The CKA exam
Format, domain weights, the competency numbering used in this handbook, and a terminal setup that saves minutes on every task.
Format
You can open the Kubernetes documentation (kubernetes.io/docs and the blog) in the exam browser. Check the current candidate handbook for the full list of allowed sites; nothing else, including your own notes, is allowed.
Where the points are
| Domain | Weight | What you'll do |
|---|---|---|
| 1 · Cluster architecture, installation and configuration | 25% | Grant access with RBAC, build and upgrade clusters with kubeadm, back up etcd, install components with Helm and Kustomize |
| 2 · Workloads and scheduling | 15% | Roll out and roll back Deployments, wire in configuration, autoscale, steer Pods to nodes |
| 3 · Services and networking | 20% | Expose apps with Services, Ingress and Gateway API, restrict traffic with NetworkPolicies, work with CoreDNS |
| 4 · Storage | 10% | Create PVs, PVCs and StorageClasses and mount them |
| 5 · Troubleshooting | 30% | Fix nodes, control plane components, failing apps and broken networking |
Competency numbers
The curriculum lists competencies without numbers. This handbook numbers them in curriculum order, and each page's Exam tasks line uses these numbers.
| Domain | Competencies |
|---|---|
| 1 · Cluster architecture | 1.1 Manage RBAC · 1.2 Prepare infrastructure for a cluster · 1.3 Create and manage clusters with kubeadm · 1.4 Manage the cluster lifecycle · 1.5 Implement a highly available control plane · 1.6 Use Helm and Kustomize to install cluster components · 1.7 Understand extension interfaces (CNI, CSI, CRI) · 1.8 Understand CRDs, install and configure operators |
| 2 · Workloads and scheduling | 2.1 Deployments, rolling updates and rollbacks · 2.2 ConfigMaps and Secrets · 2.3 Workload autoscaling · 2.4 Primitives for robust, self-healing deployments · 2.5 Pod admission and scheduling (limits, node affinity) |
| 3 · Services and networking | 3.1 Connectivity between Pods · 3.2 Network Policies · 3.3 ClusterIP, NodePort, LoadBalancer and endpoints · 3.4 Gateway API for ingress traffic · 3.5 Ingress controllers and resources · 3.6 CoreDNS |
| 4 · Storage | 4.1 StorageClasses and dynamic provisioning · 4.2 Volume types, access modes and reclaim policies · 4.3 PVs and PVCs |
| 5 · Troubleshooting | 5.1 Clusters and nodes · 5.2 Cluster components · 5.3 Resource usage of clusters and apps · 5.4 Container output streams · 5.5 Services and networking |
Set up your terminal first
Spend the first minute on this. It pays back on every task.
alias k=kubectl # usually preconfigured; check with `type k`
export do="--dry-run=client -o yaml" # k create deploy web --image=nginx $do > web.yaml
export now="--force --grace-period=0" # k delete pod web $now
source <(kubectl completion bash); complete -o default -F __start_kubectl k| Habit | Why |
|---|---|
Run the task's kubectl config use-context … line every time | Each task can use a different cluster. Work done on the wrong one scores zero |
Generate YAML with create … $do, then edit | Faster and fewer indentation errors than typing manifests from scratch |
k explain pod.spec.containers --recursive | less | Field names without leaving the terminal |
k get … -o wide, --show-labels, -A | Most "what's wrong" answers are visible in one wide listing |
ssh to the node for kubelet, etcd and static Pod tasks, then exit | Node-level work happens on the node; the next task's context starts back on the base host |
Exam signal
Verify every task the way a grader would: k get the object, check its status, and for anything with traffic
(Services, Ingress, NetworkPolicies) test it from a temporary Pod, for example
k run t --rm -it --image=busybox -- wget -qO- http://svc:80.
Editing in the wrong place
Fields such as a Pod's containers, a Deployment's selector, or a PVC's storage class can't be changed in place.
If kubectl edit refuses, it saves a copy under /tmp; replace the object with k replace --force -f on that
copy instead of fighting the editor.
If your material is older
| Older material says | Use now |
|---|---|
Docker as the node runtime, docker ps on nodes | containerd or CRI-O through the CRI, crictl ps |
| PodSecurityPolicy | Pod Security Admission with the Pod Security Standards |
kubectl run creating Deployments | kubectl run creates a Pod only; use kubectl create deployment |
autoscaling/v2beta2 HorizontalPodAutoscaler | autoscaling/v2 |
| Ingress as the only way in | Gateway API (GatewayClass, Gateway, HTTPRoute) is in the curriculum alongside Ingress |
Package repos at apt.kubernetes.io | Community repos at pkgs.k8s.io, one repo per minor version |
etcdctl snapshot restore | etcdutl snapshot restore (the etcdctl form is deprecated) |
Graders check the cluster the task names. The previous task's context was still active, so the Deployment lives
on a different cluster. Running the use-context command at the start of every task is the cheapest point
protection on the exam.
Further reading
How to use this handbook
Task-first notes for the CKA. Each page is a job you do on a live cluster, with the commands that get it done fast.
Domain 1 · Cluster architecture, installation and configuration
25% of the exam. Granting access with RBAC, building, upgrading and backing up kubeadm clusters, HA control planes, Helm and Kustomize, plugin interfaces, CRDs and operators.