The mechanism
The capstone combines the book’s mechanisms in a synthetic Deployment and Service bundle. The offline Python lab checks label selection, target-port alignment, replica-resource arithmetic and selected security-context invariants. It uses only the standard library and does not invoke kubectl.
These are application-specific fixture checks, not a Kubernetes API validator or a cluster simulator. They cannot establish admission behavior, scheduling, CNI enforcement, storage provisioning or application availability. Their value is catching clear contract mistakes before a live environment is involved.
Treat the bundle as a review artifact. The image reference is a non-runnable example, and no cluster creation or apply step is included. A later approved integration track would validate against the actual API and observe runtime behavior separately.
Worked example
Download the lab and run it in a scratch directory with a supported Python 3 runtime. Inspect the file first. It operates on in-memory dictionaries and prints unittest results; it makes no network call and writes no Kubernetes objects.
python3 parcelops_workload_lab.py
# Download: /handbook/kubernetes/parcelops_workload_lab.py
# Expected: the implemented synthetic invariant checks report OK.
# API admission, scheduling, probes and traffic: not run.
Practice: predict, inspect, explain
Offline exercise. Predict the effect of a mismatched Service selector, target port 9090 and missing resource request before reading the corresponding tests. Run the unmodified suite and retain its output. Then design a separate integration checklist for an approved disposable cluster without executing it.
Expected observation: local checks can disprove several bad configurations, but passing them does not prove the workload can run. Include runtime version, file hash, exact command, output and limitations in an evidence packet. Keep every live-cluster field explicitly not run.
Troubleshooting and trade-offs
If a test fails, inspect the invariant and fixture rather than weakening the assertion. If your real workload intentionally uses a different pattern, adapt the check with a documented reason and its own tests. Do not label the fixture suite a security scan or conformance certification. It covers only the conditions named in the source.
Interview practice
Why is this not a Kubernetes validator?
It checks a small set of application invariants in synthetic dictionaries. It does not implement the API schema, admission chain or runtime behavior.
What remains after the offline suite passes?
Server validation, policy admission, scheduling, image startup, health, storage, traffic, identity and application acceptance in the actual approved environment.
Completion check
Run the local suite and explain at least five untested cluster responsibilities.
Sources and version notes
Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.
- Official documentation: Working with objects
- Official documentation: Service
- Official documentation: Manage resources containers
- Official documentation: Pod security standards
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.