24장. Kubernetes Pod
kubectl get/describe/logs --previous, events, container state, restart reason, resource request/limit, probe를 본다. CrashLoopBackOff는 원인이 아니라 반복 상태다. OOMKilled, config, secret mount, permission, dependency를 좁힌다.
ephemeral debug container와 exec는 권한·감사 하에 쓴다. production image에 무조건 shell을 넣지 않는다. pod 내부 DNS·route·TLS를 확인하되 secret을 출력하지 않는다.
liveness는 교착 복구, readiness는 traffic 수신 가능, startup은 긴 초기화를 위한 것이다. 잘못된 liveness가 장애를 증폭한다.