⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 4 — Advanced / Mastery Module 20 of 24 Free & Open Access

CRDs & Custom Controllers/Operators

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

20 - CRDs & Custom Controllers/Operators

Why this matters

This is the single best exercise for truly understanding the Kubernetes API machinery. Once you've written a controller, every built-in resource (Deployment, Service, etc.) stops being magic — they're all just controllers watching an API and reconciling state.

Read this first — Definitions & Explanations

CRD (CustomResourceDefinition)

Extends the Kubernetes API with your own resource types (CronTab, PostgresCluster, etc.). After installing a CRD, you can kubectl get <your-kind>.

Custom Resource (CR)

An instance of a CRD — an object stored in etcd via the API server like native resources.

Operator pattern

A controller that encodes operational knowledge: watch CRs, reconcile complex apps (create StatefulSets, backups, failovers). “Kubernetes-native automation” for a specific software system.

Why operators exist

YAML alone can’t capture day-2 operations. Operators continuously maintain desired complex state.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

# First, just use one to see the pattern from the outside
kubectl apply -f https://raw.githubusercontent.com/cert-manager/cert-manager/master/deploy/crds/crd-certificates.yaml
kubectl get crd | grep cert-manager

# Now build your own minimal operator with kubebuilder
brew install kubebuilder
mkdir ~/dev/website-operator && cd ~/dev/website-operator
kubebuilder init --domain example.com --repo example.com/website-operator
kubebuilder create api --group web --version v1 --kind Website --resource --controller

# Edit api/v1/website_types.go: add a Spec field like `Replicas int32` and `Image string`
# Edit controllers/website_controller.go Reconcile(): make it create/update a Deployment
# matching Spec.Replicas / Spec.Image whenever a Website CR changes.
# (Full walkthrough: https://book.kubebuilder.io/cronjob-tutorial/cronjob-tutorial.html
#  — the CronJob tutorial in the kubebuilder book is the canonical hands-on guide, do that one first)

make manifests install run   # runs your controller locally against prod-sim's API server

# In another terminal, create a CR and watch your controller react
cat <<EOF | kubectl apply -f -
apiVersion: web.example.com/v1
kind: Website
metadata:
  name: my-site
spec:
  replicas: 2
  image: nginx:1.27
EOF
kubectl get deployments   # should see one your controller created
kubectl get website my-site -o yaml

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 20 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: A CRD allows you to:
  • A. Extend the Kubernetes API with custom resources
  • B. Replace the scheduler
  • C. Disable etcd
  • D. Create Nodes automatically from Docker
✓ Correct Answer: A (Extend the Kubernetes API with custom resources)
Option A ('Extend the Kubernetes API with custom resources') is the standard production architectural best practice.
Question 2: An Operator typically:
  • A. Encodes operational knowledge to manage an app via controllers
  • B. Only stores YAML in git
  • C. Replaces CNI
  • D. Is a type of PersistentVolume
✓ Correct Answer: A (Encodes operational knowledge to manage an app via controllers)
Option A ('Encodes operational knowledge to manage an app via controllers') is the standard production architectural best practice.
Question 3: Custom resources are stored:
  • A. In etcd via the API server like other objects
  • B. Only on local disk of kubectl
  • C. Only in Helm cache
  • D. Only in Prometheus
✓ Correct Answer: A (In etcd via the API server like other objects)
Option A ('In etcd via the API server like other objects') is the standard production architectural best practice.
Question 4: controller reconcile for CRs follows:
  • A. desired vs actual state loops
  • B. One-shot scripts only
  • C. Manual SSH only
  • D. DNS round-robin
✓ Correct Answer: A (desired vs actual state loops)
Option A ('desired vs actual state loops') is the standard production architectural best practice.
Question 5: Installing an Operator often includes:
  • A. CRDs + controller Deployment/RBAC
  • B. Only a ConfigMap
  • C. Only a NodePort
  • D. Deleting kube-system
✓ Correct Answer: A (CRDs + controller Deployment/RBAC)
Option A ('CRDs + controller Deployment/RBAC') is the standard production architectural best practice.
← Previous Module (19) Runtime & Network Security Next Module (21) → GitOps (ArgoCD/Flux)