Which Kubernetes component is the only one that reads from and writes to etcd directly?
Choose one.
etcd is the cluster's source of truth, but access to it is deliberately funneled through a single component: the kube-apiserver.
Centralizing etcd access in the API server means authentication, authorization, admission control, and validation happen in exactly one place before any state changes. The controller manager and kubelet are plausible distractors because they constantly read and update state, but they always do so via API requests - if they wrote to etcd directly, they would bypass every security and validation layer.
- A component or user submits a change through the Kubernetes API.
- The kube-apiserver validates the request and authorizes the caller.
- The kube-apiserver alone persists the resulting object into etcd.
Exam tip: Only kube-apiserver talks to etcd - every other component goes through the API server.
Kubernetes Core Concepts: Architecture, Pods, Deployments, and Services — the lesson that teaches this.