maxSurge adds capacity first; maxUnavailable lets old Pods leave; readiness gates every step.
With 3 replicas, maxSurge: 1 and maxUnavailable: 1, v1 becomes v2 without ever dropping below 2 ready Pods.
0 Start
v1v1v1
old 3, new 01 Surge
v1v1v1v2
4 total: surge allows 1 extra2 New is Ready
v1v1gonev2 ready
only now is an old Pod removed3 Repeat
v1gonev2v2
old 1, new 24 Done
v2v2v2
old ReplicaSet scaled to 0The speed and safety dial
Higher surge uses more resources briefly. Higher maxUnavailable gives up spare capacity. Both at 0 would deadlock the rollout.
No readiness probe, no safety
Without it a broken new Pod looks "ready" at once and healthy old Pods are replaced by it.
Observe and stop
kubectl rollout status, pause, undo. progressDeadlineSeconds marks a stuck rollout as failed.