Municipal SRE sees intermittent DNS failures for in-cluster names. Which first admin check best targets CoreDNS configuration and runtime behavior?
Select an answer to reveal the explanation.
Short Explanation
When the building directory starts glitching, you check the directory’s rule book and the clerk’s error log—not fire the security guards and unplug the phone switch. For CoreDNS that means the Corefile in its ConfigMap plus the Pod logs for rewrite, kubernetes, or upstream failures. Blowing away NetworkPolicies or kube-proxy first is theater, not triage.
Full Explanation
CoreDNS is configured primarily through its Corefile, typically mounted from a ConfigMap in kube-system. Intermittent resolution issues often show as plugin misconfiguration, upstream timeouts, or crash loops visible in CoreDNS logs. Checking that ConfigMap and logs is the direct admin path. Disabling cluster DNS, deleting all NetworkPolicies preemptively, or removing kube-proxy are destructive and do not diagnose CoreDNS itself.