Domain 1 · Cluster architecture, installation and configuration
25% of the exam. Granting access with RBAC, building, upgrading and backing up kubeadm clusters, HA control planes, Helm and Kustomize, plugin interfaces, CRDs and operators.
Domain 1 is where you act as the person who owns the cluster, not the person deploying to it. Tasks drop you on
a node with sudo, a half-built or out-of-date cluster, and a short instruction: join this worker, upgrade the
control plane one minor version, save an etcd snapshot to a path, give a ServiceAccount exactly these permissions,
install this chart with that value. Most points are lost on order of operations and on files edited on the wrong
host.
| Competency | What it's really asking | Pages |
|---|---|---|
| 1.1 Manage RBAC | Write the smallest Role or ClusterRole and the right binding for a user, group or ServiceAccount, then prove it with kubectl auth can-i | RBAC |
| 1.2 Prepare infrastructure | Swap, kernel forwarding, a CRI runtime with the right cgroup driver, the pkgs.k8s.io repo and held packages | Installing with kubeadm |
| 1.3 Create and manage clusters with kubeadm | kubeadm init, a CNI, kubeadm join with a fresh token, kubeconfig for the admin | Installing with kubeadm |
| 1.4 Manage the cluster lifecycle | One-minor-at-a-time upgrades, drain and uncordon, certificate renewal, etcd snapshot and restore | Cluster upgrades, etcd backup and restore |
| 1.5 Highly available control plane | Stacked vs external etcd, quorum maths, the load balancer endpoint, joining extra control plane nodes | HA control plane |
| 1.6 Helm and Kustomize | Install, upgrade and roll back a release with values; build an overlay and apply it with -k | Helm and Kustomize |
| 1.7 Extension interfaces | Which plugin the kubelet calls for containers (CRI), Pod networking (CNI) and volumes (CSI), and where each one is configured | Extension interfaces |
| 1.8 CRDs and operators | Read and create a CustomResourceDefinition, install an operator, and work with its custom resources | CRDs and operators |
What connects Domain 1 to the rest of the exam:
- A cluster you just built is only useful once Pod networking works. The networking model behind the CNI step is in Pod networking.
- CSI drivers from the extension interfaces page are what StorageClasses point at, covered in StorageClasses.
- When a kubeadm cluster stops answering after you edited a static Pod manifest, the recovery steps are in Troubleshooting the control plane and Troubleshooting nodes.
Running node commands from the wrong host
kubeadm, etcdctl, apt and edits under /etc/kubernetes/manifests act on the machine you're logged into.
Upgrading packages on the jump host, or saving a snapshot to /srv/backup on the base host when the task meant the
control plane node, leaves the graded cluster untouched. ssh to the node the task names, check hostname, and
exit when you're done.
The CKA exam
Format, domain weights, the competency numbering used in this handbook, and a terminal setup that saves minutes on every task.
RBAC
Roles and ClusterRoles, RoleBindings and ClusterRoleBindings, users, groups and ServiceAccounts as subjects, aggregated ClusterRoles, and proving access with kubectl auth can-i.