Put two containers in one Pod only when they must share a lifetime and a network: a sidecar that ships logs, renews certificates or proxies traffic. Since Kubernetes 1.33 5,150 (GA), a sidecar is an init container with restartPolicy: Always: it starts before the main containers, restarts if it dies and stops after them. Here one polls the front end over the Pod's shared localhost:
kubectl config set-context --current --namespace=booknest
kubectl apply -f - <<'EOF'
apiVersion: v1
kind: Pod
metadata: { name: web-probed }
spec:
initContainers:
- name: prober
image: localhost:33500/booknest-web:1.3
restartPolicy: Always
command: [sh, -c, 'while true; do wget -qO- 127.0.0.1/healthz 2>&-||echo down; sleep 3; done']
containers:
- { name: nginx, image: localhost:33500/booknest-web:1.3 }
EOF
kubectl wait --for=condition=Ready pod/web-probed >/dev/null && sleep 4
kubectl get pod web-probed && kubectl logs web-probed -c proberOutput
Context "kind-l3-booknest" modified. pod/web-probed created NAME READY STATUS RESTARTS AGE web-probed 2/2 Running 0 5s down ok
2/2 counts the sidecar, and its log shows the order: it started first, found nothing listening, then saw Nginx 75 . Before native sidecars, a sidecar was a second entry in containers that could start after the application and kept Jobs from completing. Keep sidecars small: every replica carries its own copy.