Domain 2 · Workloads and scheduling
15% of the exam. Rolling out and rolling back Deployments, injecting configuration, autoscaling, self-healing controllers, and controlling where Pods land and how much they may use.
Domain 2 tasks hand you a namespace and an app and ask you to change how it runs: ship a new image without downtime and undo it, feed it settings and credentials, scale it on load, keep it alive when containers or nodes fail, and pin it to (or keep it off) particular nodes. Most tasks are short, so they are cheap points if you know the exact field or command.
| Competency | What it's really asking | Pages |
|---|---|---|
| 2.1 Deployments, rolling updates and rollbacks | Change an image, tune maxSurge/maxUnavailable, read rollout history and undo to a named revision | Deployments and rollouts |
| 2.2 ConfigMaps and Secrets | Create them from literals and files, consume them as env vars or volumes, and know when a change reaches the Pod | ConfigMaps and Secrets |
| 2.3 Workload autoscaling | Scale by hand, create an HPA that actually reports metrics, know what VPA and in-place resize do | Autoscaling |
| 2.4 Robust, self-healing deployments | Pick the right controller, add probes and restart policies, run sidecars and protect Pods with a PodDisruptionBudget | Self-healing workloads |
| 2.5 Pod admission and scheduling | Requests and limits, QoS, LimitRange and ResourceQuota at admission; selectors, affinity, taints and spread at scheduling | Resources and quotas, Pod placement |
What connects Domain 2 to the rest of the exam:
- A Pod stuck in
PendingorCrashLoopBackOffis usually a Domain 2 setting gone wrong. The diagnosis steps live in Troubleshooting applications. - The HPA depends on metrics-server, which you also use for
kubectl topin Resource usage. - StatefulSets pair with per-replica volumes from Persistent volumes.
- Draining a node during an upgrade respects the PodDisruptionBudgets you write here; see Cluster upgrades.
Editing the Pod instead of its owner
If a Pod belongs to a Deployment, ReplicaSet, StatefulSet or DaemonSet, edits to the Pod are lost when the
controller replaces it, and most Pod spec fields can't be edited at all. Change the owner's template (kubectl edit deploy, kubectl set image deploy/...). Check metadata.ownerReferences when you aren't sure who owns a
Pod.
CRDs and operators
Writing a CustomResourceDefinition with a schema, versions and printer columns, working with custom resources through kubectl, and installing and checking an operator.
Deployments, rolling updates and rollbacks
How a Deployment rolls out a new revision through ReplicaSets, tuning maxSurge and maxUnavailable, Recreate, kubectl rollout history, undo, pause and restart, and spotting a stalled rollout.