Robots Atlas>ROBOTS ATLAS
Infrastructure

K8s

2014ActivePublished: 1 October 2026Updated: 1 October 2026Published
Key innovation
Declarative, self-healing container orchestration: users describe the desired application state and control loops continuously reconcile the cluster's actual state toward it, decoupling deployments from individual machines.
Category
Infrastructure
Abstraction level
System
Operation level
OrchestrationDeploymentServing
Use cases
Microservice orchestrationMLOps platforms and AI model serving (KServe, Kubeflow)Autoscaling of web applicationsBatch processing and GPU-based ML jobsMulti-cloud and hybrid deploymentsManaging fleets of AI agents

How it works

A Kubernetes cluster consists of a control plane and worker nodes. A user submits a declarative description of the desired state (e.g. a Deployment manifest specifying a replica count) to the API server. The API server persists this state in the distributed key-value store etcd. The scheduler assigns pods to nodes based on resources and constraints, and the controller manager runs control loops that compare the actual state with the desired state and take corrective action. On each node, the kubelet agent starts and supervises containers through a (CRI-compliant) container runtime, while kube-proxy maintains network rules and load-balances traffic to Services.

Problem solved

Manually deploying and operating many containers across a fleet of servers is error-prone and scales poorly. Kubernetes solves scheduling containers onto available nodes, automatically restarting and replacing failures, scaling in response to load, and managing configuration declaratively and consistently across distributed and multi-cloud environments.

Components

API server (kube-apiserver)Control plane

The cluster's central entry point, exposing the Kubernetes REST API. It validates and processes requests and is the only component that talks directly to etcd.

etcdControl plane

A distributed, consistent key-value store that holds the entire cluster state and configuration; it is the source of truth for the desired state.

Scheduler (kube-scheduler)Control plane

Assigns newly created pods to nodes based on available resources, affinity constraints, tolerations, and other rules.

Controller manager (kube-controller-manager)Control plane

Runs control loops (controllers) that observe cluster state and reconcile the actual state toward the desired state, e.g. maintaining a target replica count.

kubeletWorker node

An agent that runs on each node; it accepts pod specifications from the API server and ensures the described containers are running and healthy.

kube-proxyWorker node

Maintains network rules on nodes, enabling network communication to pods and load-balancing of traffic to Services.

Container runtimeWorker node

The software responsible for running containers (e.g. containerd, CRI-O), communicating with the kubelet through the CRI interface.

PodWorkload object

The smallest deployable unit in Kubernetes: one or more containers that share networking and storage and are scheduled and run together.

DeploymentWorkload object

An object that declaratively manages a set of pod replicas, handling rolling updates and rollbacks.

ServiceNetworking object

A stable network abstraction (fixed address and DNS name) that provides access and load-balancing to a dynamically changing set of pods.

Implementation

Implementation pitfalls
Missing resource requests and limitsHigh

Pods without defined requests/limits can be poorly scheduled and cause node resource exhaustion and evictions.

Fix:Define resources.requests and resources.limits and apply ResourceQuota and LimitRange at the namespace level.
Improper etcd operationsCritical

etcd holds the entire cluster state; lack of backups or overload leads to data loss or control-plane instability.

Fix:Take regular etcd snapshots, monitor latency, and run etcd in a high-availability configuration.
Overly broad permissions (RBAC) and default settingsHigh

Overly broad RBAC roles, privileged containers, and absent NetworkPolicies increase the cluster's attack surface.

Fix:Apply least-privilege RBAC, restrict container privileges, and enforce NetworkPolicies.

Evolution

Original paper · 2015 · EuroSys 2015 · Abhishek Verma
Large-scale cluster management at Google with Borg
Abhishek Verma, Luis Pedrosa, Madhukar R. Korupolu, David Oppenheimer, Eric Tune, John Wilkes
2014
Google announces Kubernetes and open-sources it
Inflection point

On 6 June 2014 Google announces Kubernetes, a project rooted in experience with the internal Borg system.

2015
Publication of the Borg paper

The paper "Large-scale cluster management at Google with Borg" (EuroSys 2015) documents the system that inspired Kubernetes.

2015
Version 1.0 release and donation to CNCF
Inflection point

On 21 July 2015 Kubernetes 1.0 is released; the project becomes the seed technology of the newly formed Cloud Native Computing Foundation (CNCF).

Hyperparameters (configurable axes)

Replica countHigh

The desired number of identical pod instances maintained by a Deployment/ReplicaSet.

Resource requests and limitsCritical

Declared CPU/memory requests and upper limits for containers, affecting scheduling and node stability.

Horizontal autoscalingMedium

Rules for automatically changing the replica count based on metrics (e.g. CPU usage or custom metrics).

Update strategyMedium

How new versions are rolled out (e.g. RollingUpdate vs Recreate) and the maxSurge/maxUnavailable parameters.

Execution paradigm

Primary mode
Conditional

Kubernetes is not a neural-network architecture; the execution-paradigm fields describe its control model (state-reactive control loops), not an ML compute flow.

Activation pattern
Input dependent
Routing mechanism

The scheduler routes pods to specific nodes, and controllers (reconciliation loops) conditionally take corrective action depending on the gap between desired and actual state.

Hardware requirements

Primary

Kubernetes orchestrates containers independently of the compute layer; it runs on CPUs and exposes accelerators (GPU/TPU) to nodes via device plugins.