Asterrr's Handbook

Domain 1 · Cluster architecture, installation and configuration

25% of the exam. Granting access with RBAC, building, upgrading and backing up kubeadm clusters, HA control planes, Helm and Kustomize, plugin interfaces, CRDs and operators.

Domain 1 is where you act as the person who owns the cluster, not the person deploying to it. Tasks drop you on a node with sudo, a half-built or out-of-date cluster, and a short instruction: join this worker, upgrade the control plane one minor version, save an etcd snapshot to a path, give a ServiceAccount exactly these permissions, install this chart with that value. Most points are lost on order of operations and on files edited on the wrong host.

CompetencyWhat it's really askingPages
1.1 Manage RBACWrite the smallest Role or ClusterRole and the right binding for a user, group or ServiceAccount, then prove it with kubectl auth can-iRBAC
1.2 Prepare infrastructureSwap, kernel forwarding, a CRI runtime with the right cgroup driver, the pkgs.k8s.io repo and held packagesInstalling with kubeadm
1.3 Create and manage clusters with kubeadmkubeadm init, a CNI, kubeadm join with a fresh token, kubeconfig for the adminInstalling with kubeadm
1.4 Manage the cluster lifecycleOne-minor-at-a-time upgrades, drain and uncordon, certificate renewal, etcd snapshot and restoreCluster upgrades, etcd backup and restore
1.5 Highly available control planeStacked vs external etcd, quorum maths, the load balancer endpoint, joining extra control plane nodesHA control plane
1.6 Helm and KustomizeInstall, upgrade and roll back a release with values; build an overlay and apply it with -kHelm and Kustomize
1.7 Extension interfacesWhich plugin the kubelet calls for containers (CRI), Pod networking (CNI) and volumes (CSI), and where each one is configuredExtension interfaces
1.8 CRDs and operatorsRead and create a CustomResourceDefinition, install an operator, and work with its custom resourcesCRDs and operators

What connects Domain 1 to the rest of the exam:

Running node commands from the wrong host

kubeadm, etcdctl, apt and edits under /etc/kubernetes/manifests act on the machine you're logged into. Upgrading packages on the jump host, or saving a snapshot to /srv/backup on the base host when the task meant the control plane node, leaves the graded cluster untouched. ssh to the node the task names, check hostname, and exit when you're done.