Project challenges / verified progress
Beacon: give it somewhere to live

The engineering notebook

Trust the loop

What changes when software is run by a control loop instead of a person?

Loading statusStage 1 of 10

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Phase 1 — Learn the control plane

Step 01 of 06

Learn the concept

A container image in a registry is an artifact, not a service. It does not restart itself, find a machine, receive traffic or explain why it failed. Kubernetes is the machinery that tries to make those promises true — and charges you in nouns.

DECLARE, OBSERVE, RECONCILE01Desired stateobjects in the API02Observed statewhat nodes report03Controllercloses the gap04Statustruth written back
Kubernetes is not a command runner. You write desired state to the API server; controllers compare that state with the cluster and keep nudging reality back into shape.
Step 01

The ideas this is made of

The API server is the source of truth

In Kubernetes, the object stored in the API server is the contract. A Deployment, Service or ConfigMap is not a script that runs once; it is desired state that remains available for every controller to read. kubectl apply writes that desired state. The API server validates it, stores it in etcd, and later records status reported by controllers and nodes.

Controllers make declarations true

A controller is a loop: list objects, watch for changes, compare desired state with observed state, then act. The Deployment controller creates ReplicaSets. The ReplicaSet controller creates Pods. The endpoint controller updates Service backends. This is reconciliation. It is deliberately boring, which is exactly what you want after midnight.

Declarative beats imperative when humans leave

An imperative command says, run this container now. A declarative object says, there should be three healthy copies of this container. The second form survives restarts, failed nodes and missed terminals. It also costs you ceremony: YAML, labels, status fields and controllers you must learn to interrogate.

Orchestration trades simplicity for repair

A single docker run is easier to understand than a cluster. It also has one process, one machine and one tired owner. Kubernetes buys placement, rollout, restart, service discovery and policy. The price is a new failure surface: unschedulable pods, broken selectors, bad probes, stale configuration and RBAC denial.

A thermostat is a control loop
desired: 21 C
observed: 18 C
action: heat
observed: 21 C
action: stop heating

Nobody holds a switch until the room is warm. The thermostat keeps comparing measured temperature with desired temperature. Kubernetes does the same with pods, endpoints and volumes, except the room sometimes says ImagePullBackOff.

Imperative and declarative operations

QuestionImperativeDeclarative

What you say

Start this now

Keep this true

Common tool

docker run

kubectl apply

After failure

Human repeats it

Controller repairs it

Stored where

Shell history, maybe

Kubernetes API

Debug focus

The command output

Object status and events

What these are called on the job

  • Desired state — The object spec you submit to the Kubernetes API.

  • Observed state — What controllers and nodes report is actually happening.

  • Reconciliation — Repeatedly closing the gap between desired and observed state.

  • Controller — A process that watches the API and takes action for one kind of object.