Asterrr's Handbook

Domain 2 · Container orchestration

28% of the exam. How Pods reach each other and the outside world, how a cluster is secured, how storage attaches to Pods, and how you tell what broke.

Domain 2 is the second-largest slice of the exam. Questions here assume you already know the objects from Domain 1 and ask what happens between them: which component routes a packet, which object grants a permission, which resource provisions a disk, and which status field tells you why a Pod isn't running.

CompetencyWhat it's really askingPages
2.1 NetworkingThe flat Pod network and who implements it (CNI), how Services and DNS give Pods stable names, how traffic gets in (Ingress, Gateway API), how NetworkPolicies restrict it, and what a service mesh adds on topNetworking, Service mesh
2.2 SecurityThe 4Cs, the API request path (authentication, authorization, admission), ServiceAccounts, Pod Security Standards, Secrets, and keeping images trustworthySecurity
2.3 TroubleshootingReading Pod phases, container states and events, and mapping a status like CrashLoopBackOff or Pending to its usual causeTroubleshooting
2.4 StorageEphemeral vs persistent volumes, the PV and PVC split, StorageClasses and dynamic provisioning, CSI drivers, and per-replica storage in StatefulSetsStorage

What connects Domain 2 to the rest of the exam:

  • Every object here is created through the API server described in Architecture, and RBAC basics start in API and kubectl.
  • Troubleshooting overlaps with hands-on Debugging in Domain 3, which covers kubectl exec, port-forward and ephemeral containers.
  • Mesh and network telemetry feed Observability, and project maturity levels (Istio, Linkerd, Cilium are all graduated) are in CNCF ecosystem.
  • For hands-on depth on the same topics, see the CKA handbook's Services and networking and Storage domains.

Kubernetes does it by itself

Many wrong options credit Kubernetes core with work a plug-in does. Kubernetes defines the networking model, but a CNI plugin assigns Pod IPs and enforces NetworkPolicies. It defines Ingress, but an Ingress controller serves the traffic. It defines PVCs, but a CSI driver creates the disk. When a question asks "what actually does this?", the answer is often the plug-in, not the API object.