Asterrr's Handbook

The CKA exam

Format, domain weights, the competency numbering used in this handbook, and a terminal setup that saves minutes on every task.

Format

2 hours
Online, proctored, performance-based. You solve tasks in a remote Linux desktop with a terminal and a browser.
15–20 tasks
Each task shows its weight. Tasks run on different clusters or hosts, and each one tells you which to use.
66%
Passing score. Partial credit is possible, so finish what you can on a task before moving on.
v1.35
Kubernetes version the exam environment runs. It moves to new minor releases within a couple of months.
1 retake
A free retake is included, plus two sessions of the exam simulator.
2 years
Certification validity.

You can open the Kubernetes documentation (kubernetes.io/docs and the blog) in the exam browser. Check the current candidate handbook for the full list of allowed sites; nothing else, including your own notes, is allowed.

Where the points are

DomainWeightWhat you'll do
1 · Cluster architecture, installation and configuration25%Grant access with RBAC, build and upgrade clusters with kubeadm, back up etcd, install components with Helm and Kustomize
2 · Workloads and scheduling15%Roll out and roll back Deployments, wire in configuration, autoscale, steer Pods to nodes
3 · Services and networking20%Expose apps with Services, Ingress and Gateway API, restrict traffic with NetworkPolicies, work with CoreDNS
4 · Storage10%Create PVs, PVCs and StorageClasses and mount them
5 · Troubleshooting30%Fix nodes, control plane components, failing apps and broken networking

Competency numbers

The curriculum lists competencies without numbers. This handbook numbers them in curriculum order, and each page's Exam tasks line uses these numbers.

DomainCompetencies
1 · Cluster architecture1.1 Manage RBAC · 1.2 Prepare infrastructure for a cluster · 1.3 Create and manage clusters with kubeadm · 1.4 Manage the cluster lifecycle · 1.5 Implement a highly available control plane · 1.6 Use Helm and Kustomize to install cluster components · 1.7 Understand extension interfaces (CNI, CSI, CRI) · 1.8 Understand CRDs, install and configure operators
2 · Workloads and scheduling2.1 Deployments, rolling updates and rollbacks · 2.2 ConfigMaps and Secrets · 2.3 Workload autoscaling · 2.4 Primitives for robust, self-healing deployments · 2.5 Pod admission and scheduling (limits, node affinity)
3 · Services and networking3.1 Connectivity between Pods · 3.2 Network Policies · 3.3 ClusterIP, NodePort, LoadBalancer and endpoints · 3.4 Gateway API for ingress traffic · 3.5 Ingress controllers and resources · 3.6 CoreDNS
4 · Storage4.1 StorageClasses and dynamic provisioning · 4.2 Volume types, access modes and reclaim policies · 4.3 PVs and PVCs
5 · Troubleshooting5.1 Clusters and nodes · 5.2 Cluster components · 5.3 Resource usage of clusters and apps · 5.4 Container output streams · 5.5 Services and networking

Set up your terminal first

Spend the first minute on this. It pays back on every task.

alias k=kubectl                      # usually preconfigured; check with `type k`
export do="--dry-run=client -o yaml" # k create deploy web --image=nginx $do > web.yaml
export now="--force --grace-period=0" # k delete pod web $now
source <(kubectl completion bash); complete -o default -F __start_kubectl k
HabitWhy
Run the task's kubectl config use-context … line every timeEach task can use a different cluster. Work done on the wrong one scores zero
Generate YAML with create … $do, then editFaster and fewer indentation errors than typing manifests from scratch
k explain pod.spec.containers --recursive | lessField names without leaving the terminal
k get … -o wide, --show-labels, -AMost "what's wrong" answers are visible in one wide listing
ssh to the node for kubelet, etcd and static Pod tasks, then exitNode-level work happens on the node; the next task's context starts back on the base host

Exam signal

Verify every task the way a grader would: k get the object, check its status, and for anything with traffic (Services, Ingress, NetworkPolicies) test it from a temporary Pod, for example k run t --rm -it --image=busybox -- wget -qO- http://svc:80.

Editing in the wrong place

Fields such as a Pod's containers, a Deployment's selector, or a PVC's storage class can't be changed in place. If kubectl edit refuses, it saves a copy under /tmp; replace the object with k replace --force -f on that copy instead of fighting the editor.

If your material is older

Older material saysUse now
Docker as the node runtime, docker ps on nodescontainerd or CRI-O through the CRI, crictl ps
PodSecurityPolicyPod Security Admission with the Pod Security Standards
kubectl run creating Deploymentskubectl run creates a Pod only; use kubectl create deployment
autoscaling/v2beta2 HorizontalPodAutoscalerautoscaling/v2
Ingress as the only way inGateway API (GatewayClass, Gateway, HTTPRoute) is in the curriculum alongside Ingress
Package repos at apt.kubernetes.ioCommunity repos at pkgs.k8s.io, one repo per minor version
etcdctl snapshot restoreetcdutl snapshot restore (the etcdctl form is deprecated)
Scenario
A task worth 7% says: 'Use context k8s-c2. Create a Deployment named api with 3 replicas of image nginx:1.27 in namespace shop.' You finish it in 90 seconds on the cluster that was active from the previous task, and `kubectl get deploy -n shop` shows 3/3 ready. What score should you expect for the task?

Further reading

On this page