All certifications / CKA / Lessons
CKA CKA (Kubernetes v1.35 curriculum) lessons
Study CKA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CKA study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Cluster Architecture, Installation and Configuration
- Control plane and node components: kube-apiserver, etcd, kube-scheduler, kube-controller-manager, kubelet, kube-proxy, container runtime
- Preparing hosts for kubeadm: containerd, matching systemd cgroup driver, swap, overlay and br_netfilter modules, ip_forward and bridge sysctls, required ports
- Kubeadm init (pod network CIDR, control-plane endpoint), installing a CNI plugin, kubeadm join and bootstrap tokens
- Static Pods and /etc/kubernetes/manifests; kubeadm certificates (check-expiration, renew) and kubeconfig files
- Cluster upgrades with kubeadm: one minor version at a time, upgrade plan/apply/node, drain, kubelet upgrade, uncordon, version skew
- Etcd backup and restore with etcdctl/etcdutl and the etcd PKI; pointing the etcd static Pod at a restored data directory
- Highly available control planes: stacked vs external etcd, quorum, load balancer in front of API servers, --upload-certs and --certificate-key
- RBAC: Roles, ClusterRoles, RoleBindings, ClusterRoleBindings, aggregated and built-in roles, users via CertificateSigningRequests, kubectl auth can-i
- Node maintenance: cordon, drain, uncordon and PodDisruptionBudgets
- Helm (repo add/update, upgrade --install, --version, values) and Kustomize (kubectl apply -k) for installing cluster components
- Extension interfaces: CRI (containerd, CRI-O, crictl), CNI (Calico, Cilium, Flannel), CSI drivers
- CustomResourceDefinitions, custom resources and operators (CRD plus controller)
Domain 2: Workloads and Scheduling
- Deployments and ReplicaSets as self-healing primitives; rolling updates, rollout status, history, undo and restart
- DaemonSets and StatefulSets from an operator's point of view, including tolerations for control plane nodes
- ConfigMaps and Secrets: creation, env and volume consumption, immutable objects, restarting workloads after changes
- Resource requests and limits, LimitRange and ResourceQuota as admission controls
- Scheduling: nodeSelector, nodeName, node affinity (required vs preferred)
- Taints and tolerations: NoSchedule, PreferNoSchedule, NoExecute and tolerationSeconds
- Pod affinity and anti-affinity with topologyKey; topologySpreadConstraints
- PriorityClasses and preemption
- Workload autoscaling: HorizontalPodAutoscaler (kubectl autoscale, autoscaling/v2), metrics-server and CPU requests; awareness of VPA and Cluster Autoscaler
- Static Pods vs scheduler-placed Pods; what happens when the scheduler is down
Domain 3: Services and Networking
- Kubernetes network model: one IP per Pod, NAT-free Pod-to-Pod traffic, the CNI plugin's role, Pod and Service CIDRs
- Kube-proxy modes (iptables, IPVS, nftables) and how Service virtual IPs work
- Service types: ClusterIP, NodePort (30000–32767), LoadBalancer (cloud controller or MetalLB), headless and ExternalName
- EndpointSlices, Services without selectors, externalTrafficPolicy and sessionAffinity
- NetworkPolicies: default deny, ingress and egress rules, podSelector, namespaceSelector (kubernetes.io/metadata.name), ipBlock, ports
- Gateway API: GatewayClass, Gateway listeners and allowedRoutes, HTTPRoute parentRefs, matches and weighted backendRefs; installing the CRDs and a controller
- Ingress controllers, IngressClass and the default class; Ingress rules, path types and TLS
- CoreDNS: the coredns ConfigMap and Corefile, forwarding and stub zones, Service and Pod DNS records, dnsPolicy
- Testing connectivity with temporary Pods (busybox, nicolaka/netshoot), nslookup, curl and nc
Domain 4: Storage
- Volumes vs PersistentVolumes; PV and PVC lifecycle (Available, Bound, Released) and binding rules
- Access modes: ReadWriteOnce, ReadOnlyMany, ReadWriteMany, ReadWriteOncePod
- Reclaim policies: Retain and Delete (Recycle deprecated) and cleaning up Released PVs
- StorageClasses, provisioners and dynamic provisioning; the default StorageClass annotation
- VolumeBindingMode Immediate vs WaitForFirstConsumer
- Volume expansion with allowVolumeExpansion
- Static PVs: hostPath for labs, local volumes with nodeAffinity, NFS
- CSI drivers and StatefulSet volumeClaimTemplates with PVC retention
Domain 5: Troubleshooting
- Node problems: NotReady, kubelet status and journalctl -u kubelet, kubelet config and certificates, container runtime down, node conditions (DiskPressure, MemoryPressure)
- Control plane problems: static Pod manifests, crictl ps/logs when the API server is down, scheduler and controller-manager symptoms, etcd health with etcdctl
- Pending Pods: FailedScheduling messages for resources, taints, affinity and unbound PVCs
- Resource monitoring: metrics-server, kubectl top nodes/pods --sort-by, describe node allocated resources
- Container output streams: kubectl logs options, stdout/stderr vs log files, /var/log/pods and /var/log/containers, sidecar log streaming
- Events: kubectl get events with field selectors and sorting
- Service and networking problems: selectors, readiness and EndpointSlices, kube-proxy, cross-node CNI traffic, sandbox network errors
- DNS problems: CoreDNS Pods and logs, loop detection with systemd-resolved, testing with a temporary Pod
- Cluster access problems: kubeconfig contexts, expired certificates, connection refused on 6443
- Output handling for tasks: -o jsonpath, custom-columns, --sort-by, writing answers to files
- Stuck Terminating Pods on lost nodes and force deletion