Part 2 — Build the platform · wrap-up
Cheat sheet & self-check
30 questions across 8 lessons. Each answer links back to the lesson it came from.
Pick an answer to see if you got it, and why.
Q1. Why is a /24 VPC usually a mistake for EKS?
Show answer
B. Pods consume VPC addresses. Size the VPC (and plan a secondary pod CIDR) for the pod count, not the node count.
From lesson 03 · AWS account & VPC for EKSQ2. Which subnet tag makes the AWS Load Balancer Controller place an internet-facing ALB in a subnet?
Show answer
B. Public subnets get kubernetes.io/role/elb=1, private subnets kubernetes.io/role/internal-elb=1, so the controller can discover them automatically.
From lesson 03 · AWS account & VPC for EKSQ3. What's the main reason to add VPC endpoints for ECR, S3 and STS?
Show answer
B. Endpoints remove NAT data charges for heavy traffic like image pulls and let nodes in isolated subnets reach AWS services.
From lesson 03 · AWS account & VPC for EKSQ4. One NAT gateway per AZ or a single shared one?
Show answer
B. Per-AZ NAT keeps each AZ independent. A single NAT is fine for dev to save cost.
From lesson 03 · AWS account & VPC for EKSQ5. Pods are Pending with 'failed to assign an IP address to container', but nodes have spare CPU. Likely cause?
Show answer
B. With the VPC CNI every pod needs a VPC IP. Either the instance's ENI capacity or the subnet itself is exhausted.
From lesson 04 · VPC CNI & IP planningQ6. What does prefix delegation change?
Show answer
B. Nitro instances can attach prefixes to ENIs. Many more pods fit per node, but subnets need free, contiguous /28 blocks.
From lesson 04 · VPC CNI & IP planningQ7. Why put pods in a secondary CIDR such as 100.64.0.0/16?
Show answer
B. The 100.64.0.0/10 range (reserved for carrier-grade NAT) is commonly used for pod subnets; pods reach other networks through the nodes' addresses.
From lesson 04 · VPC CNI & IP planningQ8. Your security team wants the Kubernetes API unreachable from the internet. What do you configure?
Show answer
B. Endpoint access is a cluster setting. With only private access, the API is reachable from inside the VPC and connected networks.
From lesson 05 · The EKS cluster: control plane, compute & add-onsQ9. When is Fargate a poor fit?
Show answer
B. Fargate runs one pod per micro-VM: no DaemonSets, no privileged containers, no GPUs, and per-pod pricing. Great for isolation and small footprints, not for everything.
From lesson 05 · The EKS cluster: control plane, compute & add-onsQ10. What does EKS Auto Mode take over compared with a classic cluster?
Show answer
B. Auto Mode manages compute, and the components for block storage and load balancing, so you run fewer add-ons yourself, at an extra per-instance cost and with less low-level control.
From lesson 05 · The EKS cluster: control plane, compute & add-onsQ11. Which add-ons does practically every EKS cluster need?
Show answer
B. Networking, DNS and service routing are required; storage, pod credentials and resource metrics are needed by almost every real platform.
From lesson 05 · The EKS cluster: control plane, compute & add-onsQ12. A pod needs to read one S3 prefix. What's the recommended way on a new EKS cluster?
Show answer
B. Pod Identity gives each ServiceAccount its own short-lived role credentials. The node role is shared by every pod on the node, and static keys leak.
From lesson 06 · IAM & governance: access entries, Pod Identity, IRSA, policiesQ13. What does the authentication mode API_AND_CONFIG_MAP allow?
Show answer
B. It's the migration mode: create access entries for everything in aws-auth, verify, then switch to API. You can't go back from API to CONFIG_MAP.
From lesson 06 · IAM & governance: access entries, Pod Identity, IRSA, policiesQ14. Where does a Pod Identity role's trust policy point?
Show answer
B. Pod Identity uses one fixed service principal, so the same role can be reused across clusters. IRSA trusts each cluster's own OIDC provider instead.
From lesson 06 · IAM & governance: access entries, Pod Identity, IRSA, policiesQ15. Why set the IMDSv2 hop limit to 1 on worker nodes?
Show answer
B. With a hop limit of 1 the metadata response can't cross the extra network hop into a pod's namespace. Pods then only have the credentials you gave them explicitly.
From lesson 06 · IAM & governance: access entries, Pod Identity, IRSA, policiesQ16. Which is a governance control rather than an identity control?
Show answer
B. Identity decides who can act; governance bounds what they can do and consume: quotas, admission policies, tagging, audit and cost controls.
From lesson 06 · IAM & governance: access entries, Pod Identity, IRSA, policiesQ17. What's a permissions boundary for?
Show answer
B. Delegated role creation is safe when every created role must carry a boundary that limits its effective permissions.
From lesson 06 · IAM & governance: access entries, Pod Identity, IRSA, policiesQ18. What does target-type: ip mean for an ALB created by the controller?
Show answer
B. With the VPC CNI, pods have VPC IPs, so the ALB can target them directly: fewer hops, and better health checking.
From lesson 07 · Ingress: ALB, NLB and the Load Balancer ControllerQ19. How do several Ingresses share one ALB (and one bill)?
Show answer
B. IngressGroups merge rules from multiple Ingresses into one ALB. Group only Ingresses with the same trust level.
From lesson 07 · Ingress: ALB, NLB and the Load Balancer ControllerQ20. The controller logs 'unable to resolve at least one subnet'. What's missing?
Show answer
B. The controller discovers subnets by tag. Tag your public and private subnets in Terraform when you create the VPC.
From lesson 07 · Ingress: ALB, NLB and the Load Balancer ControllerQ21. How do EKS nodes get permission to pull from ECR in the same account?
Show answer
B. Image pulls are done by the kubelet with the node role, so no pull secrets are needed for ECR in the same account (cross-account needs a repository policy too).
From lesson 08 · ECR & application deploymentQ22. Why make ECR tags immutable?
Show answer
B. Mutable tags let a re-push silently change what production runs. Immutable tags (or deploying by digest) make releases reproducible.
From lesson 08 · ECR & application deploymentQ23. A rolling update briefly drops traffic even though pods start fine. What's the most likely missing piece?
Show answer
B. Without readiness, pods receive traffic as soon as they start. Without a short preStop delay, terminating pods can still be in the load balancer's target list.
From lesson 08 · ECR & application deploymentQ24. What does a PodDisruptionBudget protect against?
Show answer
B. PDBs make drains and consolidation wait so that at least minAvailable replicas keep serving.
From lesson 08 · ECR & application deploymentQ25. Why must the gp3 StorageClass use volumeBindingMode: WaitForFirstConsumer on EKS?
Show answer
B. With Immediate binding, the volume could land in an AZ where the pod can't run, leaving it stuck.
From lesson 09 · Storage: EBS, EFS and S3Q26. Which option gives pods in different AZs a shared read-write filesystem?
Show answer
B. EFS is regional NFS supporting ReadWriteMany; EBS attaches to one node in one AZ.
From lesson 09 · Storage: EBS, EFS and S3Q27. How should the EBS CSI driver get permission to create volumes?
Show answer
B. The controller calls EC2 APIs. A dedicated role (AWS provides a managed policy for it) keeps those permissions off every node.
From lesson 09 · Storage: EBS, EFS and S3Q28. What triggers Karpenter to launch a node?
Show answer
B. Karpenter watches unschedulable pods, computes what capacity they need (resources, zones, architecture, taints) and launches matching instances.
From lesson 10 · Autoscaling: HPA & KarpenterQ29. What does consolidation do?
Show answer
B. Consolidation is how Karpenter saves money continuously, bounded by disruption budgets and PDBs.
From lesson 10 · Autoscaling: HPA & KarpenterQ30. Why does Karpenter need an interruption queue (SQS) for Spot?
Show answer
B. Spot instances get a two-minute warning. Handling it gives pods time to move gracefully.
From lesson 10 · Autoscaling: HPA & Karpenter