The Apollo11 Kubernetes Glossary
This glossary provides beginner-friendly, technically exact definitions of all Kubernetes terminology used throughout the Apollo Airlines platform, cross-referenced with the stage where each concept is introduced.
C
Cluster
A set of physical or virtual worker machines (nodes) that run containerized applications managed by a control plane. (Introduced in Ignition)
ClusterIP
The default Kubernetes Service type. Allocates an internal, virtual IP address reachable only from within the cluster. (Introduced in Stage 1, expanded in Stage 2)
ConfigMap
An API object used to store non-confidential configuration data in key-value pairs. Pods can consume ConfigMaps as environment variables, command-line arguments, or mounted configuration files. (Introduced in Stage 1)
Container
An isolated Linux process running directly on the host operating system kernel, constrained by namespaces (for process and network isolation) and cgroups (for CPU and memory limits). (Introduced in Launchpad)
Control Plane
The collection of master processes (kube-apiserver, etcd, kube-scheduler, kube-controller-manager) that control, schedule, and maintain desired cluster state. (Introduced in Ignition)
CoreDNS
The internal DNS server running in the cluster that automatically resolves Service names to virtual ClusterIPs (e.g. booking.apollo-airlines-apps.svc.cluster.local). (Introduced in Stage 2)
CRD (Custom Resource Definition)
An extension mechanism that lets developers define custom API resource types in Kubernetes beyond built-in objects like Pods and Deployments. (Introduced in Stage 6 with ServiceMonitors; expanded in Stage 11)
D
DaemonSet
A controller that ensures a copy of a specific Pod runs on all (or selected) worker nodes. Used for system infrastructure like log collection (Alloy), monitoring agents (Node Exporter), and network proxies. (Introduced in Stage 6)
Deployment
A declarative controller that manages the creation, scaling, and rolling updates of identical, stateless Pods via ReplicaSets. (Introduced in Stage 1)
Desired State vs. Observed State
The core philosophy of Kubernetes: You declare your desired state in YAML (e.g. "run 3 replicas of booking"). The controller continuously monitors the observed state (e.g. "only 2 are running") and executes actions to align observed state with desired state (Reconciliation). (Introduced in Ignition)
E
emptyDir
An ephemeral volume created when a Pod is assigned to a node and deleted when the Pod terminates. Useful for scratch space and temporary buffers, but unsuitable for database persistence. (Introduced in Stage 1)
Endpoints & EndpointSlice
Kubernetes objects dynamically generated by the EndpointSlice controller that track the real, live IP addresses and ports of healthy Pods matching a Service's label selector. (Introduced in Stage 2)
Envoy Gateway
An open-source Gateway API implementation powered by the Envoy proxy. In the verified Apollo11 local path, it is the canonical Layer 7 routing edge; that does not alone make the local cluster production-ready. (Introduced in Stage 2)
etcd
The consistent, distributed key-value store used as Kubernetes' backing database for all cluster state and metadata. (Introduced in Ignition)
Eviction API
An API endpoint used by administrators or controllers (kubectl drain, Karpenter) to voluntarily terminate Pods in an orderly fashion while respecting PodDisruptionBudgets. (Introduced in Stage 4)
G
Gateway API
The modern official Kubernetes networking standard that replaces the legacy Ingress API. Separates routing into GatewayClass (infrastructure implementation), Gateway (listener configuration), HTTPRoute (routing rules), and ReferenceGrant (cross-namespace security). (Introduced in Stage 2)
GitOps
An operational pattern where Git repositories serve as the single source of truth for declared infrastructure and application configuration, automated by tools like Argo CD. (Introduced in Stage 5)
Guaranteed QoS
The highest Quality of Service class in Kubernetes, achieved when a container sets requests == limits for both CPU and memory. Guaranteed Pods are given the highest eviction resistance under node memory starvation. (Introduced in Stage 4)
H
Headless Service
A Service with clusterIP: None. Instead of returning a single load-balanced virtual IP, CoreDNS returns direct DNS A-records for backing Pods. Required by StatefulSets for predictable per-pod network identity. (Introduced in Stage 3)
Helm
The package manager for Kubernetes. Packages related YAML templates into versioned Charts, parameterizes them with values.yaml, and tracks release revision histories. (Introduced in Stage 5)
Horizontal Pod Autoscaler (HPA)
A controller that automatically scales the replica count of a Deployment based on observed CPU utilization, memory, or custom metrics. (Introduced in Stage 7)
HTTPRoute
A Gateway API resource that specifies routing rules (hostnames, path prefixes, headers) and forwards traffic to backend Kubernetes Services. (Introduced in Stage 2)
I
Ingress
A legacy Kubernetes API object that manages external HTTP/HTTPS access to cluster services, typically using host and path-based routing rules. (Introduced in Stage 2)
J
Job
A controller that runs a finite task to completion (e.g. database schema migrations or batch reports) and terminates, contrasting with Deployments which run indefinitely. (Introduced in Stage 1)
K
kind (Kubernetes in Docker)
A tool for running local multi-node Kubernetes clusters where each cluster node is simulated by a Docker container. (Introduced in Ignition)
kubelet
The primary agent that runs on every node in the cluster. It receives Pod specifications from the API server, ensures containers are running via the container runtime, executes health probes, and restarts failed processes. (Introduced in Ignition)
kube-proxy
A network daemon running on each node that configures host packet filtering rules (iptables or IPVS) to implement virtual Service routing. (Introduced in Ignition)
Kustomize
A template-free declarative configuration customization tool built directly into kubectl (kubectl apply -k). Composes shared base manifests with environment-specific overlays and patches. (Introduced in Stage 5)
L
Labels and Selectors
Key-value pairs attached to objects (labels) and queried by controllers and Services (selectors) to establish dynamic ownership and routing contracts. (Introduced in Stage 1)
Liveness Probe
A health check probe run periodically by the kubelet. If it fails, the kubelet kills and restarts the container. (Introduced in Stage 4)
LoadBalancer Service
A Service type that requests an external load-balancer address. A controller must fulfil that request: Apollo11's local kind path uses MetalLB, while cloud behaviour depends on the installed provider integration. (Introduced in Stage 2)
M
MetalLB
A bare-metal load-balancer implementation for Kubernetes that provides Layer 2 (ARP) network address allocation for type: LoadBalancer Services in non-cloud environments. (Introduced in Stage 2)
N
Namespace
A virtual cluster mechanism used to organize, group, and isolate resources, quotas, and access control policies within a single physical cluster. (Introduced in Stage 1)
NetworkPolicy
An API specification that acts as an in-cluster firewall, controlling ingress and egress network traffic between Pods based on label selectors and CIDRs. Requires a CNI like Calico. (Introduced in Stage 2, roadmap in Stage 8)
NodePort
A Service type that exposes an application on a high port (30000–32767) across every node in the cluster. (Introduced in Stage 1, expanded in Stage 2)
O
OOMKilled (Exit Code 137)
An event where the Linux kernel Out-Of-Memory killer abruptly terminates a container process because its physical memory usage exceeded its declared resources.limits.memory. (Introduced in Stage 4)
OpenTelemetry (OTel)
A vendor-neutral observability framework providing standardized APIs, SDKs, and tooling to generate and export distributed traces, metrics, and logs. (Introduced in Stage 6)
P
PersistentVolume (PV) & PersistentVolumeClaim (PVC)
- PVC: An application's claim/request for persistent storage.
- PV: A piece of storage in the cluster provisioned statically by an admin or dynamically by a StorageClass. (Introduced in Stage 3)
Pod
The atomic scheduling unit in Kubernetes consisting of one or more co-located containers sharing a network namespace, IP, and storage volumes. (Introduced in Ignition)
PodDisruptionBudget (PDB)
A policy that limits the number of replicas of a workload that can be simultaneously unavailable during voluntary disruptions (e.g. node drains or cluster upgrades). (Introduced in Stage 4)
preStop Hook
A lifecycle command executed by the kubelet inside a container before sending
the SIGTERM termination signal. Apollo11 uses a short delay to give endpoint
and proxy updates time to propagate; it reduces rather than guarantees the
elimination of traffic races. (Introduced in Stage 4)
PriorityClass
A cluster-scoped object that defines numerical scheduling priorities. High-priority pods can preempt (evict) lower-priority pods when a node runs out of resources. (Introduced in Stage 4)
R
Readiness Probe
A health check probe run periodically by the kubelet. If it fails, Kubernetes removes the Pod from Service endpoints, stopping traffic without killing the process. (Introduced in Launchpad conceptually, Kubernetes in Stage 4)
ReferenceGrant
A Gateway API security resource in a target namespace that explicitly authorizes routes from another namespace to bind to its Services. (Introduced in Stage 2)
ReplicaSet
A controller that maintains a stable number of identical running Pods matching a label selector at all times. (Introduced in Stage 1)
Rolling Update
A Deployment strategy that incrementally replaces old Pod instances with new
Pod instances, subject to maxSurge, maxUnavailable, readiness, and available
capacity. It can reduce disruption but is not an unconditional no-downtime
guarantee. (Introduced in Stage 1)
S
Secret
A Kubernetes API object designed to store sensitive data (passwords, tokens, keys). Base64-encoded by default. (Introduced in Stage 1)
Service
An abstract API object that defines a logical set of Pods and a policy by which to access them (via a stable virtual IP and DNS name). (Introduced in Stage 1)
ServiceAccount
An identity attached to a Pod providing authentication credentials for interacting with the Kubernetes API server. Token automount can be disabled for least-privilege security. (Introduced in Stage 1)
Startup Probe
A probe that checks whether an application has finished its initial boot process. Suspends liveness and readiness checks until it passes. (Introduced in Stage 4)
StatefulSet
A controller designed for stateful applications (databases, clustered stores) requiring stable unique network identities (app-0), ordered deployments, and persistent dedicated storage. (Introduced in Stage 3)
StorageClass
A Kubernetes object describing the provisioner, parameters, and volume binding mode (WaitForFirstConsumer) used to dynamically create PersistentVolumes. (Introduced in Stage 3)
T
Taints and Tolerations
- Taint: A node attribute that repels Pods.
- Toleration: A Pod attribute that permits the Pod to schedule onto a tainted node. (Introduced in Stage 7)
Topology Spread Constraints
A Pod specification field (topologySpreadConstraints) that directs the scheduler to distribute replicas evenly across failure domains (nodes, availability zones). (Introduced in Stage 4)
V
Vertical Pod Autoscaler (VPA)
A controller that analyzes historical resource usage of Pods and recommends or automatically adjusts CPU and memory requests and limits. (Introduced in Stage 7)
VolumeClaimTemplate
A template embedded in a StatefulSet manifest that automatically generates a unique, persistent PVC for each ordinal replica. (Introduced in Stage 3)