DevOps & Kubernetes Interview Guide 2025-2026: CI/CD, Docker, and Cloud
DevOps is one of the fastest-growing roles in India's tech sector — and Kubernetes expertise commands some of the highest packages. But DevOps interviews in 2025 go far beyond knowing kubectl commands. This guide covers every layer of a modern DevOps interview: container orchestration architecture, CI/CD design, Infrastructure as Code, cloud services, observability, and the real scenario-based questions interviewers at Amazon, Infosys, HCL, Wipro, and Indian product startups ask.
The Scope of a Modern DevOps Interview
DevOps roles have evolved. In 2025, "DevOps Engineer" encompasses several distinct competencies that senior interviewers probe separately: container orchestration (Kubernetes), CI/CD automation (Jenkins, GitHub Actions, GitLab CI), Infrastructure as Code (Terraform, Ansible, Pulumi), cloud platforms (AWS, GCP, Azure), observability (Prometheus, Grafana, ELK), and site reliability engineering principles.
The mistake most DevOps candidates make is going wide but shallow — they know all the tools but can't go deep on any. Senior interviewers want depth: how does the Kubernetes scheduler work, what happens during a rolling update, how does etcd handle leader election, why did your Terraform plan drift. This guide is designed to take you deep on each critical area.
DevOps Interview Preparation Plan: 6 Weeks
6-Week DevOps Interview Preparation Roadmap
Round 1: Docker Fundamentals and Container Security
Every DevOps interview starts with Docker. Don't treat this as basic — senior interviewers probe container internals.
Docker Architecture Deep Dive
- Explain Docker's layered filesystem. Why are layers immutable and what is a "copy-on-write" filesystem?
- What is the difference between COPY and ADD in a Dockerfile? When is each appropriate?
- Explain multi-stage builds. Why do they dramatically reduce final image size?
- What is Docker's networking model? Explain bridge, host, and overlay networks and when you'd use each.
- How do you minimize attack surface in a Docker container? (Non-root user, minimal base image, read-only filesystem, no-new-privileges flag)
Round 2: Kubernetes Architecture and Internals
Kubernetes is the core of most DevOps senior interviews. Go beyond kubectl — understand the architecture.
Control Plane Components (Must Know)
- API Server: The central API gateway — all cluster communication goes through it. Explain authentication, authorization (RBAC), and admission controllers.
- etcd: Distributed key-value store for all cluster state. Why is etcd backup critical? What happens if etcd fails?
- Scheduler: Assigns Pods to nodes based on resource requests, affinity rules, taints/tolerations. Explain the two phases: filtering and scoring.
- Controller Manager: Runs controllers (ReplicaSet, Deployment, Job) that reconcile desired vs actual state.
- kubelet: Node agent that ensures containers run per PodSpec. Explain the pod lifecycle and how kubelet reports readiness/liveness.
Real Scenario: Pod Is in CrashLoopBackOff — How Do You Debug It?
kubectl describe pod [name]— check Events section for scheduling failures or container errorskubectl logs [pod] --previous— logs from the previous (crashed) container instance- Check OOMKilled — container exceeded memory limit, increase limits or fix memory leak
- Check liveness probe too aggressive — failing before app is ready, increase initialDelaySeconds
- Check image pull errors — wrong tag, missing imagePullSecrets for private registry
Kubernetes Networking
- Explain the Kubernetes networking model: every pod gets a unique IP, pods communicate without NAT.
- What is a ClusterIP service vs NodePort vs LoadBalancer vs ExternalName?
- How does Ingress work? What is an Ingress Controller (NGINX, Traefik, AWS ALB)?
- What are Network Policies and how do you implement a default-deny policy?
- Explain how CoreDNS enables service discovery in Kubernetes.
Round 3: CI/CD Pipeline Design
CI/CD questions in DevOps interviews are architecture questions: how would you design a pipeline for this constraint?
Pipeline Best Practices (Interview Answers)
- Fail fast: Run static analysis and unit tests first before integration tests to save time on failures.
- Pipeline as Code: Jenkinsfile or GitHub Actions YAML in the repository — versioned, reviewable, reproducible.
- Secret management: Never hardcode secrets. Use Vault, AWS Secrets Manager, or Kubernetes Secrets mounted as env vars.
- Artifact immutability: Tag Docker images with git SHA, not "latest" — ensures traceability and rollback.
- Deployment strategies: Rolling update (zero downtime, gradual), Blue-Green (instant switch, expensive), Canary (small % traffic to new version).
Round 4: Infrastructure as Code with Terraform
Terraform is mandatory for senior DevOps roles. Know it deeply, not just the basics.
Terraform Internals and Interview Questions
- Explain Terraform's state file. Why is remote state (S3 + DynamoDB) critical for teams?
- What is a Terraform module? How do you structure modules for reusability across environments?
- What is the difference between terraform plan and terraform apply? Why should plans be reviewed in CI?
- How do you handle Terraform state drift? What causes it and how do you resolve it?
- Explain Terraform workspaces. When would you use workspaces vs separate state files for environments?
Round 5: Observability and Incident Response
The SRE-influenced DevOps interview probes your observability and on-call readiness. Key topics:
- The three pillars: Metrics (Prometheus + Grafana), Logs (ELK/Loki), Traces (Jaeger/Zipkin/X-Ray). Explain them and when you'd use each.
- SLA/SLO/SLI: Explain error budgets. If you have a 99.9% SLO, how many minutes of downtime per month is your budget?
- Alerting philosophy: Alert on symptoms, not causes. Alert on SLO burn rate, not individual component health.
- Runbooks and postmortems: How would you structure a production incident response? Blameless postmortem.
Salary Expectations for DevOps Engineers in India (2025-2026)
- 2–4 years experience: ₹10L–₹22L; stronger for Kubernetes + cloud roles
- 4–7 years, Kubernetes + Terraform + AWS: ₹22L–₹42L for senior DevOps
- 7+ years, SRE/platform engineering: ₹45L–₹80L at product companies and FAANG
- Remote US contracts: $110K–$180K for Senior DevOps/SRE Engineer
Get DevOps Interview Coaching from Industry Experts
RVK Tech's DevOps coaches run deep Kubernetes, Terraform, and CI/CD mock rounds. We know precisely what Amazon, Infosys, and Indian startups ask — and we'll make sure you're fully prepared before your interview day.