The voyage to CKAD

Every competency in the official CKAD curriculum has a home in a chapter. Chapters 1 to 17 are built in the full format (illustrated scenes, hands-on pages, exam drill, quiz); the exam-day appendix is being written. Each chapter has a cover and opening page, New words on deck, a step-by-step page, an interactive page and a recap.

Chapter 1

Done

Pods, Nodes & Services

The fleet

Pods, Nodes, Deployments, self-healing, labels and selectors, Services

  • Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)
  • Understand Deployments and how to perform rolling updates
  • Provide and troubleshoot access to applications via services
Design and BuildDeploymentServices and Networking

Chapter 2

Done

ConfigMaps, Secrets & CrashLoopBackOff

Scrolls, sealed amphorae, the Cyclops’s curse

ConfigMaps, creating and consuming Secrets, env vars vs. files, CrashLoopBackOff, logs --previous

  • Utilize container logs
  • Debugging in Kubernetes
  • Understand ConfigMaps
  • Create & consume Secrets
Environment, Configuration and SecurityObservability and Maintenance

Chapter 3

Done

Ingress

The harbor gate

Ingress rules, controllers, path matching, TLS, Service types

  • Provide and troubleshoot access to applications via services
  • Use Ingress rules to expose applications
Services and Networking

Chapter 4

Done

Namespaces

Greek city-states

Namespaces, ResourceQuota, cross-namespace DNS, cluster-wide things

  • Understand requests, limits, quotas
Environment, Configuration and Security

Chapter 5

Done

Volumes

Sea chests and storehouses

emptyDir, PersistentVolumes, PersistentVolumeClaims, StorageClasses

  • Utilize persistent and ephemeral volumes
Design and Build

Chapter 6

Done

Probes & health checks

The ship’s lookout

Liveness, readiness and startup probes; HTTP, TCP, exec and gRPC checks; timing defaults; exam drill

  • Implement probes and health checks
Observability and Maintenance

Chapter 7

Done

Requests, limits & quotas

Cargo weight

Requests and limits, scheduling and Pending, OOMKilled, LimitRange, quotas in depth; placing Pods on Nodes; autoscaling

  • Understand requests, limits, quotas
  • Define resource requirements
  • Placing Pods on Nodes: nodeSelector, affinity, taints and tolerations
  • Autoscaling with the HorizontalPodAutoscaler
Environment, Configuration and Security

Chapter 8

Done

Rolling updates & deployment strategies

Refitting the fleet at sea

Rolling updates, rollout history and undo, blue/green and canary with labels

  • Use Kubernetes primitives to implement common deployment strategies (e.g. blue/green or canary)
  • Understand Deployments and how to perform rolling updates
Deployment

Chapter 9

Done

The right ship for the job

A navy of different vessels

Deployment vs. DaemonSet vs. StatefulSet vs. Job vs. CronJob

  • Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)
Design and Build

Chapter 10

Done

Multi-container Pods

A crew of specialists

Init containers, sidecars (native sidecars too), shared volumes between containers

  • Understand multi-container Pod design patterns (e.g. sidecar, init and others)
Design and Build

Chapter 11

Done

Building container images

The shipyard

Dockerfiles / Containerfiles, build, tag, push, multi-stage builds, editing an image

  • Define, build and modify container images
Design and Build

Chapter 12

Done

Helm & Kustomize

Ship plans and tailored plans

Helm repos, install, upgrade, rollback, values; Kustomize bases and overlays

  • Use the Helm package manager to deploy existing packages
  • Kustomize
Deployment

Chapter 13

Done

Logs, monitoring & debugging

The ship’s log

kubectl logs, describe, events, top, exec, debug; a troubleshooting routine

  • Use built-in CLI tools to monitor Kubernetes applications
  • Utilize container logs
  • Debugging in Kubernetes
Observability and Maintenance

Chapter 14

Done

Security on deck

The crew’s oath

SecurityContexts, runAsNonRoot, capabilities, read-only filesystems, ServiceAccounts, Pod Security admission

  • Understand ServiceAccounts
  • Understand Application Security (SecurityContexts, Capabilities, etc.)
  • Understand authentication, authorization and admission control (Pod Security admission)
Environment, Configuration and Security

Chapter 15

Done

Authentication, RBAC & admission

The city council

Who you are, what you may do (Roles, RoleBindings), admission control, kubectl auth can-i

  • Understand authentication, authorization and admission control
Environment, Configuration and Security

Chapter 16

Done

NetworkPolicy & troubleshooting Services

City walls

Default-allow, deny-all, allow rules by label and namespace; fixing selectors, ports and endpoints

  • Demonstrate basic understanding of NetworkPolicies
  • Provide and troubleshoot access to applications via services
Services and Networking

Chapter 17

Done

CRDs, Operators & API deprecations

New kinds in the harbor

Custom resources with schemas, Operators, kubectl api-resources, deprecation policy, migrating deprecated API versions with kubectl convert

  • Understand API deprecations
  • Discover and use resources that extend Kubernetes (CRD, Operators)
Environment, Configuration and SecurityObservability and Maintenance

Interlude

Done

Thoth's toolkit: vim and the shell

A scribe comes ashore

Between Chapter 17 and Exam day: the editor and shell habits behind every task. Modes, cut and paste, search, dry-run manifests, redirects, and a drill that mixes them

Appendix

In progress

Exam day

The race

kubectl speed, imperative commands, contexts and namespaces, using the docs, a practice run, guarded by the Sphinx

Design and BuildDeploymentObservability and MaintenanceEnvironment, Configuration and SecurityServices and Networking

CKAD coverage checklist

The five exam domains with their weights, every competency listed in the curriculum, and the chapter that teaches it.

Application Design and Build · 20% of the exam

Define, build and modify container imagesCh. 11
Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)Ch. 1, Ch. 7, Ch. 9
Understand multi-container Pod design patterns (e.g. sidecar, init and others)Ch. 10
Utilize persistent and ephemeral volumesCh. 5

Application Deployment · 20% of the exam

Use Kubernetes primitives to implement common deployment strategies (e.g. blue/green or canary)Ch. 8
Understand Deployments and how to perform rolling updatesCh. 1, Ch. 8
Use the Helm package manager to deploy existing packagesCh. 12
KustomizeCh. 12

Application Observability and Maintenance · 15% of the exam

Understand API deprecationsCh. 17
Implement probes and health checksCh. 6
Use built-in CLI tools to monitor Kubernetes applicationsCh. 7, Ch. 13
Utilize container logsCh. 2, Ch. 13
Debugging in KubernetesCh. 2, Ch. 13

Application Environment, Configuration and Security · 25% of the exam

Discover and use resources that extend Kubernetes (CRD, Operators)Ch. 17
Understand authentication, authorization and admission controlCh. 14, Ch. 15
Understand requests, limits, quotasCh. 4, Ch. 7
Understand ConfigMapsCh. 2
Define resource requirementsCh. 7
Create & consume SecretsCh. 2
Understand ServiceAccountsCh. 14, Ch. 15
Understand Application Security (SecurityContexts, Capabilities, etc.)Ch. 14

Services and Networking · 20% of the exam

Demonstrate basic understanding of NetworkPoliciesCh. 16
Provide and troubleshoot access to applications via servicesCh. 1, Ch. 3, Ch. 16
Use Ingress rules to expose applicationsCh. 3