Pod
In short
A pod is the smallest deployable unit in Kubernetes: one or more containers that share a network address and storage and are scheduled together on one node.
What is a pod in Kubernetes?
In Kubernetes, you don't run containers directly; you run pods. A pod wraps one or more containers that always run together on the same machine, called a node, and share the same network identity and storage volumes. Most pods contain a single application container, and Kubernetes creates, moves, and deletes pods as its basic unit of scheduling.
All containers in a pod share one IP address and port space, so they can talk to each other on localhost, and they can mount the same volumes to share files. This makes pods a good fit for the sidecar pattern, where a helper container, such as a log shipper or a service mesh proxy, runs next to the main app. Pods are designed to be disposable: if a pod crashes or its node fails, it is not repaired but replaced by a new pod with a new name and IP address, which is why traffic is sent through a Service, a stable address that routes to whichever pods are currently healthy.
In practice you rarely create pods by hand. You define a Deployment, StatefulSet, or Job, and that controller creates and maintains the right number of pods from a template, replacing any that fail and rolling out new versions gradually. A pod is like a shared apartment for containers: the roommates share one address and one kitchen, and when the lease ends, everyone moves out together.
A pod is often confused with a container. A container is a single packaged process with its own image, while a pod is the Kubernetes wrapper around one or more containers that adds shared networking, storage, and a lifecycle. A pod is also not a node: a node is the virtual or physical machine, and one node typically runs many pods.
Key takeaways
- A pod is the smallest unit that Kubernetes schedules and manages.
- Containers in the same pod share an IP address,
localhost, and volumes. - Most pods run one container; helper containers in the same pod are called sidecars.
- Pods are disposable and are replaced, not repaired, when they fail.
- Controllers such as Deployments create and manage pods; Services give them a stable address.
Example
apiVersion: v1
kind: Pod
metadata:
name: web
labels:
app: web
spec:
containers:
- name: app # the main application container
image: registry.example.com/web:1.4.2
ports:
- containerPort: 8080
- name: log-shipper # sidecar: same IP address and localhost as the app
image: registry.example.com/log-shipper:2.0Readers ask
What is the difference between a pod and a container?
A container is one isolated process packaged from an image. A pod is a Kubernetes object that holds one or more containers, gives them a shared IP address and storage, and is scheduled onto a node as a single unit.
Why does a pod's IP address change?
Pods are disposable, so when one is replaced, the new pod gets a new IP address. Applications should reach pods through a Kubernetes Service, which keeps a stable name and address and forwards traffic to the current healthy pods.
See also
- KubernetesDevOps & Cloud, p. 32Kubernetes is an open-source system that automates deploying, scaling, and managing containerized applications across a cluster of machines.
- ContainerDevOps & Cloud, p. 12A container is a lightweight, isolated package that bundles an application with its dependencies and runs it on the host's shared operating system kernel.
- DockerDevOps & Cloud, p. 17Docker is an open-source platform for packaging an application and everything it needs into a container that runs the same way on any machine.
- Service MeshDevOps & Cloud, p. 48A service mesh is an infrastructure layer that manages traffic between microservices, adding encryption, retries, routing, and monitoring without code changes.
- AutoscalingDevOps & Cloud, p. 2Autoscaling is the automatic adding or removing of computing resources, such as servers or containers, based on demand to keep performance steady and costs low.
- Health CheckBackend & APIs, p. 21A health check is a small automated test, usually an HTTP endpoint, that reports whether a service is up and able to handle requests, so failures show fast.
- kubectlDevOps & Cloud, p. 31kubectl is the command-line tool for Kubernetes: it sends requests to a cluster's API server to deploy applications, inspect them and change them.
- Sidecar PatternSoftware Architecture, p. 40The sidecar pattern runs a helper process next to an application, sharing its lifecycle and network, to add features such as logging, proxying or security.
Spotted a mistake or something missing on this page?Suggest an edit