Kubernetes Explained for Beginners
SkillVeris Team
Cloud & Security Team

Kubernetes is an open-source system that automates deploying, scaling, and managing containerized applications across a cluster of machines.
In this guide, you'll learn:
- It keeps your app running by constantly comparing the actual state to the desired state you declared and fixing any difference.
- A pod is the smallest deployable unit — one or more containers that share networking and storage.
- Deployments manage pods, handling rollouts, scaling, and automatic recovery when a pod dies.
- Services give pods a stable network address and load-balance traffic across them.
1What Is Kubernetes?
Kubernetes is an open-source platform that automates deploying, scaling, and managing containerized applications across a group of machines called a cluster. If Docker packages your app into a container, Kubernetes decides where those containers run, restarts them when they crash, and scales them up or down as demand changes.
Running one container by hand is easy. Running hundreds across many servers, keeping them healthy, updating them without downtime, and balancing traffic between them is not — and that orchestration is exactly the job Kubernetes exists to do.
2Why Use Kubernetes?
As soon as you run containers in production at any scale, manual management becomes impossible. Kubernetes automates the operational work that would otherwise consume a team.
- Self-healing: crashed containers are automatically restarted or rescheduled.
- Scaling: add or remove copies of your app based on load, automatically or on command.
- Rolling updates: deploy new versions gradually with no downtime, and roll back if needed.
- Load balancing: traffic is distributed across healthy instances.
- Portability: the same cluster definitions run on any cloud or on-premises.
🔑Key Takeaway
Kubernetes exists to run containers reliably at scale — restarting failures, spreading load, and rolling out updates automatically, so humans do not have to babysit every server.
3The Core Idea: Desired State
The concept that makes Kubernetes click is declarative desired state. You do not tell Kubernetes how to do things step by step; you declare what you want — 'run three copies of this app' — and Kubernetes works continuously to make reality match that declaration.
This is a control loop: Kubernetes constantly compares the actual state of the cluster to your desired state and takes action to close any gap. If a pod dies and you asked for three, it starts a new one automatically. You manage the what, and the system handles the how.
4Pods: The Smallest Unit
A pod is the smallest thing you can deploy in Kubernetes. It wraps one or more containers that share the same network address and storage, so they behave like a single cohesive unit.
- Usually one main container per pod, sometimes with small helper 'sidecar' containers.
- Containers in a pod share an IP address and can talk over localhost.
- Pods are ephemeral — they are created and destroyed freely, never repaired in place.
- Because pods come and go, you rarely manage them directly; higher-level objects do that.
Why Not Manage Pods Directly
Since pods are disposable, you do not create them one by one in production. Instead you tell a Deployment how many you want, and it creates, replaces, and scales the pods for you. Managing pods directly would mean losing self-healing and rolling updates.
5Deployments: Managing Pods
A Deployment is the object you actually work with most. It describes the desired state for a set of identical pods — which image to run and how many replicas — and manages their entire lifecycle.
- apiVersion: apps/v1
- kind: Deployment
- spec:
- replicas: 3 # run three copies of the app
- template:
- spec:
- containers:
- - name: web
- image: myapp:1.2
💡Pro Tip
To ship a new version, just change the image tag in the Deployment and apply it. Kubernetes performs a rolling update, replacing pods a few at a time so users never see downtime.
6Services: Stable Networking
Because pods are created and destroyed constantly, their IP addresses keep changing. A Service solves this by giving a set of pods a single, stable address and load-balancing traffic across them.
- ClusterIP: an internal address reachable only inside the cluster (the default).
- NodePort: exposes the service on a port of every node, for basic external access.
- LoadBalancer: provisions a cloud load balancer for public traffic.
- Ingress: routes external HTTP traffic to services by hostname and path.
Service Discovery
A Service also provides discovery: other pods can reach it by a stable DNS name rather than a fragile IP. So your web pods can talk to a database Service by name, and Kubernetes routes the traffic to whichever database pods are currently healthy.
7Cluster Architecture in Brief
A Kubernetes cluster has two kinds of machines. The control plane makes decisions; the worker nodes run your containers. You interact with the cluster mainly through the kubectl command-line tool and YAML files.
- Control plane: the API server, scheduler, and controllers that manage the cluster's state.
- Worker nodes: the machines that actually run your pods.
- kubectl: the CLI you use to apply configs and inspect the cluster.
- etcd: the key-value store that holds the cluster's desired and current state.
- Managed options (EKS, GKE, AKS) run the control plane for you.
8Common Mistakes to Avoid
Kubernetes is powerful but easy to misuse, especially early on.
- Reaching for Kubernetes too soon — a small app may be simpler on a single server or a managed platform.
- Not setting resource requests and limits, so pods starve each other or get evicted.
- Skipping health checks (liveness and readiness probes), so Kubernetes cannot tell a hung pod from a healthy one.
- Managing bare pods instead of Deployments, losing self-healing and rollouts.
- Storing secrets in plain YAML committed to Git instead of using Secrets and proper access control.
⚠️Watch Out
Always define liveness and readiness probes. Without them, Kubernetes cannot tell whether a pod is genuinely ready to serve traffic or silently hung, and it may route requests to a broken instance.
9Key Takeaways
The mental model for Kubernetes rests on a few big ideas.
- Kubernetes automates deploying, scaling, and healing containers across a cluster.
- You declare a desired state in YAML and a control loop makes reality match it.
- A pod is the smallest unit; Deployments manage pods and enable rolling updates.
- Services give pods a stable address and load-balance traffic among them.
- Set resource limits and health probes, and prefer Deployments over bare pods.
10Frequently Asked Questions
Q: What is the difference between Docker and Kubernetes? A: Docker packages and runs individual containers, while Kubernetes orchestrates many containers across a cluster of machines. Docker handles the container itself; Kubernetes handles deploying, scaling, healing, and networking those containers in production.
Q: What is a pod in Kubernetes? A: A pod is the smallest deployable unit — one or more containers that share a network address and storage and run together as a unit. Pods are ephemeral, created and destroyed freely, which is why you manage them through Deployments rather than directly.
Q: Do I always need Kubernetes to run containers? A: No. For a small app, a single server running Docker or a managed container platform is often simpler and cheaper. Kubernetes pays off when you need to run many containers reliably at scale with automated healing, scaling, and zero-downtime updates.
Q: What is a Service and why do I need one? A: Because pods come and go and their IP addresses change, a Service gives a stable network address and DNS name to a set of pods and load-balances traffic across them. It lets other components reach your app reliably without tracking individual pod IPs.
Related Reading
Get The Print Version
Download a PDF of this article for offline reading.
About the Publisher
SkillVeris Team
Cloud & Security Team
Our cloud and security experts break down complex infrastructure topics into practical, beginner-friendly guides.
View all postsRelated Posts
Never miss an update
Get the latest tutorials and guides delivered to your inbox.
No spam. Unsubscribe anytime.