CNCF CKAD Hands-on 16 tasks 2 hours

Certified Kubernetes Application Developer

A hands-on exam for people who ship applications on Kubernetes: build, configure, expose and debug workloads from the command line, graded on the resulting cluster state. Covered: images, Jobs and CronJobs, DaemonSets, multi-container pods and native sidecars, rollouts, Helm, Kustomize, probes, ConfigMaps, Secrets, security contexts, Services and Ingress. Not simulated yet: custom resources and operators. NetworkPolicies are enforced between pods, so a policy can be tested with kubectl exec. ResourceQuotas and LimitRanges refuse what goes over them, and two tasks are about pods a namespace refuses; the older NetworkPolicy and ResourceQuota tasks grade the object you write.

The blueprint

A mock lab here has 16 tasks in 2 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 66%. FixOps scores practice against a target of 66%.

  1. 01

    Application Design and Build

    20%

  2. 02

    Application Deployment

    20%

  3. 03

    Application Observability and Maintenance

    15%

  4. 04

    Application Environment, Configuration and Security

    25%

  5. 05

    Services and Networking

    20%

The free sample lab

Two tasks from the bank, in a simulated cluster you drive with kubectl and helm. You are graded on the state you leave behind, not on the commands you type.

  • Add a log-shipping sidecar. Create a two-container pod whose containers share a volume.
  • A crash loop with the answer in the logs. Read the logs of a crash-looping Deployment and supply the setting it asks for.

Revision notes: Application Design and Build

The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.

Building images, choosing the right workload resource, composing multi-container pods and using volumes.

Images

  • A Dockerfile's FROM names the base image, COPY adds files, RUN executes at build time, and CMD or ENTRYPOINT is what runs at start.
  • Multi-stage builds compile in one stage and copy only the result into a small final image.
  • In a pod, command replaces the image's ENTRYPOINT and args replaces its CMD.
  • Pin images by a specific tag or digest; imagePullPolicy defaults to Always for the latest tag and IfNotPresent otherwise.

Choosing a workload

  • Deployment for stateless replicas, StatefulSet for stable identity and per-pod storage, DaemonSet for one pod per node.
  • kubectl create job NAME --image=IMAGE -- COMMAND runs to completion; completions and parallelism control how many pods and how many at once; backoffLimit caps retries.
  • kubectl create cronjob NAME --image=IMAGE --schedule="*/15 * * * *" -- COMMAND runs Jobs on a schedule.
  • A CronJob's concurrencyPolicy is Allow, Forbid or Replace, and the history limits keep a number of finished Jobs.
  • A Job's pods need restartPolicy Never or OnFailure.

Multi-container pods

  • Containers in a pod share the network (localhost) and any volume both of them mount, but not their file systems.
  • A sidecar extends the main container, for example by shipping its logs from a shared emptyDir.
  • Init containers run one after another to completion before the application containers start.
  • An init container with restartPolicy: Always is a native sidecar: it starts first and keeps running beside the main containers.
  • kubectl logs POD -c CONTAINER and kubectl exec POD -c CONTAINER -- COMMAND address one container.

Volumes

  • emptyDir is scratch space for the life of the pod and the usual way to share files between containers.
  • A PersistentVolumeClaim requests durable storage; the pod mounts the claim by name.
  • volumeMounts in each container say where a volume appears; the same volume can have different paths in different containers.
  • readOnly: true on a mount protects the data from that container.

Easy to mix up

  • command overrides ENTRYPOINT; args overrides CMD.
  • Init containers finish before the app starts; sidecars run alongside it.
  • Forbid skips a new CronJob run while the last is still going; Replace kills the old one.
  • completions is how many pods must succeed; parallelism is how many run at the same time.

Practice tasks written by FixOps from the public CKAD curriculum (Kubernetes v1.37). They are not real exam tasks and run in a simulator, not a live cluster. FixOps is not affiliated with or endorsed by the Linux Foundation or the CNCF.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.