The kubelet runs directly on the host as a systemd 142,543 service. It registers the node, watches for Pods bound to it, and runs a sync loop per Pod: create what is missing, restart exited containers per restartPolicy, run probes (Probes and Resources), mount volumes and report status. It also runs the static Pods in its manifest directory.
docker exec l3-booknest-worker systemctl is-active kubelet
docker exec l3-booknest-worker grep -E \
'cgroupDriver|containerRuntimeEndpoint|staticPodPath|clusterDomain' /var/lib/kubelet/config.yaml
kubectl get lease -n kube-node-leaseactive cgroupDriver: systemd clusterDomain: cluster.local containerRuntimeEndpoint: unix:///run/containerd/containerd.sock staticPodPath: /etc/kubernetes/manifests NAME HOLDER AGE l3-booknest-control-plane l3-booknest-control-plane 17m l3-booknest-worker l3-booknest-worker 16m
The systemd cgroup driver must match containerd 234,762 's (SystemdCgroup = true), or Pods fail with cgroup errors. The heartbeat is a Lease per node, renewed every ten seconds. If it goes stale, the node controller marks the node NotReady and, after the default 300-second toleration, evicts its Pods so they are recreated elsewhere; a brief network blip should not reshuffle a node. Under memory or disk pressure the kubelet evicts Pods itself.