All certifications / CKA / Cheat sheet
CKA CKA (Kubernetes v1.35 curriculum) cheat sheet
Domain 1: Cluster Architecture, Installation and Configuration (25%)
Exam tips
- Match the symptom to the component: Pods stuck Pending with no events points to the scheduler; replicas not being created points to the controller-manager; kubectl refused on 6443 points to the API server; a single node NotReady points to its kubelet or runtime.
- A cgroup driver mismatch does not always stop the install; it shows up later as flapping Pods or kubelet errors. Check
SystemdCgroup = truein the containerd config and restart containerd whenever you touch it. - Nodes NotReady and CoreDNS Pending immediately after init almost always mean no CNI plugin is installed yet, not a broken cluster.
- To change a control plane flag, edit the manifest in /etc/kubernetes/manifests on that node, never the mirror Pod through kubectl. Keep a backup copy of the manifest outside that directory, because every YAML file inside it is treated as a Pod.
- Upgrading the package is not enough: forgetting
systemctl daemon-reload && systemctl restart kubeletleaves the node reporting the old version. Also rememberupgrade applyonly on the first control plane node andupgrade nodeeverywhere else. - Snapshot save fails with a TLS or deadline error if you omit --cacert, --cert or --key; copy the paths straight from the etcd manifest instead of guessing. For restore, remember the hostPath volume is what actually decides which host directory etcd sees.
- Know the quorum math cold: 3 members survive 1 failure, 5 survive 2, and adding a fourth member to three does not improve fault tolerance. Also remember that the scheduler and controller-manager are active/passive while API servers are active/active.
- A RoleBinding that references a ClusterRole still only grants access in the RoleBinding's namespace. Also remember ServiceAccount subjects are written as system:serviceaccount:<namespace>:<name> when impersonating.
- The exam often wants
kubectl drain <node> --ignore-daemonsets(plus --delete-emptydir-data if needed). If drain errors about DaemonSet-managed Pods, you forgot --ignore-daemonsets; if it complains about unmanaged Pods, it needs --force. - Helm releases are namespaced:
helm listshows only the current namespace, so usehelm list -Awhen a release seems missing. And --version refers to the chart version, not the app version. - If kubectl is unavailable, crictl is your eyes on the node. Remember Flannel alone does not enforce NetworkPolicy; a policy that seems ignored may simply have no enforcing CNI.
- If
kubectl applysays 'no matches for kind', the CRD is missing or its group/version does not match the object's apiVersion. Usekubectl api-resourcesto see exactly which kinds and groups the cluster knows.
Key terms
- kube-apiserver
- The central REST API for the cluster; the only component that reads and writes etcd, and the one every other component talks to.
- etcd
- A consistent, distributed key-value store holding all cluster state.
- kube-scheduler
- Assigns unscheduled Pods to nodes by filtering and scoring candidate nodes.
- kube-controller-manager
- A single binary running many reconciliation loops such as the ReplicaSet, Node and Job controllers.
- kubelet
- The node agent, run by systemd, that starts Pods via the container runtime and reports status.
- kube-proxy
- The per-node component that programs Service virtual IP forwarding rules.
- cgroup driver
- How the kubelet and runtime create control groups; both must use the same one, normally systemd.
- br_netfilter
- A kernel module that lets iptables see traffic crossing a Linux bridge.
- net.ipv4.ip_forward
- The sysctl that allows the kernel to route packets between interfaces, required for Pod traffic.
- Preflight checks
- Tests kubeadm runs before init or join to catch host misconfiguration.
- --pod-network-cidr
- The IP range reserved for Pod addresses, which the CNI plugin allocates from.
- --control-plane-endpoint
- A shared, stable address for the API server, required for later HA expansion.
- Bootstrap token
- A short-lived token that lets a joining node authenticate to request its kubelet certificate.
- discovery-token-ca-cert-hash
- A hash of the cluster CA public key that the joining node uses to verify the control plane.
- Static Pod
- A Pod managed directly by a kubelet from a file in its staticPodPath, not by the API server.
- Mirror Pod
- The read-only API object the kubelet creates so a static Pod is visible to kubectl.
- kubeadm certs check-expiration
- Lists each kubeadm-managed certificate and when it expires.
- Kubeconfig context
- A named combination of a cluster, a user and a default namespace.
- kubeadm upgrade plan
- Checks upgradeability and lists target versions without changing anything.
- kubeadm upgrade apply
- Upgrades the first control plane node's components to a given version.
- kubeadm upgrade node
- Upgrades additional control plane nodes or updates a worker's kubelet config.
- Version skew policy
- Rules on how far component versions may differ; kubelets may never be newer than the API server.
- etcdctl
- The network client for a running etcd; used for snapshot save, member list and endpoint health.
- etcdutl
- The offline etcd utility for working with data files, including snapshot restore and status.
- Data directory
- The on-disk location of the etcd database, set by --data-dir and mounted via a hostPath volume.
- etcd PKI
- The separate CA and certificates under /etc/kubernetes/pki/etcd used for etcd mutual TLS.
- Stacked etcd
- Topology where each control plane node also runs an etcd member.
- External etcd
- Topology where etcd runs on separate hosts from the control plane.
- Quorum
- A majority of etcd members, floor(n/2)+1, needed to commit writes.
- --certificate-key
- The key used to decrypt control plane certificates uploaded by --upload-certs when joining as a control plane node.
- Leader election
- Mechanism that keeps only one scheduler and one controller-manager active across control plane nodes.
- Role / ClusterRole
- Sets of permission rules, namespaced or cluster-wide respectively.
- RoleBinding / ClusterRoleBinding
- Objects that grant a role to users, groups or ServiceAccounts, in one namespace or cluster-wide.
- Aggregated ClusterRole
- A ClusterRole whose rules are automatically assembled from other ClusterRoles matching a label selector.
- CertificateSigningRequest
- An API object that asks a signer, such as the kube-apiserver-client signer, to issue a certificate.
- Cordon
- Marks a node unschedulable without touching running Pods.
- Drain
- Cordons a node and evicts its Pods so they are rescheduled elsewhere.
- PodDisruptionBudget
- A policy limiting how many selected Pods can be down at once due to voluntary disruptions.
- Eviction API
- The API drain uses to remove Pods, which honours PodDisruptionBudgets.
- Chart
- A Helm package of templated Kubernetes manifests with default values.
- Release
- A named, installed instance of a chart in a namespace, with its own revision history.
- helm upgrade --install
- Installs a release if absent or upgrades it if present.
- kustomization.yaml
- The Kustomize file listing resources and transformations; applied with kubectl apply -k.
- CRI
- The gRPC interface the kubelet uses to control container runtimes such as containerd and CRI-O.
- crictl
- A command-line client for CRI runtimes, used for node-level debugging.
- CNI
- The specification and plugins that configure Pod network interfaces and IP addresses.
- CSI
- The standard interface for out-of-tree storage drivers that provision, attach and mount volumes.
- CustomResourceDefinition
- An object that registers a new resource type with the API server.
- Custom resource
- An instance of a type defined by a CRD, stored in etcd like any object.
- Operator
- A controller plus CRDs that automates running a specific application.
- Finalizer
- A key on an object that blocks its deletion until a controller performs cleanup and removes it.
Domain 2: Workloads and Scheduling (15%)
Exam tips
- Editing a Deployment's replica count does not create a new revision; only changes to the Pod template do. And never edit a ReplicaSet owned by a Deployment directly, because the Deployment will overwrite it.
- When a DaemonSet has fewer Pods than nodes, compare node taints (
kubectl describe node | grep -i taint) with the Pod template's tolerations and nodeSelector before anything else. - Env-var consumption never updates live; volume consumption does (except with subPath). If a task says 'make the Pods use the new value', restart the workload.
- Pods missing entirely usually means admission rejected them (quota or LimitRange), so look at ReplicaSet events. Pods existing but Pending usually means scheduling failed on insufficient requests.
- Terms are ORed, expressions within a term are ANDed. And a missing label with required affinity or nodeSelector means Pending forever, never a fallback.
- A toleration alone will not put a Pod on the tainted node; pair it with nodeSelector or affinity. Removing a taint uses the same command with a trailing minus sign.
- Read the topologyKey carefully: hostname means per node, zone means per zone. The same selector with a different key gives completely different placement.
- PriorityClass is cluster-scoped and Pods reference it by name; a typo in priorityClassName makes the Pod creation fail at admission. Only lower-priority Pods can be preempted.
<unknown>targets mean either metrics-server is missing or not working, or the Pods have no request for that resource. Checkkubectl topfirst, then the requests.- Pending with a FailedScheduling event means the scheduler ran and found no node. Pending with no events at all suggests the scheduler is not running or the Pod names a scheduler that does not exist.
Key terms
- ReplicaSet
- A controller that keeps a specified number of identical Pods running.
- Deployment
- A controller that manages ReplicaSets to provide declarative rolling updates and rollbacks.
- maxSurge / maxUnavailable
- RollingUpdate settings for extra Pods allowed and Pods allowed to be missing during an update.
- kubectl rollout restart
- Triggers a rolling replacement of all Pods by changing an annotation on the Pod template.
- DaemonSet
- A controller that runs one copy of a Pod on each eligible node.
- StatefulSet
- A controller giving Pods stable ordinal names, stable DNS and per-Pod persistent storage.
- Headless Service
- A Service with clusterIP None that publishes individual Pod DNS records, required by StatefulSets.
- Control plane taint
- node-role.kubernetes.io/control-plane:NoSchedule, which keeps ordinary Pods off control plane nodes.
- ConfigMap
- An object holding non-confidential configuration as key-value pairs.
- Secret
- An object for sensitive data; values are base64-encoded, not encrypted, by default.
- envFrom
- Imports every key of a ConfigMap or Secret as environment variables.
- Immutable ConfigMap/Secret
- An object with immutable: true whose data cannot be changed after creation.
- Request
- The amount of CPU or memory reserved for a container and used for scheduling decisions.
- Limit
- The maximum CPU (throttled) or memory (OOM-killed) a container may use.
- LimitRange
- A namespaced admission policy for per-container or per-Pod defaults, minimums and maximums.
- ResourceQuota
- A namespaced cap on aggregate resource usage and object counts.
- QoS class
- Guaranteed, Burstable or BestEffort, derived from requests and limits and used for eviction order.
- nodeName
- A Pod field that pins the Pod to a node directly, bypassing the scheduler.
- nodeSelector
- A simple label map a node must fully match for the Pod to be scheduled there.
- Required node affinity
- A hard scheduling rule; the Pod stays Pending if no node satisfies it.
- Preferred node affinity
- A weighted soft rule that influences scoring but does not block scheduling.
- Taint
- A key, value and effect on a node that repels Pods lacking a matching toleration.
- Toleration
- A Pod setting that allows, but does not force, scheduling on nodes with matching taints.
- NoExecute
- A taint effect that evicts running non-tolerating Pods as well as blocking new ones.
- tolerationSeconds
- How long a Pod tolerating a NoExecute taint may stay before eviction.
- topologyKey
- A node label whose value defines a topology domain such as a node or zone.
- Pod anti-affinity
- A rule keeping a Pod away from domains that already run Pods matching a selector.
- topologySpreadConstraints
- Rules limiting how unevenly matching Pods are distributed across domains.
- maxSkew
- The maximum allowed difference in matching Pod counts between any two domains.
- PriorityClass
- A cluster-scoped object assigning an integer priority to Pods that reference it.
- Preemption
- The scheduler evicting lower-priority Pods to make room for a higher-priority Pending Pod.
- globalDefault
- A PriorityClass flag making it the default for Pods that name no class.
- preemptionPolicy: Never
- Gives a class queue priority without allowing it to evict other Pods.
- HorizontalPodAutoscaler
- A controller that adjusts a workload's replica count to meet a metric target.
- metrics-server
- An add-on that collects CPU and memory usage from kubelets and serves the Resource Metrics API.
- averageUtilization
- A target expressed as a percentage of the Pods' resource requests.
- Vertical Pod Autoscaler
- An add-on that recommends or sets container requests based on observed usage.
- Cluster Autoscaler
- An add-on that adds or removes nodes based on Pending Pods and node utilization.
- Binding
- The act of assigning a Pod to a node, recorded by setting spec.nodeName.
- Mirror Pod
- The API representation of a static Pod, owned by the Node and not editable.
- schedulerName
- A Pod field naming which scheduler should place it, default-scheduler by default.
Domain 3: Services and Networking (20%)
Exam tips
- Remember which component owns which range: the Pod CIDR is used by the CNI and controller-manager, the Service CIDR by the API server and kube-proxy. They must not overlap each other or the node subnet.
- Do not use ping to test a ClusterIP; test the port. If one node cannot reach Services while others can, suspect that node's kube-proxy Pod first.
- port is the Service's port, targetPort is the container's port, nodePort is the node's port. Mixing up port and targetPort is the most common cause of a Service that exists but refuses connections.
- An empty EndpointSlice means the selector matches no Ready Pods; check labels and readiness before blaming kube-proxy. For externalTrafficPolicy, remember: Local preserves source IP, Cluster spreads load.
- Count the dashes: podSelector and namespaceSelector under one dash are ANDed, under separate dashes are ORed. And egress deny without a DNS exception breaks everything.
- If a route is ignored, check both sides of attachment: parentRefs (including sectionName and namespace) and the listener's allowedRoutes. The status conditions tell you which side refused.
- Prefix matching is by path segment, not string prefix: /app matches /app/x but not /application. And the TLS Secret must live in the same namespace as the Ingress.
- The Service is called kube-dns but the Pods and ConfigMap are called coredns. dnsPolicy Default is not the default; ClusterFirst is.
- Always test from a Pod with the same namespace and labels as the real client, or NetworkPolicy results will mislead you. And busybox has wget, not curl.
Key terms
- Pod CIDR
- The address range from which Pod IPs are allocated, set at cluster creation.
- Service CIDR
- The address range for Service ClusterIPs, set by --service-cluster-ip-range.
- Pause container
- The sandbox container that holds a Pod's shared network namespace.
- Overlay network
- An encapsulation (such as VXLAN) that carries Pod traffic between nodes over the node network.
- ClusterIP
- A virtual IP for a Service, implemented as forwarding rules rather than a real interface.
- iptables mode
- kube-proxy mode that uses NAT chains (KUBE-SERVICES, KUBE-SVC, KUBE-SEP) to forward Service traffic.
- IPVS mode
- kube-proxy mode using the kernel's IP Virtual Server hash-based load balancer.
- nftables mode
- kube-proxy mode that programs rules with the nftables framework.
- NodePort
- A Service type that also opens a port in the 30000–32767 range on every node.
- LoadBalancer
- A Service type that requests an external load balancer from a cloud controller or MetalLB.
- Headless Service
- A Service with clusterIP None whose DNS name resolves to Pod IPs directly.
- ExternalName
- A Service that returns a DNS CNAME to an external hostname, with no proxying.
- EndpointSlice
- An object listing a subset of a Service's backend addresses, ports and readiness conditions.
- Selectorless Service
- A Service without a selector whose EndpointSlices you manage manually.
- externalTrafficPolicy: Local
- Only node-local Pods receive external traffic, preserving the client source IP.
- sessionAffinity: ClientIP
- Routes a given client IP consistently to the same backend Pod.
- NetworkPolicy
- A namespaced object that allow-lists ingress and egress traffic for selected Pods.
- Default deny
- A policy selecting all Pods with no allow rules, blocking all traffic in the listed directions.
- namespaceSelector
- A peer selector matching all Pods in namespaces whose labels match.
- ipBlock
- A peer defined by a CIDR range, with optional exceptions.
- GatewayClass
- A cluster-scoped resource naming the controller that implements Gateways of that class.
- Gateway
- A request for a traffic entry point with one or more listeners.
- HTTPRoute
- Routing rules that attach to Gateway listeners via parentRefs and forward to backendRefs.
- allowedRoutes
- Listener setting controlling which namespaces and route kinds may attach.
- ReferenceGrant
- An object permitting cross-namespace references, such as a route to another namespace's Service.
- Ingress controller
- A proxy running in the cluster that implements Ingress objects.
- IngressClass
- A cluster-scoped object linking an Ingress to a specific controller.
- Default IngressClass
- The class annotated is-default-class true, used when an Ingress sets no ingressClassName.
- pathType
- Exact, Prefix (element-wise) or ImplementationSpecific path matching.
- Corefile
- CoreDNS's configuration, held in the coredns ConfigMap, made of server blocks and plugins.
- forward plugin
- Sends queries CoreDNS is not authoritative for to upstream resolvers.
- Stub zone
- A server block that forwards a specific domain to designated DNS servers.
- dnsPolicy
- Pod setting choosing ClusterFirst, Default, ClusterFirstWithHostNet or None DNS behaviour.
- kubectl run --rm -it
- Creates an interactive temporary Pod that is deleted when the session ends.
- busybox
- A minimal image with basic tools such as nslookup, wget and nc, but no curl.
- nicolaka/netshoot
- A troubleshooting image containing many networking tools including curl, dig and tcpdump.
- Connection refused vs timeout
- Refused means nothing listens on the port; timeout usually means traffic is dropped or unroutable.
Domain 4: Storage (10%)
Exam tips
- Pending PVCs are almost always a mismatch in storageClassName, access mode, size or selector. Compare the PVC and PV fields side by side with kubectl get -o yaml.
- RWO is per node, not per Pod. If the question says only one Pod may ever use the volume, the answer is ReadWriteOncePod.
- Dynamic provisioning defaults to Delete. If the exam asks you to preserve data behind a dynamically provisioned claim, patch the PV to Retain before deleting the PVC.
- Omitting storageClassName means 'use the default'; setting it to an empty string means 'no class'. They behave very differently.
- Pending with 'waiting for first consumer' is the expected state until a Pod uses the claim. Do not set nodeName on such Pods, because it skips the scheduler that triggers binding.
- Expand the PVC, never the PV, and only upwards. If the edit is rejected, check allowVolumeExpansion on the claim's StorageClass first.
- A local PV without nodeAffinity is rejected by the API server. And hostPath data stays on one node; if the Pod moves, its data does not.
- Default retention is Retain for both whenDeleted and whenScaled, so deleting a StatefulSet does not delete its data. PVC names follow template-statefulset-ordinal.
Key terms
- PersistentVolume
- A cluster-scoped object representing a piece of storage and its properties.
- PersistentVolumeClaim
- A namespaced request for storage that binds to a matching PV.
- Released
- PV phase after its claim is deleted, before the storage is reclaimed or manually freed.
- emptyDir
- A Pod-scoped scratch volume removed when the Pod leaves the node.
- ReadWriteOnce (RWO)
- Read-write by a single node; multiple Pods on that node may share it.
- ReadOnlyMany (ROX)
- Read-only by many nodes.
- ReadWriteMany (RWX)
- Read-write by many nodes, requiring shared file storage.
- ReadWriteOncePod (RWOP)
- Read-write by exactly one Pod cluster-wide, supported for CSI volumes.
- persistentVolumeReclaimPolicy
- The PV field deciding what happens to the volume after its claim is deleted.
- Retain
- Keeps the PV and data after the claim is deleted; the PV becomes Released.
- Delete
- Removes the PV and its backing storage when the claim is deleted.
- Recycle
- A deprecated policy that scrubbed the volume and made it Available again.
- StorageClass
- A cluster-scoped description of a type of storage and how to provision it.
- Provisioner
- The component, usually a CSI driver, that creates volumes for a StorageClass.
- Dynamic provisioning
- Automatic creation of a PV when a PVC requests a StorageClass.
- Default StorageClass
- The class annotated is-default-class true, applied to PVCs without storageClassName.
- volumeBindingMode
- StorageClass field controlling when PVCs bind: Immediate or WaitForFirstConsumer.
- Immediate
- Binds or provisions as soon as the PVC is created, regardless of Pod placement.
- WaitForFirstConsumer
- Delays binding until a Pod using the claim is scheduled, respecting topology.
- Volume node affinity conflict
- A scheduling failure where the Pod cannot run on any node the bound volume can reach.
- allowVolumeExpansion
- StorageClass flag permitting PVCs of that class to be enlarged.
- Online expansion
- Growing a volume's filesystem while the Pod using it keeps running.
- FileSystemResizePending
- A PVC condition indicating the filesystem will be resized when a Pod next mounts it.
- Static provisioning
- Creating PV objects manually for existing storage.
- hostPath
- A volume type mounting a directory from the node's filesystem; suitable for labs only.
- local volume
- A PV for node-attached storage that requires nodeAffinity to pin Pods to that node.
- NFS volume
- Network file storage identified by server and path, usable read-write from many nodes.
- CSI driver
- A vendor storage plugin, split into controller and per-node components, that implements CSI.
- volumeClaimTemplates
- StatefulSet field that creates one PVC per Pod ordinal.
- persistentVolumeClaimRetentionPolicy
- StatefulSet setting controlling whether PVCs are deleted when the set is deleted or scaled down.
- VolumeAttachment
- An object recording that a CSI volume is attached to a particular node.
Domain 5: Troubleshooting (30%)
Exam tips
- Ready Unknown means the kubelet has stopped reporting; Ready False means it reports a problem. In both cases,
systemctl status kubeletandjournalctl -u kubeleton the node are your first two commands. - No container at all in crictl ps -a means the manifest could not be parsed (check the kubelet journal); a crashing container means the component started but rejected its configuration (check crictl logs).
- Read the whole FailedScheduling message: the counts tell you why each group of nodes was rejected, and the fix differs for each. Remember the scheduler uses requests, not live usage.
- kubectl top shows real usage; describe node shows requests and limits. Scheduling decisions are based on requests, so 'low usage but Pods won't schedule' is a requests problem.
- For a CrashLoopBackOff, the useful output is almost always in
kubectl logs <pod> --previous. For multi-container Pods, always specify -c. - Events are not sorted by time by default and expire after about an hour; add --sort-by and filter with --field-selector type=Warning to cut the noise quickly.
- Empty endpoints means selector or readiness; endpoints present but refused means targetPort or the app; works on one node but not another means kube-proxy or the CNI on that node.
- CoreDNS in CrashLoopBackOff with a 'Loop detected' log line is the systemd-resolved stub problem; fix the kubelet's resolvConf or the forward target, not the loop plugin.
- Refused means nothing is listening (API server down or wrong address); x509 means certificates; Unauthorized means credentials; Forbidden means RBAC. The error tells you which layer to fix.
- Single-quote jsonpath expressions, check the object structure with -o yaml before writing the path, and always cat the answer file afterwards.
- StatefulSet Pods on a lost node are not replaced automatically; force deletion (or the out-of-service taint) is the fix, but only after confirming the node is really down.
Key terms
- NotReady
- Node status when the Ready condition is False or Unknown.
- journalctl -u kubelet
- Shows the kubelet service's logs, the primary source for node-level errors.
- Node conditions
- Status flags such as Ready, MemoryPressure, DiskPressure and PIDPressure reported by the kubelet.
- KubeletConfiguration
- The kubelet's config file, typically /var/lib/kubelet/config.yaml.
- crictl ps -a
- Lists all containers on a node from the runtime, including exited ones.
- crictl logs
- Reads a container's logs directly from the runtime, useful when the API server is down.
- etcdctl endpoint health
- Checks whether an etcd member is responding.
- /var/log/pods
- On-disk directory where the kubelet stores container log files per Pod.
- FailedScheduling
- Event reason recorded when the scheduler cannot find a suitable node.
- Insufficient cpu/memory
- Scheduler message meaning the Pod's requests exceed every node's free allocatable capacity.
- Untolerated taint
- Scheduler message meaning a node's taint has no matching toleration on the Pod.
- Unbound immediate PersistentVolumeClaims
- Scheduler message meaning a PVC the Pod needs is not bound.
- kubectl top
- Shows current CPU and memory usage of nodes or Pods using metrics-server.
- Allocatable
- Node resources available for Pods after system reservations, used by the scheduler.
- Allocated resources
- The describe node summary of total requests and limits of Pods on the node.
- Overcommitment
- When the sum of limits on a node exceeds its allocatable capacity.
- kubectl logs --previous
- Shows logs from the last terminated instance of a container.
- /var/log/containers
- Node directory of symlinks to container log files, commonly tailed by log agents.
- Streaming sidecar
- A helper container that reads an application's log file from a shared volume and writes it to stdout.
- Event
- A namespaced record of something that happened to an object, with type, reason and message.
- involvedObject
- The object an event refers to; a common field-selector target.
- --field-selector
- Server-side filtering on supported object fields such as type or reason.
- --sort-by
- Sorts kubectl output by a JSONPath field, such as .metadata.creationTimestamp.
- Empty EndpointSlice
- A Service with no backends, usually from a selector mismatch or unready Pods.
- Readiness probe
- A check that decides whether a Pod receives Service traffic.
- Pod sandbox
- The Pod's network namespace and pause container, set up via the CNI before containers start.
- Cross-node traffic
- Pod-to-Pod traffic between nodes, carried by the CNI's overlay or routing.
- loop plugin
- CoreDNS plugin that detects forwarding loops and stops CoreDNS if one is found.
- systemd-resolved stub
- A local resolver at 127.0.0.53 that causes loops if CoreDNS forwards to it.
- resolvConf
- Kubelet setting naming the resolv.conf file passed to Pods using the Default policy and to CoreDNS.
- k8s-app=kube-dns
- The label selecting CoreDNS Pods and the kube-dns Service's backends.
- Context
- A kubeconfig entry combining a cluster, a user and an optional namespace.
- KUBECONFIG
- Environment variable listing kubeconfig files for kubectl to merge.
- Unauthorized vs Forbidden
- 401 means authentication failed; 403 means authenticated but not permitted by RBAC.
- kubeadm certs renew
- Command that renews kubeadm-managed certificates, including those embedded in kubeconfigs.
- -o jsonpath
- Output mode that prints values selected by a JSONPath template.
- range ... end
- JSONPath construct for iterating over a list, commonly used to print one item per line.
- -o custom-columns
- Output mode that prints a table with user-defined column names and JSONPath values.
- Terminating
- Pod state shown when a deletion timestamp is set but deletion has not been confirmed.
- Force deletion
- Removing a Pod object immediately with --grace-period=0 --force, without kubelet confirmation.
- out-of-service taint
- A node taint marking a node as shut down so its Pods and volume attachments are cleaned up.
- Grace period
- Time allowed between SIGTERM and SIGKILL for a container to shut down, 30 seconds by default.
Study CKA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CKA study planLessons, quizzes, exam simulations and hands-on labs.