kube-controller-manager runs a few dozen controllers, each a loop that watches one kind 14,561 of object and acts on it: Deployments create ReplicaSets, ReplicaSets create Pods, and others manage Jobs, DaemonSets, StatefulSets, EndpointSlices, namespaces, node health and garbage collection. Only one copy may act at a time, so copies hold an election through a Lease:
kubectl -n kube-system get pod kube-controller-manager-l3-booknest-control-plane \
-o jsonpath='{range .spec.containers[0].command[*]}{@}{"\n"}{end}' | grep -E 'controllers|leader'
kubectl get lease -n kube-system kube-controller-manager kube-scheduler
kubectl delete pod -l app=hungry --field-selector=status.phase=Running
sleep 5
kubectl get events --field-selector involvedObject.kind=ReplicaSet \
-o custom-columns=SOURCE:.source.component,REASON:.reason,MESSAGE:.message | tail -1--controllers=*,bootstrapsigner,tokencleaner --leader-elect=true NAME HOLDER AGE kube-controller-manager l3-booknest-control-plane_f74593a9-5998-4d2e-9fcb-4625d6d8a4d3 8m48s kube-scheduler l3-booknest-control-plane_1ffb2788-ba0d-4721-9a14-eee560c87347 8m49s pod "hungry-66f6c7c98-ccl6l" deleted from default namespace replicaset-controller SuccessfulCreate Created pod: hungry-66f6c7c98-pznwz
* enables every default controller, plus two for kubeadm 5,150 's bootstrap tokens. If the Lease holder stops renewing, another control-plane node takes over within about 15 seconds. The deleted Pod was replaced at once by the ReplicaSet controller. Controllers never talk to each other; each reads and writes objects through the API server (The Reconciliation Loop).