Domain 1 · Kubernetes fundamentals
44% of the exam. What each cluster component and object does, how you talk to the API, how the scheduler places Pods, and how containers and runtimes fit underneath.
Domain 1 is almost half the exam, and nearly every question is a matching exercise: the stem describes a job ("stores cluster state", "restarts failed containers", "keeps three copies running") and the options are real Kubernetes names that each do a different job. Learn what each piece is responsible for, and just as importantly what it is not responsible for.
| Competency | What it's really asking | Pages |
|---|---|---|
| 1.1 Kubernetes core concepts | Which control plane or node component does a job, and which object (Pod, Deployment, StatefulSet, DaemonSet, Job, Service, ConfigMap) fits a workload | Architecture, Core objects |
| 1.2 Administration | How the API is organized into groups and versions, declarative vs imperative kubectl, RBAC basics, and which tool builds which kind of cluster | API and kubectl |
| 1.3 Scheduling | How the scheduler filters and scores nodes, and how requests, selectors, affinity, taints and tolerations steer it | Scheduling |
| 1.4 Containerization | Images and layers, the OCI specs, registries, the CRI, containerd and CRI-O, and sandboxed runtimes | Containers and runtimes |
Read the diagram left to right and you have the domain: you declare an object, the API server stores it in etcd, controllers turn it into Pods, the scheduler places them, and the kubelet asks the runtime to start containers.
What connects Domain 1 to the rest of the exam:
- Services were introduced here, but how Pods actually reach each other (CNI, DNS, Ingress, Gateway API) is in Networking.
- RBAC basics are here; authentication, ServiceAccounts and Pod Security Standards are in Security.
- StatefulSets need persistent volumes, covered in Storage.
- Rolling out new versions of a Deployment (and Helm) is in Packaging and rollouts.
- Autoscaling and the declarative design ideas behind controllers are in Cloud native principles.
The API server does everything
The API server is the only component that talks to etcd, and every other component talks to it, so it's tempting to credit it with every job. It validates and stores objects; it doesn't place Pods (scheduler), create them from a Deployment (controller manager) or start containers (kubelet and the runtime).