The blueprint
A mock lab here has 16 tasks in 2 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 66%. FixOps scores practice against a target of 66%.
-
01
Application Design and Build
-
02
Application Deployment
-
03
Application Observability and Maintenance
-
04
Application Environment, Configuration and Security
-
05
Services and Networking
The free sample lab
Two tasks from the bank, in a simulated cluster you drive with kubectl and helm. You are graded on the state you leave behind, not on the commands you type.
- Add a log-shipping sidecar. Create a two-container pod whose containers share a volume.
- A crash loop with the answer in the logs. Read the logs of a crash-looping Deployment and supply the setting it asks for.
Revision notes: Application Design and Build
The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.
Building images, choosing the right workload resource, composing multi-container pods and using volumes.
Images
- A Dockerfile's FROM names the base image, COPY adds files, RUN executes at build time, and CMD or ENTRYPOINT is what runs at start.
- Multi-stage builds compile in one stage and copy only the result into a small final image.
- In a pod, command replaces the image's ENTRYPOINT and args replaces its CMD.
- Pin images by a specific tag or digest; imagePullPolicy defaults to Always for the latest tag and IfNotPresent otherwise.
Choosing a workload
- Deployment for stateless replicas, StatefulSet for stable identity and per-pod storage, DaemonSet for one pod per node.
- kubectl create job NAME --image=IMAGE -- COMMAND runs to completion; completions and parallelism control how many pods and how many at once; backoffLimit caps retries.
- kubectl create cronjob NAME --image=IMAGE --schedule="*/15 * * * *" -- COMMAND runs Jobs on a schedule.
- A CronJob's concurrencyPolicy is Allow, Forbid or Replace, and the history limits keep a number of finished Jobs.
- A Job's pods need restartPolicy Never or OnFailure.
Multi-container pods
- Containers in a pod share the network (localhost) and any volume both of them mount, but not their file systems.
- A sidecar extends the main container, for example by shipping its logs from a shared emptyDir.
- Init containers run one after another to completion before the application containers start.
- An init container with restartPolicy: Always is a native sidecar: it starts first and keeps running beside the main containers.
- kubectl logs POD -c CONTAINER and kubectl exec POD -c CONTAINER -- COMMAND address one container.
Volumes
- emptyDir is scratch space for the life of the pod and the usual way to share files between containers.
- A PersistentVolumeClaim requests durable storage; the pod mounts the claim by name.
- volumeMounts in each container say where a volume appears; the same volume can have different paths in different containers.
- readOnly: true on a mount protects the data from that container.
Easy to mix up
- command overrides ENTRYPOINT; args overrides CMD.
- Init containers finish before the app starts; sidecars run alongside it.
- Forbid skips a new CronJob run while the last is still going; Replace kills the old one.
- completions is how many pods must succeed; parallelism is how many run at the same time.