← CKAD: Kubernetes applications in production
01 / 7 · 24 MIN

Reproducible images and finite work

Choose artifacts and controllers according to the work lifecycle.

Concept and mechanism

An image should contain what the application needs at runtime. In a multi-stage build, one stage can compile while another receives only the artifact and runtime dependencies. Deleting tools in a later layer does not remove data from earlier layers. To reproduce a release, record its approved digest: a tag can change content. The digest identifies the artifact but does not prove it was tested or is secure. Approval evidence, configuration, and dependencies should accompany promotion between environments.

Guided application

Choose a Deployment for an ongoing service and a Job for work that finishes. A CronJob adds scheduling, with decisions about concurrency and missed runs. In a reconciliation batch, Forbid can prevent overlapping Jobs from the same CronJob but does not guarantee each posting happens only once. The application should recognize repeated work and retain enough state to reconcile results after retries. Before production handover, define how to observe success, failure, delay, and partial effects, including who decides to reprocess a file.

IN PRACTICE

A batch scheduled every five minutes takes eight. Discuss Forbid, per-file identifier idempotency, and an alert when execution misses the business window.

Common pitfalls

Treating latest as approval; confusing a Job with exactly-once execution; using Replace without handling already-produced effects.

Related topics: Init containers, sharing, and persistence · Deployments and recovery

Take this idea with you

The artifact needs an identity and the work needs an explicit lifecycle.

Create account

Reference: Multi-stage container builds · CKAD Kubernetes v1.35