Concept and mechanism
The API server exposes the cluster API; controllers reconcile state and the scheduler chooses nodes for eligible Pods. The kubelet operates on a node and coordinates execution through the runtime. These responsibilities help locate failures without reinstalling everything. Before any operation, confirm context, identity, and namespace in kubeconfig. Two clusters may contain identically named namespaces. During kubeadm bootstrap, Pod networking needs a compatible plugin; CNI, CRI, and CSI represent interfaces with different networking, runtime, and storage roles. An API object’s creation does not prove all these integrations work.
Guided application
For high availability, prepare a stable API endpoint and a topology capable of surviving expected failures. kubeadm upgrades follow consecutive minor versions and the documented control-plane and worker sequence. Plan recovery evidence, compatibility, and change-stop criteria. Cordon prevents normal new scheduling but does not evacuate workloads. Drain attempts evacuation while respecting mechanisms such as PodDisruptionBudgets. If a budget blocks the operation, investigate healthy replicas and capacity before forcing disruption. Finally, validate node and service conditions before returning it to normal use.
In a lab, start with kubectl config current-context and kubectl --context=lab get nodes. Explain why these results should precede a maintenance operation. Commands are reading examples and were not executed against a cluster by DR.
Common pitfalls
Confusing context with directory; repeating init to solve missing CNI; skipping minor versions; ignoring a PDB to meet the schedule.
Related topics: Access, tools, and extensions · Workloads, configuration, and scheduling
Confirm destination, dependencies, and operational headroom before the change.
Reference: Upgrade kubeadm clusters · CKA Kubernetes v1.35