Worker nodes
kubelet
32 / 82

The kubelet turns "this Pod is assigned to me" into running, healthy containers.

It is the only node component that talks to the API server. It watches, starts, probes and reports back, continuously.

API serverPods assigned to nodekubeletwatches, decidescontainerdstarts containers (CRI)probesliveness, readinessnode statusheartbeat to API

Always reconciling

The kubelet compares "Pods that should run here" with "containers running here" and fixes the difference, exactly like any controller.

Static Pods

It can also run Pods from files in /etc/kubernetes/manifests. That is how kubeadm starts the API server and etcd themselves.

Security-critical port 10250

Its API powers exec and logs. Require authentication and webhook authorization; never allow anonymous access.