Concept and mechanism
A container can fail before application code runs. In GKE Standard without an imagePullSecret, a 403 fetching a private image points toward node identity and repository authorization after existence and connectivity are confirmed. Pod Workload Identity serves another purpose and does not automatically fix image pulls. When Pods are Pending for lack of capacity, distinguish replicas from nodes: HPA changes replicas while cluster autoscaler evaluates node growth within conditions and limits. Check requests and scheduling constraints before increasing any limit. Adding nodes does not resolve a constraint that the available configuration cannot satisfy.
Guided application
For Cloud Run releases, keep an earlier revision usable while observing new-revision traffic. Reverting traffic is valid recovery only if the old application remains compatible with data and dependencies. To remove the effects of an unwanted logical write in Cloud SQL MySQL, configured PITR permits recovery into another instance; plan validation, endpoint handling, and reconciliation of later work. Measure RTO through validated service and RPO from the actual recovered point. A drill from 08:00 to 08:38 with data through 07:56 and no replay gives 38 minutes of recovery and a four-minute data gap. With objectives of 40 and three, only the first is met.
A recovery report includes data state, functional validation, duration, dependencies, and the cutover decision; “instance created” is only an intermediate milestone.
Common pitfalls
Pod identity confused with node identity; HPA confused with nodes; traffic rollback treated as schema rollback; HA confused with PITR; lifecycle treated as immediate deletion.
Related topics: Observability, log delivery, and evidence · IAM, inheritance, and privilege boundaries
Diagnose by stage and validate the complete service after mitigation.
Reference: Cloud SQL MySQL PITR · Standard exam guide linked 2026-09-29; edition date unconfirmed