CNCF CKA Hands-on 16 tasks 2 hours

Certified Kubernetes Administrator

A hands-on exam: you are given a terminal and a list of cluster tasks. Practise them here against a simulated cluster that grades the state you leave behind. Covered: RBAC, etcd backup and restore, upgrading a control plane node with kubeadm, Helm, Kustomize, scheduling, priority classes, disruption budgets and drains, StatefulSets and DaemonSets, static pods, autoscaling, Services, Ingress, storage and troubleshooting, including a control plane whose API server, scheduler or controller manager does not come up and a node whose kubelet does not run. Not simulated yet: custom resources and the Gateway API. The kubeadm upgrade is between patch releases of 1.31 on the node you are logged in to: its packages, kubeadm upgrade plan and apply, and a kubelet that reports the new version once it is restarted; kubeadm init and join, and upgrading a worker, are not simulated. NetworkPolicies are enforced between pods, and one task is graded on the traffic it lets through; the two older ones grade the policy you write. ResourceQuotas and LimitRanges are enforced as well, and two tasks are about pods a quota refuses.

The blueprint

A mock lab here has 16 tasks in 2 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 66%. FixOps scores practice against a target of 66%.

  1. 01

    Cluster Architecture, Installation and Configuration

    25%

  2. 02

    Workloads and Scheduling

    15%

  3. 03

    Services and Networking

    20%

  4. 04

    Storage

    10%

  5. 05

    Troubleshooting

    30%

The free sample lab

Two tasks from the bank, in a simulated cluster you drive with kubectl and helm. You are graded on the state you leave behind, not on the commands you type.

  • Give a pipeline account deploy rights in one namespace. Create a ServiceAccount, a Role and a RoleBinding scoped to the ci namespace.
  • A rollout that never finishes. Find out why the new pods of a Deployment do not start and finish the rollout.

Revision notes: Cluster Architecture, Installation and Configuration

The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.

Access control with RBAC, building and upgrading a cluster with kubeadm, backing up etcd, and extending the cluster with Helm, Kustomize and custom resources.

RBAC

  • kubectl create role NAME --verb=get,list --resource=pods -n NS makes a namespaced Role; create clusterrole does the same cluster-wide.
  • kubectl create rolebinding NAME --role=ROLE --serviceaccount=NS:SA -n NS binds it; --user and --group bind people.
  • A RoleBinding can refer to a ClusterRole, which grants its rules in that one namespace only.
  • kubectl auth can-i VERB RESOURCE --as=system:serviceaccount:NS:SA -n NS checks the result in seconds.
  • Cluster-scoped resources such as nodes and persistent volumes need a ClusterRole and a ClusterRoleBinding.

kubeadm lifecycle

  • kubeadm init creates a control plane; kubeadm join adds a node with a token and the CA certificate hash.
  • kubeadm token create --print-join-command prints a fresh join command.
  • Upgrade one minor version at a time: upgrade kubeadm, run kubeadm upgrade plan and kubeadm upgrade apply on the first control plane node, then kubeadm upgrade node on the others.
  • For each node: drain it, upgrade the kubelet and kubectl packages, restart the kubelet, then uncordon it.
  • The packages are on hold: apt-cache madison kubeadm lists the versions, then apt-mark unhold kubeadm, apt-get install -y kubeadm=VERSION and apt-mark hold kubeadm.
  • A node reports the new kubelet version only after systemctl daemon-reload and systemctl restart kubelet; installing the package changes nothing that runs.
  • Static pod manifests for the control plane live in /etc/kubernetes/manifests, and the kubelet restarts a component when its file changes.

etcd backup and restore

  • etcdctl snapshot save FILE needs --endpoints, --cacert, --cert and --key; the paths are in the etcd static pod manifest.
  • Restoring writes a new data directory, and the etcd manifest's hostPath is then pointed at it.
  • etcdctl endpoint health and member list show the state of the etcd cluster.

High availability and extensions

  • A highly available control plane has several API servers behind a load balancer and an odd number of etcd members, stacked on the control plane nodes or external.
  • Helm installs charts as releases: helm install, upgrade, rollback, and helm template to render without installing.
  • Kustomize applies overlays to plain manifests with kubectl apply -k.
  • A CustomResourceDefinition adds a new kind to the API, and an operator is a controller that manages it.
  • CNI, CSI and CRI are the plugin interfaces for networking, storage and container runtimes.

Easy to mix up

  • A Role and a RoleBinding stay in a namespace; ClusterRole and ClusterRoleBinding do not.
  • kubeadm upgrade apply is for the first control plane node; kubeadm upgrade node is for the rest.
  • Drain evicts the pods and cordons the node; cordon only stops new pods from being scheduled.
  • kubectl version shows the API server's version, which kubeadm upgrade apply moves; the VERSION column of the node list is each kubelet's.
  • An etcd snapshot restores the cluster's state, not the data in persistent volumes.

Practice tasks written by FixOps from the public CKA curriculum (Kubernetes v1.35). They are not real exam tasks and run in a simulator, not a live cluster. FixOps is not affiliated with or endorsed by the Linux Foundation or the CNCF.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.