StudyToCert

All certifications / CKAD / Cheat sheet

CKAD CKAD (Kubernetes v1.35 curriculum) cheat sheet

Every exam tip and key term from the free CKAD lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Application Design and Build (20%)

Exam tips

Key terms

Base image
The image named in FROM that supplies the starting filesystem and runtime for your build.
Layer
A cached, read-only filesystem change produced by an instruction such as RUN or COPY.
Multi-stage build
A Dockerfile with several FROM stages where only selected artifacts are copied into the final image.
ENTRYPOINT
The fixed executable the container runs at start.
CMD
Default arguments (or a default command if there is no ENTRYPOINT) that are replaced by arguments given at run time.
Build context
The directory sent to the builder whose files COPY and ADD can reach.
Tag
A human-readable, movable label such as 1.0 that points to an image.
Digest
The immutable sha256 content hash that uniquely identifies an image.
docker save / load
Commands that export images with all layers and metadata to a tar archive and import them again.
command
Container field that replaces the image ENTRYPOINT.
args
Container field that replaces the image CMD.
$(VAR) expansion
Kubernetes substitution of container environment variables inside command and args, done without a shell.
Deployment
Controller for stateless, interchangeable replicas with rolling updates and rollback.
StatefulSet
Controller giving each replica a stable name, ordered start-up and its own persistent storage.
DaemonSet
Controller that runs one Pod per eligible node.
Job / CronJob
Controllers for run-to-completion work, once or on a schedule.
completions
Number of successful Pod runs required for the Job to finish (default 1).
parallelism
Maximum number of the Job's Pods running at once (default 1).
backoffLimit
Number of retries before the Job is marked Failed (default 6).
activeDeadlineSeconds
Maximum run time for the whole Job, after which its Pods are stopped and it fails.
schedule
Five-field cron expression: minute, hour, day of month, month, day of week.
concurrencyPolicy
Allow, Forbid or Replace: what to do if a run is due while the previous one is still active.
History limits
successfulJobsHistoryLimit and failedJobsHistoryLimit, the number of finished Jobs kept.
jobTemplate
The Job specification that the CronJob stamps out for each run.
Init container
A container that runs to completion, in order, before the app containers start.
Sidecar
A helper container that runs alongside the main container for the Pod's lifetime.
Native sidecar
An init container with restartPolicy: Always, started before and stopped after the main containers.
Adapter
A helper that converts the main container's output to a standard format.
Ambassador
A helper that proxies the app's connections to external services via localhost.
emptyDir
A Pod-lifetime scratch volume, empty at start and shared by the Pod's containers.
medium: Memory
Makes an emptyDir a RAM-backed tmpfs that counts toward memory usage.
Projected volume
A volume that combines configMap, secret, downwardAPI and serviceAccountToken sources in one directory.
Ephemeral volume
Storage whose lifetime is tied to the Pod and is deleted with it.
PersistentVolume (PV)
A cluster-scoped object representing a piece of real storage.
PersistentVolumeClaim (PVC)
A namespaced request for storage that binds to a matching PV.
StorageClass
A named type of storage with a provisioner used for dynamic provisioning.
Access mode
RWO, ROX, RWX or RWOP: how many nodes or Pods may mount the volume and whether they can write.
Reclaim policy
Delete or Retain: what happens to a PV's storage after its claim is released.
volumeMounts
Per-container list linking a Pod volume to a path inside that container.
mountPath
The absolute path in the container where the volume appears, hiding anything already there.
subPath
Mounts a single file or subdirectory of a volume instead of its whole root.
readOnly
Mount option that blocks writes from that container to the volume.

Domain 2: Application Deployment (20%)

Exam tips

Key terms

ReplicaSet
Controller that keeps a set number of identical Pods running; normally managed by a Deployment.
Pod template
The Pod metadata and spec inside a controller from which every replica is created.
Label selector
A query on labels, such as matchLabels app: web, that decides which Pods an object manages or targets.
pod-template-hash
Label added by the Deployment to tell Pods of different ReplicaSets apart.
RollingUpdate
Default Deployment strategy that replaces Pods gradually while the app keeps serving.
maxSurge
How many Pods above the desired count may exist during an update (default 25%).
maxUnavailable
How many Pods below the desired count may be unavailable during an update (default 25%).
minReadySeconds
How long a new Pod must stay ready before it counts as available.
Recreate
Strategy that terminates all old Pods before creating new ones, causing brief downtime.
Revision
A numbered version of a Deployment's Pod template kept for rollback.
rollout undo
Returns the Deployment to the previous or a chosen revision by reapplying its template.
rollout pause / resume
Temporarily stops and restarts rollouts so several changes can be applied as one.
change-cause
The kubernetes.io/change-cause annotation shown in rollout history.
Blue/green deployment
Running old and new versions in full side by side and switching all traffic at once.
Service selector
Label query that decides which Pods receive a Service's traffic.
Cut-over
The moment traffic moves from the old version to the new one.
Canary release
Sending a small share of traffic to a new version to test it with real users.
Track label
A label such as track: canary used to tell the two Deployments' Pods apart without affecting the Service.
Replica weighting
Using the ratio of Pod counts to approximate a traffic split behind one Service.
Chart
A Helm package of templated Kubernetes manifests plus default values.
Repository
A server hosting an index of charts, added locally with helm repo add.
Release
A named, installed instance of a chart in a namespace, with revision history.
helm rollback
Returns a release to an earlier revision, recorded as a new revision.
values.yaml
The chart's default configuration file read by its templates.
--set
Command-line override of individual values using dotted keys.
-f / --values
Supplies a YAML file of value overrides; can be repeated.
helm template
Renders chart manifests locally without installing anything.
kustomization.yaml
The file that lists resources and the transformations Kustomize applies to them.
namePrefix
Text added to the start of every resource name, with references updated.
labels / commonLabels
Fields that add labels to all resources; commonLabels also changes selectors and is deprecated.
patches
Partial changes (strategic merge or JSON 6902) applied to selected resources.
configMapGenerator
Creates ConfigMaps from literals, files or env files, with a content hash in the name.
Base
A kustomization directory holding shared manifests that overlays build upon.
Overlay
A kustomization that references a base and adds environment-specific changes.
kubectl apply -k
Builds the kustomization in a directory and applies the result to the cluster.
kubectl kustomize
Builds a kustomization and prints the resulting YAML without applying it.

Domain 3: Application Observability and Maintenance (15%)

Exam tips

Key terms

apiVersion
The API group and version of an object, such as apps/v1; core objects use just v1.
Deprecation
An API version is marked for future removal; it still works but produces warnings.
kubectl api-resources
Lists resource types with short names, API version, namespaced flag and kind.
kubectl explain
Shows documentation and field structure for a resource type and version.
networking.k8s.io/v1
Stable API group/version for Ingress and NetworkPolicy.
pathType
Required Ingress path field in v1: Prefix, Exact or ImplementationSpecific.
autoscaling/v2
Stable HPA version with a metrics list supporting resource, pods, object and external metrics.
batch/v1
Stable group/version for Job and CronJob.
Liveness probe
Checks whether a container should be restarted.
Readiness probe
Checks whether a container should receive Service traffic.
Startup probe
Checks whether a slow container has started, holding off the other probes until it has.
failureThreshold
Consecutive failures needed before the probe is considered failed (default 3).
Probe handler
The check method: httpGet, tcpSocket, exec or grpc.
Restart
The liveness/startup failure action: the kubelet kills the container and starts it again in the same Pod.
Not ready
The readiness failure state: the Pod stays running but is removed from Service endpoints.
Ready condition
Pod status condition shown in the READY column that decides whether the Pod receives Service traffic.
kubectl describe
Detailed view of one object including related status and recent events.
Event
A short-lived record of something that happened to an object, such as a scheduling failure or image pull.
metrics-server
Cluster add-on that collects CPU and memory usage from kubelets for kubectl top and the HPA.
kubectl top
Shows current CPU and memory usage of nodes or Pods from the Metrics API.
-c
Selects which container's logs to show in a multi-container Pod.
--previous
Shows logs from the last terminated instance of the container.
-f
Follows the log stream as new lines are written.
-l
Selects Pods by label to show logs from several Pods at once.
Pending
Pod accepted but containers not running yet, often unscheduled or still creating.
ImagePullBackOff
The image cannot be pulled and Kubernetes is backing off between retries.
CrashLoopBackOff
The container keeps exiting after start and is restarted with increasing delays.
OOMKilled
The container was killed for exceeding its memory limit, usually with exit code 137.
Exit code 128+n
A process killed by signal n, such as 137 for SIGKILL or 143 for SIGTERM.
kubectl exec
Runs a command, or an interactive shell with -it, inside a running container.
Ephemeral container
A temporary debugging container added to a running Pod by kubectl debug.
kubectl debug --copy-to
Creates a modified copy of a Pod for troubleshooting.
kubectl port-forward
Tunnels a local port to a port on a Pod through the API server.
-o wide
Adds extra columns such as Pod IP, node and images.
-o yaml
Prints the complete object, including status and defaults.
jsonpath
Output template that extracts specific fields from the object tree.
--sort-by
Orders list output by a field given as a JSONPath expression.
custom-columns
Output format that builds a table from named field paths.

Domain 4: Application Environment, Configuration and Security (25%)

Exam tips

Key terms

CustomResourceDefinition (CRD)
An object that registers a new resource type with the Kubernetes API.
Custom resource
An object of a type defined by a CRD, managed with kubectl like built-in objects.
Controller
A program that watches objects and acts to make actual state match their spec.
Operator
A controller plus CRDs that automate running a specific application.
Authentication
Establishing who is making the request; failure returns 401.
Authorization
Deciding whether the identity may perform the verb on the resource; failure returns 403.
Mutating admission
Admission step that can modify an object before it is stored.
Validating admission
Admission step that accepts or rejects an object without changing it.
Role
Namespaced set of allowed verbs on resources.
ClusterRole
Non-namespaced set of permissions, usable cluster-wide or bound per namespace.
RoleBinding
Grants a Role or ClusterRole to subjects within one namespace.
ClusterRoleBinding
Grants a ClusterRole to subjects across the whole cluster.
kubectl auth can-i --as
Checks whether a user or ServiceAccount may perform an action, using impersonation.
Request
Resources reserved for a container and used by the scheduler for placement.
Limit
Maximum resources a container may use; CPU is throttled and memory overuse is killed.
Millicore (m)
One thousandth of a CPU core; 500m is half a core.
Mi / Gi
Binary memory units based on powers of 1024.
QoS class
Guaranteed, Burstable or BestEffort, derived from requests and limits and used for eviction order.
ResourceQuota
Namespace-wide cap on total resource usage and object counts.
LimitRange
Namespace policy that sets default and minimum/maximum resources per container, Pod or PVC.
defaultRequest / default
LimitRange fields giving the request and the limit applied when a container omits them.
count/<resource>
Quota key that limits how many objects of a type may exist in the namespace.
ConfigMap
An object holding non-secret configuration as key-value pairs.
--from-env-file
Creates one ConfigMap key per KEY=value line in a file.
configMapKeyRef
Sets one environment variable from one ConfigMap key.
envFrom
Imports all keys of a ConfigMap or Secret as environment variables.
Opaque
Default Secret type for arbitrary user data, created with kubectl create secret generic.
kubernetes.io/dockerconfigjson
Secret type holding registry credentials, used via imagePullSecrets.
kubernetes.io/tls
Secret type holding tls.crt and tls.key for certificates.
Base64
Reversible text encoding used for Secret data; it provides no confidentiality.
secretKeyRef
Sets one environment variable from one key of a Secret.
ServiceAccount
A namespaced identity for processes running in Pods.
serviceAccountName
Pod spec field choosing which ServiceAccount the Pod runs as.
Bound (projected) token
A short-lived, audience-scoped token tied to a Pod and refreshed by the kubelet.
automountServiceAccountToken
Setting on a ServiceAccount or Pod that controls whether the token is mounted.
kubectl create token
Command that issues a short-lived token for a ServiceAccount.
runAsUser
Numeric UID the container processes run as.
runAsNonRoot
Makes the kubelet refuse to start a container that would run as UID 0.
fsGroup
Pod-level supplementary group applied to containers and to ownership of supported volumes.
readOnlyRootFilesystem
Container-level setting that makes the container's root filesystem read-only.
allowPrivilegeEscalation
Container-level setting that, when false, stops processes gaining more privileges than their parent.
Capability
A named slice of root privilege, such as NET_BIND_SERVICE, that can be added to or dropped from a container.
Pod Security Admission
Built-in admission controller enforcing Pod Security Standards through namespace labels.
Baseline
Pod Security level that blocks known privilege escalations such as privileged containers and host namespaces.
Restricted
Strictest Pod Security level requiring non-root, no privilege escalation, dropped capabilities and a seccomp profile.
enforce / audit / warn
PSA modes that reject, log or warn about violating Pods.

Domain 5: Services and Networking (20%)

Exam tips

Key terms

ClusterIP
Default Service type with an internal virtual IP reachable only inside the cluster.
NodePort
Service type that also opens a port (default range 30000-32767) on every node.
LoadBalancer
Service type that provisions an external load balancer through the cloud provider or an add-on.
ExternalName
Service type that returns a DNS CNAME to an external host, without proxying.
Headless Service
Service with clusterIP: None whose DNS returns individual Pod IPs.
port
The port the Service listens on at its ClusterIP and DNS name.
targetPort
The Pod port traffic is forwarded to; defaults to port, may be a named port.
Named port
A containerPort with a name that a Service can reference as its targetPort.
EndpointSlice
An object listing the addresses, ports and readiness of Pods backing a Service.
kubernetes.io/service-name
Label linking an EndpointSlice to its Service.
Ready condition
Endpoint flag showing whether a backend Pod should receive traffic.
CoreDNS
The DNS server that normally provides cluster DNS for Services and Pods.
Service FQDN
The fully qualified Service name <service>.<namespace>.svc.cluster.local.
Search domains
Suffixes in a Pod's resolv.conf that let short names like web resolve within its namespace.
ndots
Resolver option setting how many dots a name needs before it is tried as absolute first.
kubectl expose
Creates a Service for an existing resource, copying its selector.
kubectl create service
Creates a Service of a given type from scratch, with selector app=<name>.
--tcp=port:targetPort
Flag for create service that sets the Service port and target port.
kubectl port-forward
Temporary tunnel from a local port to one Pod; creates no Service.
NetworkPolicy
Namespaced object that restricts traffic to and from selected Pods.
podSelector
Chooses the Pods a policy applies to; {} selects all Pods in the namespace.
policyTypes
Ingress, Egress or both: which directions the policy isolates.
Isolated Pod
A Pod selected by a policy for a direction, which then only allows traffic explicitly permitted.
Default deny
A policy selecting all Pods with no allow rules, blocking all traffic in the listed directions.
namespaceSelector
Peer that matches Pods in namespaces with the given labels.
ipBlock
Peer that matches a CIDR range, with optional except ranges, usually for external traffic.
AND semantics
namespaceSelector and podSelector in the same peer item must both match.
OR semantics
Separate peer items or separate rules each allow traffic independently.
kubernetes.io/metadata.name
Automatic namespace label holding the namespace's name.
CNI (Container Network Interface)
The standard interface Kubernetes uses to have a plugin set up Pod networking.
Network plugin
The CNI implementation that provides Pod networking and, if supported, enforces NetworkPolicy.
Calico / Cilium
Widely used network plugins that enforce NetworkPolicy.
eBPF
Linux kernel technology for running small verified programs, used by some plugins to filter traffic.
Ingress
An object defining host- and path-based HTTP(S) routing rules to Services.
ingressClassName
Field selecting which IngressClass (controller) implements the Ingress.
pathType Prefix
Matches the path and anything below it, element by element.
pathType Exact
Matches only the exact URL path.
defaultBackend
Service that receives requests matching no rule.
Ingress controller
The component that watches Ingress objects and runs the proxy that routes traffic.
IngressClass
Object identifying a controller that Ingresses select with ingressClassName.
Host header
HTTP header naming the requested host, used by Ingress host rules.
curl --resolve
Makes curl connect to a chosen IP for a host name, keeping the correct name for TLS.
Study CKAD for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CKAD study plan