
DNS Debugging in Kubernetes: ndots and CoreDNS
Why DNS is always the problem, and how to diagnose ndots, search domains, and CoreDNS issues.
This site stores data to improve your experience. Learn more in our Consent Policy and Privacy Policy.

Container orchestration platform for scheduling, networking, and scaling workloads
Kubernetes is the operating system of platform engineering. Its declarative API, reconciliation loop, and extensibility model provide the foundation that tools like Argo CD, Crossplane, and Helm build on. For platform teams, Kubernetes is less about running containers and more about providing a consistent control plane where infrastructure, deployments, and policies converge into a single programmable surface that application teams consume through self-service abstractions.
The depth of Kubernetes knowledge that platform engineering demands goes well beyond deploying workloads. Cluster networking with CNI plugins, ingress controller tuning, pod security standards, RBAC policy design, and resource quota management are the daily concerns that determine whether a multi-tenant cluster is secure and stable or a shared liability. Custom Resource Definitions and operator patterns let platform teams extend the API server with domain-specific abstractions—turning Kubernetes into a platform-building framework rather than just a runtime.
Operational maturity means understanding failure modes: etcd latency under load, node pressure evictions, webhook timeout cascading, and the subtle ways misconfigured HPA and PDB interact during rollouts. Platform engineers who invest in cluster observability, upgrade automation, and capacity planning build platforms that application teams trust. Those who treat Kubernetes as a black-box deployment target inevitably face reliability surprises at scale.

Why DNS is always the problem, and how to diagnose ndots, search domains, and CoreDNS issues.

Balancing standardization with team autonomy so the right thing is easy but not the only option.

Consumer-driven contracts that catch breaking changes without heavyweight tooling or coordination overhead.

Supply chain security basics that you can implement without a dedicated security team or expensive tooling.

When to build abstractions over kubectl or terraform and when the wrapper creates more problems than it solves.

Pod killing and latency injection experiments without expensive platforms or dedicated chaos teams.

When to use Kubernetes Ingress, when to migrate to Gateway API, and the tradeoffs between them.

Connection pool sizing, timeout configuration, and the saturation signals that predict database problems.

Tradeoffs between deployment strategies for stateless and stateful workloads, with and without service mesh.

Replacing service account keys with workload identity federation for secure, keyless cloud access.

Implementing infrastructure policies with OPA and Conftest that catch violations before they reach production.

Managing Helm across dozens of services without losing track of what is actually deployed.