Kubernetes definition
Kubernetes is an open-source system for automating the deployment, scaling and management of containerized applications across clusters of machines. Originally designed at Google and released in 2014, it is maintained by the Cloud Native Computing Foundation and offered as a managed service by every major cloud, including Amazon EKS, Azure AKS and Google GKE.
How does Kubernetes work?
A Kubernetes cluster has a control plane and worker nodes. The control plane includes the API server that every tool talks to, etcd as the store of cluster state, a scheduler that places workloads on nodes and controllers that keep things running. Each worker node runs a kubelet agent and a container runtime that start and monitor containers, plus networking components that route traffic between them.
You describe the desired state declaratively, usually in YAML: run three replicas of this image, expose them on port 8080, give each 512 MB of memory. Controllers continuously compare the actual state with the desired state and fix differences. If a node fails, its pods are rescheduled elsewhere. If you change the image version, Kubernetes performs a rolling update, replacing pods gradually and stopping if the new ones fail health checks.
Core Kubernetes objects
- Pod: the smallest unit, one or more containers sharing network and storage.
- Deployment: manages replicated, stateless pods and rolling updates.
- StatefulSet: runs stateful workloads that need stable identity and storage.
- Service: a stable network address and load balancing for a set of pods.
- Gateway API, and the older, feature-frozen Ingress: route external HTTP traffic into the cluster.
- ConfigMap and Secret: configuration and sensitive values injected into pods.
- HorizontalPodAutoscaler: scales pods based on CPU, memory or custom metrics.
- Job and CronJob: batch and scheduled tasks.
The Kubernetes ecosystem
Kubernetes is a foundation, and most production clusters add tools around it. Helm and Kustomize package and customize manifests. Argo CD and Flux apply GitOps, deploying whatever is committed to a Git repository. Prometheus and Grafana handle metrics and dashboards, cert-manager automates TLS certificates, and service meshes such as Istio and Linkerd add encryption and traffic control between services. Cluster Autoscaler and Karpenter add or remove nodes to match demand.
When Kubernetes is worth it, and when it is not
Kubernetes pays off when an organization runs many services, has several teams deploying independently, needs portability across clouds or on-premises, or wants one consistent platform for diverse workloads. Its declarative model, self-healing and ecosystem are hard to match at that scale.
For a small team with a few services, it is often more platform than needed. Upgrades, networking, security policies and cost management require ongoing expertise. A PaaS, serverless containers such as Cloud Run or AWS Fargate, or Amazon ECS can deliver the same outcomes with far less operational work until scale demands more.
Running Kubernetes well
Use a managed service such as EKS, AKS or GKE rather than running the control plane yourself, unless there is a strong reason. Set resource requests and limits on every workload, use namespaces and role-based access control to separate teams, apply network policies, keep the cluster version current and manage everything through Git. Nexzem builds and operates Kubernetes platforms with these guardrails in place, along with cost visibility per team and namespace.