StudyToCert

All certifications / CKA / Cheat sheet

CKA CKA (Kubernetes v1.35 curriculum) cheat sheet

Every exam tip and key term from the free CKA lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Cluster Architecture, Installation and Configuration (25%)

Exam tips

Key terms

kube-apiserver
The central REST API for the cluster; the only component that reads and writes etcd, and the one every other component talks to.
etcd
A consistent, distributed key-value store holding all cluster state.
kube-scheduler
Assigns unscheduled Pods to nodes by filtering and scoring candidate nodes.
kube-controller-manager
A single binary running many reconciliation loops such as the ReplicaSet, Node and Job controllers.
kubelet
The node agent, run by systemd, that starts Pods via the container runtime and reports status.
kube-proxy
The per-node component that programs Service virtual IP forwarding rules.
cgroup driver
How the kubelet and runtime create control groups; both must use the same one, normally systemd.
br_netfilter
A kernel module that lets iptables see traffic crossing a Linux bridge.
net.ipv4.ip_forward
The sysctl that allows the kernel to route packets between interfaces, required for Pod traffic.
Preflight checks
Tests kubeadm runs before init or join to catch host misconfiguration.
--pod-network-cidr
The IP range reserved for Pod addresses, which the CNI plugin allocates from.
--control-plane-endpoint
A shared, stable address for the API server, required for later HA expansion.
Bootstrap token
A short-lived token that lets a joining node authenticate to request its kubelet certificate.
discovery-token-ca-cert-hash
A hash of the cluster CA public key that the joining node uses to verify the control plane.
Static Pod
A Pod managed directly by a kubelet from a file in its staticPodPath, not by the API server.
Mirror Pod
The read-only API object the kubelet creates so a static Pod is visible to kubectl.
kubeadm certs check-expiration
Lists each kubeadm-managed certificate and when it expires.
Kubeconfig context
A named combination of a cluster, a user and a default namespace.
kubeadm upgrade plan
Checks upgradeability and lists target versions without changing anything.
kubeadm upgrade apply
Upgrades the first control plane node's components to a given version.
kubeadm upgrade node
Upgrades additional control plane nodes or updates a worker's kubelet config.
Version skew policy
Rules on how far component versions may differ; kubelets may never be newer than the API server.
etcdctl
The network client for a running etcd; used for snapshot save, member list and endpoint health.
etcdutl
The offline etcd utility for working with data files, including snapshot restore and status.
Data directory
The on-disk location of the etcd database, set by --data-dir and mounted via a hostPath volume.
etcd PKI
The separate CA and certificates under /etc/kubernetes/pki/etcd used for etcd mutual TLS.
Stacked etcd
Topology where each control plane node also runs an etcd member.
External etcd
Topology where etcd runs on separate hosts from the control plane.
Quorum
A majority of etcd members, floor(n/2)+1, needed to commit writes.
--certificate-key
The key used to decrypt control plane certificates uploaded by --upload-certs when joining as a control plane node.
Leader election
Mechanism that keeps only one scheduler and one controller-manager active across control plane nodes.
Role / ClusterRole
Sets of permission rules, namespaced or cluster-wide respectively.
RoleBinding / ClusterRoleBinding
Objects that grant a role to users, groups or ServiceAccounts, in one namespace or cluster-wide.
Aggregated ClusterRole
A ClusterRole whose rules are automatically assembled from other ClusterRoles matching a label selector.
CertificateSigningRequest
An API object that asks a signer, such as the kube-apiserver-client signer, to issue a certificate.
Cordon
Marks a node unschedulable without touching running Pods.
Drain
Cordons a node and evicts its Pods so they are rescheduled elsewhere.
PodDisruptionBudget
A policy limiting how many selected Pods can be down at once due to voluntary disruptions.
Eviction API
The API drain uses to remove Pods, which honours PodDisruptionBudgets.
Chart
A Helm package of templated Kubernetes manifests with default values.
Release
A named, installed instance of a chart in a namespace, with its own revision history.
helm upgrade --install
Installs a release if absent or upgrades it if present.
kustomization.yaml
The Kustomize file listing resources and transformations; applied with kubectl apply -k.
CRI
The gRPC interface the kubelet uses to control container runtimes such as containerd and CRI-O.
crictl
A command-line client for CRI runtimes, used for node-level debugging.
CNI
The specification and plugins that configure Pod network interfaces and IP addresses.
CSI
The standard interface for out-of-tree storage drivers that provision, attach and mount volumes.
CustomResourceDefinition
An object that registers a new resource type with the API server.
Custom resource
An instance of a type defined by a CRD, stored in etcd like any object.
Operator
A controller plus CRDs that automates running a specific application.
Finalizer
A key on an object that blocks its deletion until a controller performs cleanup and removes it.

Domain 2: Workloads and Scheduling (15%)

Exam tips

Key terms

ReplicaSet
A controller that keeps a specified number of identical Pods running.
Deployment
A controller that manages ReplicaSets to provide declarative rolling updates and rollbacks.
maxSurge / maxUnavailable
RollingUpdate settings for extra Pods allowed and Pods allowed to be missing during an update.
kubectl rollout restart
Triggers a rolling replacement of all Pods by changing an annotation on the Pod template.
DaemonSet
A controller that runs one copy of a Pod on each eligible node.
StatefulSet
A controller giving Pods stable ordinal names, stable DNS and per-Pod persistent storage.
Headless Service
A Service with clusterIP None that publishes individual Pod DNS records, required by StatefulSets.
Control plane taint
node-role.kubernetes.io/control-plane:NoSchedule, which keeps ordinary Pods off control plane nodes.
ConfigMap
An object holding non-confidential configuration as key-value pairs.
Secret
An object for sensitive data; values are base64-encoded, not encrypted, by default.
envFrom
Imports every key of a ConfigMap or Secret as environment variables.
Immutable ConfigMap/Secret
An object with immutable: true whose data cannot be changed after creation.
Request
The amount of CPU or memory reserved for a container and used for scheduling decisions.
Limit
The maximum CPU (throttled) or memory (OOM-killed) a container may use.
LimitRange
A namespaced admission policy for per-container or per-Pod defaults, minimums and maximums.
ResourceQuota
A namespaced cap on aggregate resource usage and object counts.
QoS class
Guaranteed, Burstable or BestEffort, derived from requests and limits and used for eviction order.
nodeName
A Pod field that pins the Pod to a node directly, bypassing the scheduler.
nodeSelector
A simple label map a node must fully match for the Pod to be scheduled there.
Required node affinity
A hard scheduling rule; the Pod stays Pending if no node satisfies it.
Preferred node affinity
A weighted soft rule that influences scoring but does not block scheduling.
Taint
A key, value and effect on a node that repels Pods lacking a matching toleration.
Toleration
A Pod setting that allows, but does not force, scheduling on nodes with matching taints.
NoExecute
A taint effect that evicts running non-tolerating Pods as well as blocking new ones.
tolerationSeconds
How long a Pod tolerating a NoExecute taint may stay before eviction.
topologyKey
A node label whose value defines a topology domain such as a node or zone.
Pod anti-affinity
A rule keeping a Pod away from domains that already run Pods matching a selector.
topologySpreadConstraints
Rules limiting how unevenly matching Pods are distributed across domains.
maxSkew
The maximum allowed difference in matching Pod counts between any two domains.
PriorityClass
A cluster-scoped object assigning an integer priority to Pods that reference it.
Preemption
The scheduler evicting lower-priority Pods to make room for a higher-priority Pending Pod.
globalDefault
A PriorityClass flag making it the default for Pods that name no class.
preemptionPolicy: Never
Gives a class queue priority without allowing it to evict other Pods.
HorizontalPodAutoscaler
A controller that adjusts a workload's replica count to meet a metric target.
metrics-server
An add-on that collects CPU and memory usage from kubelets and serves the Resource Metrics API.
averageUtilization
A target expressed as a percentage of the Pods' resource requests.
Vertical Pod Autoscaler
An add-on that recommends or sets container requests based on observed usage.
Cluster Autoscaler
An add-on that adds or removes nodes based on Pending Pods and node utilization.
Binding
The act of assigning a Pod to a node, recorded by setting spec.nodeName.
Mirror Pod
The API representation of a static Pod, owned by the Node and not editable.
schedulerName
A Pod field naming which scheduler should place it, default-scheduler by default.

Domain 3: Services and Networking (20%)

Exam tips

Key terms

Pod CIDR
The address range from which Pod IPs are allocated, set at cluster creation.
Service CIDR
The address range for Service ClusterIPs, set by --service-cluster-ip-range.
Pause container
The sandbox container that holds a Pod's shared network namespace.
Overlay network
An encapsulation (such as VXLAN) that carries Pod traffic between nodes over the node network.
ClusterIP
A virtual IP for a Service, implemented as forwarding rules rather than a real interface.
iptables mode
kube-proxy mode that uses NAT chains (KUBE-SERVICES, KUBE-SVC, KUBE-SEP) to forward Service traffic.
IPVS mode
kube-proxy mode using the kernel's IP Virtual Server hash-based load balancer.
nftables mode
kube-proxy mode that programs rules with the nftables framework.
NodePort
A Service type that also opens a port in the 30000–32767 range on every node.
LoadBalancer
A Service type that requests an external load balancer from a cloud controller or MetalLB.
Headless Service
A Service with clusterIP None whose DNS name resolves to Pod IPs directly.
ExternalName
A Service that returns a DNS CNAME to an external hostname, with no proxying.
EndpointSlice
An object listing a subset of a Service's backend addresses, ports and readiness conditions.
Selectorless Service
A Service without a selector whose EndpointSlices you manage manually.
externalTrafficPolicy: Local
Only node-local Pods receive external traffic, preserving the client source IP.
sessionAffinity: ClientIP
Routes a given client IP consistently to the same backend Pod.
NetworkPolicy
A namespaced object that allow-lists ingress and egress traffic for selected Pods.
Default deny
A policy selecting all Pods with no allow rules, blocking all traffic in the listed directions.
namespaceSelector
A peer selector matching all Pods in namespaces whose labels match.
ipBlock
A peer defined by a CIDR range, with optional exceptions.
GatewayClass
A cluster-scoped resource naming the controller that implements Gateways of that class.
Gateway
A request for a traffic entry point with one or more listeners.
HTTPRoute
Routing rules that attach to Gateway listeners via parentRefs and forward to backendRefs.
allowedRoutes
Listener setting controlling which namespaces and route kinds may attach.
ReferenceGrant
An object permitting cross-namespace references, such as a route to another namespace's Service.
Ingress controller
A proxy running in the cluster that implements Ingress objects.
IngressClass
A cluster-scoped object linking an Ingress to a specific controller.
Default IngressClass
The class annotated is-default-class true, used when an Ingress sets no ingressClassName.
pathType
Exact, Prefix (element-wise) or ImplementationSpecific path matching.
Corefile
CoreDNS's configuration, held in the coredns ConfigMap, made of server blocks and plugins.
forward plugin
Sends queries CoreDNS is not authoritative for to upstream resolvers.
Stub zone
A server block that forwards a specific domain to designated DNS servers.
dnsPolicy
Pod setting choosing ClusterFirst, Default, ClusterFirstWithHostNet or None DNS behaviour.
kubectl run --rm -it
Creates an interactive temporary Pod that is deleted when the session ends.
busybox
A minimal image with basic tools such as nslookup, wget and nc, but no curl.
nicolaka/netshoot
A troubleshooting image containing many networking tools including curl, dig and tcpdump.
Connection refused vs timeout
Refused means nothing listens on the port; timeout usually means traffic is dropped or unroutable.

Domain 4: Storage (10%)

Exam tips

Key terms

PersistentVolume
A cluster-scoped object representing a piece of storage and its properties.
PersistentVolumeClaim
A namespaced request for storage that binds to a matching PV.
Released
PV phase after its claim is deleted, before the storage is reclaimed or manually freed.
emptyDir
A Pod-scoped scratch volume removed when the Pod leaves the node.
ReadWriteOnce (RWO)
Read-write by a single node; multiple Pods on that node may share it.
ReadOnlyMany (ROX)
Read-only by many nodes.
ReadWriteMany (RWX)
Read-write by many nodes, requiring shared file storage.
ReadWriteOncePod (RWOP)
Read-write by exactly one Pod cluster-wide, supported for CSI volumes.
persistentVolumeReclaimPolicy
The PV field deciding what happens to the volume after its claim is deleted.
Retain
Keeps the PV and data after the claim is deleted; the PV becomes Released.
Delete
Removes the PV and its backing storage when the claim is deleted.
Recycle
A deprecated policy that scrubbed the volume and made it Available again.
StorageClass
A cluster-scoped description of a type of storage and how to provision it.
Provisioner
The component, usually a CSI driver, that creates volumes for a StorageClass.
Dynamic provisioning
Automatic creation of a PV when a PVC requests a StorageClass.
Default StorageClass
The class annotated is-default-class true, applied to PVCs without storageClassName.
volumeBindingMode
StorageClass field controlling when PVCs bind: Immediate or WaitForFirstConsumer.
Immediate
Binds or provisions as soon as the PVC is created, regardless of Pod placement.
WaitForFirstConsumer
Delays binding until a Pod using the claim is scheduled, respecting topology.
Volume node affinity conflict
A scheduling failure where the Pod cannot run on any node the bound volume can reach.
allowVolumeExpansion
StorageClass flag permitting PVCs of that class to be enlarged.
Online expansion
Growing a volume's filesystem while the Pod using it keeps running.
FileSystemResizePending
A PVC condition indicating the filesystem will be resized when a Pod next mounts it.
Static provisioning
Creating PV objects manually for existing storage.
hostPath
A volume type mounting a directory from the node's filesystem; suitable for labs only.
local volume
A PV for node-attached storage that requires nodeAffinity to pin Pods to that node.
NFS volume
Network file storage identified by server and path, usable read-write from many nodes.
CSI driver
A vendor storage plugin, split into controller and per-node components, that implements CSI.
volumeClaimTemplates
StatefulSet field that creates one PVC per Pod ordinal.
persistentVolumeClaimRetentionPolicy
StatefulSet setting controlling whether PVCs are deleted when the set is deleted or scaled down.
VolumeAttachment
An object recording that a CSI volume is attached to a particular node.

Domain 5: Troubleshooting (30%)

Exam tips

Key terms

NotReady
Node status when the Ready condition is False or Unknown.
journalctl -u kubelet
Shows the kubelet service's logs, the primary source for node-level errors.
Node conditions
Status flags such as Ready, MemoryPressure, DiskPressure and PIDPressure reported by the kubelet.
KubeletConfiguration
The kubelet's config file, typically /var/lib/kubelet/config.yaml.
crictl ps -a
Lists all containers on a node from the runtime, including exited ones.
crictl logs
Reads a container's logs directly from the runtime, useful when the API server is down.
etcdctl endpoint health
Checks whether an etcd member is responding.
/var/log/pods
On-disk directory where the kubelet stores container log files per Pod.
FailedScheduling
Event reason recorded when the scheduler cannot find a suitable node.
Insufficient cpu/memory
Scheduler message meaning the Pod's requests exceed every node's free allocatable capacity.
Untolerated taint
Scheduler message meaning a node's taint has no matching toleration on the Pod.
Unbound immediate PersistentVolumeClaims
Scheduler message meaning a PVC the Pod needs is not bound.
kubectl top
Shows current CPU and memory usage of nodes or Pods using metrics-server.
Allocatable
Node resources available for Pods after system reservations, used by the scheduler.
Allocated resources
The describe node summary of total requests and limits of Pods on the node.
Overcommitment
When the sum of limits on a node exceeds its allocatable capacity.
kubectl logs --previous
Shows logs from the last terminated instance of a container.
/var/log/containers
Node directory of symlinks to container log files, commonly tailed by log agents.
Streaming sidecar
A helper container that reads an application's log file from a shared volume and writes it to stdout.
Event
A namespaced record of something that happened to an object, with type, reason and message.
involvedObject
The object an event refers to; a common field-selector target.
--field-selector
Server-side filtering on supported object fields such as type or reason.
--sort-by
Sorts kubectl output by a JSONPath field, such as .metadata.creationTimestamp.
Empty EndpointSlice
A Service with no backends, usually from a selector mismatch or unready Pods.
Readiness probe
A check that decides whether a Pod receives Service traffic.
Pod sandbox
The Pod's network namespace and pause container, set up via the CNI before containers start.
Cross-node traffic
Pod-to-Pod traffic between nodes, carried by the CNI's overlay or routing.
loop plugin
CoreDNS plugin that detects forwarding loops and stops CoreDNS if one is found.
systemd-resolved stub
A local resolver at 127.0.0.53 that causes loops if CoreDNS forwards to it.
resolvConf
Kubelet setting naming the resolv.conf file passed to Pods using the Default policy and to CoreDNS.
k8s-app=kube-dns
The label selecting CoreDNS Pods and the kube-dns Service's backends.
Context
A kubeconfig entry combining a cluster, a user and an optional namespace.
KUBECONFIG
Environment variable listing kubeconfig files for kubectl to merge.
Unauthorized vs Forbidden
401 means authentication failed; 403 means authenticated but not permitted by RBAC.
kubeadm certs renew
Command that renews kubeadm-managed certificates, including those embedded in kubeconfigs.
-o jsonpath
Output mode that prints values selected by a JSONPath template.
range ... end
JSONPath construct for iterating over a list, commonly used to print one item per line.
-o custom-columns
Output mode that prints a table with user-defined column names and JSONPath values.
Terminating
Pod state shown when a deletion timestamp is set but deletion has not been confirmed.
Force deletion
Removing a Pod object immediately with --grace-period=0 --force, without kubelet confirmation.
out-of-service taint
A node taint marking a node as shut down so its Pods and volume attachments are cleaned up.
Grace period
Time allowed between SIGTERM and SIGKILL for a container to shut down, 30 seconds by default.
Study CKA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CKA study plan