetes is a collection of specialized components working together through a continuous reconciliation process.

Every component has a specific responsibility:

  • API Server accepts and validates requests.
  • ETCD stores the cluster state.
  • Controller Manager reconciles the desired and current state.
  • Scheduler selects the best node for Pods.
  • Kubelet manages workloads on each node.
  • Container Runtime pulls images and runs containers.

Once you understand this flow, troubleshooting Kubernetes becomes much less stressful because you know exactly where to look when something breaks.

Conclusion

And that's the journey of a simple kubectl apply command.

What looks like a single command from our terminal is actually a well-orchestrated sequence of events involving multiple Kubernetes components, each doing one specific job. This separation of responsibilities is what makes Kubernetes powerful, scalable, and resilient.

I hope this article helped you understand not just what Kubernetes does, but how it does it behind the scenes.

This is just the beginning of our Kubernetes Internals journey. In the upcoming articles, we'll dive deeper into individual components like the API Server, ETCD, Scheduler, Kubelet, and many more to understand how they work under the hood.

If you enjoyed this article, consider following me on my socials, where I regularly share content around Kubernetes, AWS, DevOps, and Cloud Engineering.

See you in the next episode of K8s with Pravesh. 🚀

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten 🤔 What Really Happens When You Run kubectl apply? Episode 3

Thematisch verwandte Begriffe: What, Really, Happens, When · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick