Domain 2 · Container orchestration
28% of the exam. How Pods reach each other and the outside world, how a cluster is secured, how storage attaches to Pods, and how you tell what broke.
Domain 2 is the second-largest slice of the exam. Questions here assume you already know the objects from Domain 1 and ask what happens between them: which component routes a packet, which object grants a permission, which resource provisions a disk, and which status field tells you why a Pod isn't running.
| Competency | What it's really asking | Pages |
|---|---|---|
| 2.1 Networking | The flat Pod network and who implements it (CNI), how Services and DNS give Pods stable names, how traffic gets in (Ingress, Gateway API), how NetworkPolicies restrict it, and what a service mesh adds on top | Networking, Service mesh |
| 2.2 Security | The 4Cs, the API request path (authentication, authorization, admission), ServiceAccounts, Pod Security Standards, Secrets, and keeping images trustworthy | Security |
| 2.3 Troubleshooting | Reading Pod phases, container states and events, and mapping a status like CrashLoopBackOff or Pending to its usual cause | Troubleshooting |
| 2.4 Storage | Ephemeral vs persistent volumes, the PV and PVC split, StorageClasses and dynamic provisioning, CSI drivers, and per-replica storage in StatefulSets | Storage |
What connects Domain 2 to the rest of the exam:
- Every object here is created through the API server described in Architecture, and RBAC basics start in API and kubectl.
- Troubleshooting overlaps with hands-on Debugging in Domain 3,
which covers
kubectl exec,port-forwardand ephemeral containers. - Mesh and network telemetry feed Observability, and project maturity levels (Istio, Linkerd, Cilium are all graduated) are in CNCF ecosystem.
- For hands-on depth on the same topics, see the CKA handbook's Services and networking and Storage domains.
Kubernetes does it by itself
Many wrong options credit Kubernetes core with work a plug-in does. Kubernetes defines the networking model, but a CNI plugin assigns Pod IPs and enforces NetworkPolicies. It defines Ingress, but an Ingress controller serves the traffic. It defines PVCs, but a CSI driver creates the disk. When a question asks "what actually does this?", the answer is often the plug-in, not the API object.
Containers and runtimes
What a container really is, images and layers, tags and digests, the three OCI specs, registries, the CRI, containerd and CRI-O, low-level runtimes, and sandboxed runtimes with RuntimeClass.
Kubernetes networking
The Kubernetes networking model, CNI plugins, Service types and kube-proxy, cluster DNS names, Ingress vs Gateway API, and NetworkPolicies for KCNA.