The blueprint
A mock lab here has 16 tasks in 2 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 66%. FixOps scores practice against a target of 66%.
-
01
Cluster Architecture, Installation and Configuration
-
02
Workloads and Scheduling
-
03
Services and Networking
-
04
Storage
-
05
Troubleshooting
The free sample lab
Two tasks from the bank, in a simulated cluster you drive with kubectl and helm. You are graded on the state you leave behind, not on the commands you type.
- Give a pipeline account deploy rights in one namespace. Create a ServiceAccount, a Role and a RoleBinding scoped to the ci namespace.
- A rollout that never finishes. Find out why the new pods of a Deployment do not start and finish the rollout.
Revision notes: Cluster Architecture, Installation and Configuration
The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.
Access control with RBAC, building and upgrading a cluster with kubeadm, backing up etcd, and extending the cluster with Helm, Kustomize and custom resources.
RBAC
- kubectl create role NAME --verb=get,list --resource=pods -n NS makes a namespaced Role; create clusterrole does the same cluster-wide.
- kubectl create rolebinding NAME --role=ROLE --serviceaccount=NS:SA -n NS binds it; --user and --group bind people.
- A RoleBinding can refer to a ClusterRole, which grants its rules in that one namespace only.
- kubectl auth can-i VERB RESOURCE --as=system:serviceaccount:NS:SA -n NS checks the result in seconds.
- Cluster-scoped resources such as nodes and persistent volumes need a ClusterRole and a ClusterRoleBinding.
kubeadm lifecycle
- kubeadm init creates a control plane; kubeadm join adds a node with a token and the CA certificate hash.
- kubeadm token create --print-join-command prints a fresh join command.
- Upgrade one minor version at a time: upgrade kubeadm, run kubeadm upgrade plan and kubeadm upgrade apply on the first control plane node, then kubeadm upgrade node on the others.
- For each node: drain it, upgrade the kubelet and kubectl packages, restart the kubelet, then uncordon it.
- The packages are on hold: apt-cache madison kubeadm lists the versions, then apt-mark unhold kubeadm, apt-get install -y kubeadm=VERSION and apt-mark hold kubeadm.
- A node reports the new kubelet version only after systemctl daemon-reload and systemctl restart kubelet; installing the package changes nothing that runs.
- Static pod manifests for the control plane live in /etc/kubernetes/manifests, and the kubelet restarts a component when its file changes.
etcd backup and restore
- etcdctl snapshot save FILE needs --endpoints, --cacert, --cert and --key; the paths are in the etcd static pod manifest.
- Restoring writes a new data directory, and the etcd manifest's hostPath is then pointed at it.
- etcdctl endpoint health and member list show the state of the etcd cluster.
High availability and extensions
- A highly available control plane has several API servers behind a load balancer and an odd number of etcd members, stacked on the control plane nodes or external.
- Helm installs charts as releases: helm install, upgrade, rollback, and helm template to render without installing.
- Kustomize applies overlays to plain manifests with kubectl apply -k.
- A CustomResourceDefinition adds a new kind to the API, and an operator is a controller that manages it.
- CNI, CSI and CRI are the plugin interfaces for networking, storage and container runtimes.
Easy to mix up
- A Role and a RoleBinding stay in a namespace; ClusterRole and ClusterRoleBinding do not.
- kubeadm upgrade apply is for the first control plane node; kubeadm upgrade node is for the rest.
- Drain evicts the pods and cordons the node; cordon only stops new pods from being scheduled.
- kubectl version shows the API server's version, which kubeadm upgrade apply moves; the VERSION column of the node list is each kubelet's.
- An etcd snapshot restores the cluster's state, not the data in persistent volumes.