Cloud infrastructure is often managed by describing a desired state and letting controllers move the live system toward it. The description is not a command that completes atomically. It is an input to a control loop that observes, compares, and acts over time.
Package the workload
A container image groups application files and runtime dependencies into a versioned artifact. A container runtime starts processes with configured namespaces, resource limits, mounts, and network settings. Containers share a host kernel; they are not miniature virtual machines with a separate kernel.
Controllers reconcile resources
In Kubernetes, a Deployment declares a desired number of interchangeable Pods and a pod template. A Deployment controller manages ReplicaSets; the scheduler assigns unscheduled Pods to nodes; node agents ask the container runtime to start them. Readiness and health checks influence when a Pod receives traffic or is restarted, but they must reflect actual service health.
The control plane and data plane have different jobs. The API server stores and exposes cluster objects; controllers observe object changes and reconcile state. The network data path carries traffic between clients and Pods, often through Services and an implementation-specific proxy or network plugin. A successful API update does not mean every workload is already ready.
Operate the state transition
A rollout changes the pod template, creates new replicas, and retires old ones according to its strategy. Watch desired versus ready replicas, events, logs, and application metrics. Plan rollback and database compatibility separately: rolling back an image cannot automatically reverse a schema migration or external side effect.
The Kubernetes concepts guide and Deployment documentation explain the resources and reconciliation behavior.