OpenShift Interview Questions
Top OpenShift interview questions and answers covering OpenShift architecture, Routes, ImageStreams, BuildConfigs, DeploymentConfig, Operators, GitOps, Tekton, SCC, Service Mesh, OpenShift Pipelines, and production troubleshooting.
Introduction
OpenShift is one of the most frequently asked Kubernetes platforms in enterprise interviews, especially for banking, insurance, healthcare, retail, and government organizations.
Interviewers expect candidates to understand not only Kubernetes fundamentals but also OpenShift-specific enterprise features such as:
- Routes
- ImageStreams
- BuildConfigs
- DeploymentConfigs
- Security Context Constraints (SCC)
- Operators
- OpenShift Pipelines
- GitOps
- OpenShift GitOps (ArgoCD)
- OpenShift Service Mesh
This guide contains production-oriented interview questions commonly asked for:
- DevOps Engineer
- Platform Engineer
- Cloud Engineer
- SRE
- Java Backend Engineer
- Solution Architect
Enterprise OpenShift Architecture
flowchart LR
Developer --> GitHub --> Tekton --> ImageRegistry --> ArgoCD --> OpenShift --> Prometheus --> Grafana --> Users
OpenShift Basics
1. What is OpenShift?
Answer
OpenShift is Red Hat's enterprise Kubernetes platform.
It provides:
- Kubernetes
- Enterprise Security
- Built-in Registry
- Routes
- Operators
- GitOps
- Pipelines
- Monitoring
- Logging
2. Why do enterprises use OpenShift?
Benefits
- Enterprise Support
- Better Security
- Developer Console
- Integrated CI/CD
- Operators
- Built-in Monitoring
- High Availability
3. Kubernetes vs OpenShift?
| Kubernetes | OpenShift |
|---|---|
| Community Platform | Enterprise Platform |
| Ingress | Routes |
| RBAC | RBAC + SCC |
| Manual Registry | Built-in Registry |
| Community Support | Red Hat Support |
Architecture Questions
4. Explain OpenShift Architecture.
flowchart TD
API --> ControlPlane
ControlPlane --> Worker1
ControlPlane --> Worker2
Worker1-->Pods
Worker2-->Pods
5. What are OpenShift Control Plane components?
- API Server
- Scheduler
- etcd
- Controller Manager
- Ingress Controller
6. What is a Project?
Project is OpenShift's implementation of a Kubernetes Namespace.
Benefits
- Resource Isolation
- RBAC
- Quotas
- Security
Deployment Questions
7. Difference between Deployment and DeploymentConfig?
| Deployment | DeploymentConfig |
|---|---|
| Kubernetes | OpenShift Specific |
| ReplicaSet | ReplicationController |
| Standard | Supports Image Triggers |
8. What is an ImageStream?
ImageStream tracks image versions.
Benefits
- Versioning
- Automatic Updates
- Rollback
- Image Triggers
9. What is BuildConfig?
BuildConfig automates image creation.
Supported Build Types
- Source-to-Image (S2I)
- Docker Build
- Custom Build
10. Explain Source-to-Image (S2I).
flowchart LR
Git --> Source --> S2I --> Image --> Registry
Benefits
- Faster Builds
- Secure Builds
- No Dockerfile Required
Networking Questions
11. What is a Route?
A Route exposes applications outside the cluster.
flowchart LR
User --> Route --> Service --> Pods
12. Difference between Route and Ingress?
| Route | Ingress |
|---|---|
| OpenShift | Kubernetes |
| Built-in | Requires Controller |
| Simpler | More Flexible |
Security Questions
13. What is SCC?
Security Context Constraints control container permissions.
Examples
- RunAsUser
- Privileged
- Host Network
- Volumes
14. Why is SCC important?
It prevents
- Running containers as root
- Unauthorized host access
- Privileged containers
15. What is RBAC?
Role-Based Access Control manages permissions.
Roles
- Admin
- Edit
- View
- Cluster Admin
GitOps Questions
16. What is OpenShift GitOps?
GitOps manages cluster configuration using Git.
flowchart LR
Git --> ArgoCD --> OpenShift
17. Benefits of GitOps?
- Version Control
- Rollback
- Audit Trail
- Drift Detection
- Automation
Pipelines Questions
18. What is OpenShift Pipelines?
OpenShift Pipelines is based on Tekton.
Pipeline
flowchart LR
Git --> Build --> Test --> Image --> Deploy
19. Why Tekton instead of Jenkins?
Advantages
- Kubernetes Native
- Container-Based
- Scalable
- Cloud Native
Operators Questions
20. What is an Operator?
Operator automates application lifecycle.
Responsibilities
- Install
- Upgrade
- Scale
- Backup
- Restore
21. What is OLM?
Operator Lifecycle Manager manages
- Installation
- Updates
- Dependencies
Service Mesh Questions
22. What is OpenShift Service Mesh?
Built on
- Istio
- Envoy
- Jaeger
- Kiali
23. Why use Service Mesh?
Features
- mTLS
- Retry
- Traffic Routing
- Observability
- Circuit Breaking
Monitoring Questions
24. Which monitoring tools are included?
- Prometheus
- Grafana
- Alertmanager
25. Which logging solutions are used?
- Loki
- Elasticsearch
- Kibana
- Fluentd
Autoscaling Questions
26. Difference between HPA and Cluster Autoscaler?
| HPA | Cluster Autoscaler |
|---|---|
| Scales Pods | Scales Nodes |
| CPU/Memory Based | Infrastructure Based |
Scenario Questions
27. Pods keep restarting. What will you check?
Possible reasons
- CrashLoopBackOff
- OOMKilled
- Failed Liveness Probe
- Failed Startup Probe
- Missing Secrets
- Wrong ConfigMap
28. Application is running but users cannot access it.
What would you verify?
- Route
- Service
- Pod Status
- DNS
- TLS Certificate
- Network Policy
29. Image update is not triggering deployment.
Possible reasons
- ImageStream not updated
- DeploymentConfig trigger missing
- Wrong Image Tag
- Registry Authentication Failure
30. BuildConfig fails during S2I build.
Things to check
- Git URL
- Build Logs
- Builder Image
- Network Access
- Resource Limits
Advanced Questions
31. How do you perform zero-downtime deployments?
Options
- Rolling Updates
- Blue-Green
- Canary
32. Explain Blue-Green Deployment.
flowchart LR
Users --> Route
Route --> Blue
Route --> Green
33. Explain Canary Deployment.
flowchart LR
Users --> 10Percent --> NewVersion
Users --> 90Percent --> StableVersion
34. How do you secure OpenShift?
Best Practices
- SCC
- RBAC
- Secrets
- Image Scanning
- Network Policies
- TLS Everywhere
35. How do you troubleshoot a production issue?
Steps
- Check Pod Status
- View Events
- Read Logs
- Verify Routes
- Check Services
- Check Image
- Verify Resources
- Monitor Metrics
Production Troubleshooting Flow
flowchart TD
UserIssue --> Route
Route --> Service
Service --> Pod
Pod --> Logs
Logs --> Metrics
Metrics --> RootCause
Real-World Production Scenario
A Spring Boot microservice deployment fails after deployment.
What would you check?
- Pod Status
- Route
- Service
- ImageStream
- DeploymentConfig
- BuildConfig
- Liveness Probe
- Readiness Probe
- SCC
- Resource Limits
- Prometheus Alerts
- Application Logs
Common oc Commands
oc login
oc project my-project
oc get pods
oc get deployments
oc get dc
oc get routes
oc get svc
oc logs pod-name
oc describe pod pod-name
oc rollout status deployment/app
oc rollout undo deployment/app
oc adm top nodes
oc adm top pods
Production Best Practices
- Use GitOps
- Prefer Tekton Pipelines
- Enable SCC
- Use Network Policies
- Store secrets securely
- Scan container images
- Configure Resource Limits
- Enable HPA
- Monitor with Prometheus
- Centralize logs
- Use Rolling or Canary Deployments
- Automate rollback
Enterprise OpenShift Components
| Component | Purpose |
|---|---|
| Project | Namespace |
| Pod | Smallest Deployable Unit |
| Service | Internal Networking |
| Route | External Access |
| ImageStream | Image Versioning |
| BuildConfig | Image Build |
| Deployment | Kubernetes Deployment |
| DeploymentConfig | OpenShift Deployment |
| SCC | Security |
| Operator | Lifecycle Automation |
| Tekton | CI/CD Pipelines |
| ArgoCD | GitOps |
| Prometheus | Monitoring |
| Grafana | Dashboards |
| Loki | Logging |
| ACM | Multi-Cluster Management |
Quick Revision Cheat Sheet
| Topic | Key Point |
|---|---|
| Project | Namespace |
| Route | External URL |
| Service | Internal Communication |
| Pod | Container Group |
| ImageStream | Tracks Image Versions |
| BuildConfig | Build Automation |
| Deployment | Kubernetes Deployment |
| DeploymentConfig | OpenShift Deployment |
| SCC | Container Security |
| Operator | Automated Lifecycle |
| GitOps | Git Driven Deployment |
| Tekton | Kubernetes Native Pipeline |
| Prometheus | Monitoring |
| Grafana | Dashboards |
| Loki | Logging |
| ACM | Multi-Cluster Management |
Interview Tips
Remember these keywords
- OpenShift
- OCP
- SCC
- Route
- BuildConfig
- ImageStream
- DeploymentConfig
- Tekton
- GitOps
- ArgoCD
- Operator
- OLM
- Service Mesh
- Prometheus
- Grafana
- Loki
- ACM
- Rolling Update
- Blue-Green
- Canary
Summary
OpenShift interviews focus heavily on enterprise application deployment, security, automation, GitOps, CI/CD, and production troubleshooting. Beyond Kubernetes fundamentals, interviewers expect candidates to understand OpenShift-specific capabilities such as Routes, ImageStreams, BuildConfigs, DeploymentConfigs, Security Context Constraints (SCC), Operators, and Tekton Pipelines.
Hands-on experience with GitOps (ArgoCD), OpenShift Pipelines, monitoring, logging, and troubleshooting production workloads will significantly strengthen your performance in DevOps Engineer, Platform Engineer, Cloud Engineer, SRE, and Solution Architect interviews.