Pods, Nodes & Services
The fleet
Pods, Nodes, Deployments, self-healing, labels and selectors, Services
- Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)
- Understand Deployments and how to perform rolling updates
- Provide and troubleshoot access to applications via services
Design and BuildDeploymentServices and Networking
ConfigMaps, Secrets & CrashLoopBackOff
Scrolls, sealed amphorae, the Cyclops’s curse
ConfigMaps, creating and consuming Secrets, env vars vs. files, CrashLoopBackOff, logs --previous
- Utilize container logs
- Debugging in Kubernetes
- Understand ConfigMaps
- Create & consume Secrets
Environment, Configuration and SecurityObservability and Maintenance
Ingress
The harbor gate
Ingress rules, controllers, path matching, TLS, Service types
- Provide and troubleshoot access to applications via services
- Use Ingress rules to expose applications
Services and Networking
Namespaces
Greek city-states
Namespaces, ResourceQuota, cross-namespace DNS, cluster-wide things
- Understand requests, limits, quotas
Environment, Configuration and Security
Volumes
Sea chests and storehouses
emptyDir, PersistentVolumes, PersistentVolumeClaims, StorageClasses
- Utilize persistent and ephemeral volumes
Design and Build
Probes & health checks
The ship’s lookout
Liveness, readiness and startup probes; HTTP, TCP, exec and gRPC checks; timing defaults; exam drill
- Implement probes and health checks
Observability and Maintenance
Requests, limits & quotas
Cargo weight
Requests and limits, scheduling and Pending, OOMKilled, LimitRange, quotas in depth; placing Pods on Nodes; autoscaling
- Understand requests, limits, quotas
- Define resource requirements
- Placing Pods on Nodes: nodeSelector, affinity, taints and tolerations
- Autoscaling with the HorizontalPodAutoscaler
Environment, Configuration and Security
Rolling updates & deployment strategies
Refitting the fleet at sea
Rolling updates, rollout history and undo, blue/green and canary with labels
- Use Kubernetes primitives to implement common deployment strategies (e.g. blue/green or canary)
- Understand Deployments and how to perform rolling updates
Deployment
The right ship for the job
A navy of different vessels
Deployment vs. DaemonSet vs. StatefulSet vs. Job vs. CronJob
- Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)
Design and Build
Multi-container Pods
A crew of specialists
Init containers, sidecars (native sidecars too), shared volumes between containers
- Understand multi-container Pod design patterns (e.g. sidecar, init and others)
Design and Build
Building container images
The shipyard
Dockerfiles / Containerfiles, build, tag, push, multi-stage builds, editing an image
- Define, build and modify container images
Design and Build
Helm & Kustomize
Ship plans and tailored plans
Helm repos, install, upgrade, rollback, values; Kustomize bases and overlays
- Use the Helm package manager to deploy existing packages
- Kustomize
Deployment
Logs, monitoring & debugging
The ship’s log
kubectl logs, describe, events, top, exec, debug; a troubleshooting routine
- Use built-in CLI tools to monitor Kubernetes applications
- Utilize container logs
- Debugging in Kubernetes
Observability and Maintenance
Security on deck
The crew’s oath
SecurityContexts, runAsNonRoot, capabilities, read-only filesystems, ServiceAccounts, Pod Security admission
- Understand ServiceAccounts
- Understand Application Security (SecurityContexts, Capabilities, etc.)
- Understand authentication, authorization and admission control (Pod Security admission)
Environment, Configuration and Security
Authentication, RBAC & admission
The city council
Who you are, what you may do (Roles, RoleBindings), admission control, kubectl auth can-i
- Understand authentication, authorization and admission control
Environment, Configuration and Security
NetworkPolicy & troubleshooting Services
City walls
Default-allow, deny-all, allow rules by label and namespace; fixing selectors, ports and endpoints
- Demonstrate basic understanding of NetworkPolicies
- Provide and troubleshoot access to applications via services
Services and Networking
CRDs, Operators & API deprecations
New kinds in the harbor
Custom resources with schemas, Operators, kubectl api-resources, deprecation policy, migrating deprecated API versions with kubectl convert
- Understand API deprecations
- Discover and use resources that extend Kubernetes (CRD, Operators)
Environment, Configuration and SecurityObservability and Maintenance
Thoth's toolkit: vim and the shell
A scribe comes ashore
Between Chapter 17 and Exam day: the editor and shell habits behind every task. Modes, cut and paste, search, dry-run manifests, redirects, and a drill that mixes them
Exam day
The race
kubectl speed, imperative commands, contexts and namespaces, using the docs, a practice run, guarded by the Sphinx
Design and BuildDeploymentObservability and MaintenanceEnvironment, Configuration and SecurityServices and Networking
CKAD coverage checklist
The five exam domains with their weights, every competency listed in the curriculum, and the chapter that teaches it.
Application Design and Build · 20% of the exam
Define, build and modify container imagesCh. 11
Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.)Ch. 1, Ch. 7, Ch. 9
Understand multi-container Pod design patterns (e.g. sidecar, init and others)Ch. 10
Utilize persistent and ephemeral volumesCh. 5
Application Deployment · 20% of the exam
Use Kubernetes primitives to implement common deployment strategies (e.g. blue/green or canary)Ch. 8
Understand Deployments and how to perform rolling updatesCh. 1, Ch. 8
Use the Helm package manager to deploy existing packagesCh. 12
KustomizeCh. 12
Application Observability and Maintenance · 15% of the exam
Understand API deprecationsCh. 17
Implement probes and health checksCh. 6
Use built-in CLI tools to monitor Kubernetes applicationsCh. 7, Ch. 13
Utilize container logsCh. 2, Ch. 13
Debugging in KubernetesCh. 2, Ch. 13
Application Environment, Configuration and Security · 25% of the exam
Discover and use resources that extend Kubernetes (CRD, Operators)Ch. 17
Understand authentication, authorization and admission controlCh. 14, Ch. 15
Understand requests, limits, quotasCh. 4, Ch. 7
Understand ConfigMapsCh. 2
Define resource requirementsCh. 7
Create & consume SecretsCh. 2
Understand ServiceAccountsCh. 14, Ch. 15
Understand Application Security (SecurityContexts, Capabilities, etc.)Ch. 14
Services and Networking · 20% of the exam
Demonstrate basic understanding of NetworkPoliciesCh. 16
Provide and troubleshoot access to applications via servicesCh. 1, Ch. 3, Ch. 16
Use Ingress rules to expose applicationsCh. 3