All certifications / CKAD / Cheat sheet
CKAD CKAD (Kubernetes v1.35 curriculum) cheat sheet
Domain 1: Application Design and Build (20%)
Exam tips
- Remember the combination rule: ENTRYPOINT plus CMD run together, run-time arguments replace only CMD. Questions often ask what command a container actually runs.
- Tasks that ask for an image archive want
save(image with layers and metadata), notexport(a container's flat filesystem). Also read the exact tag and output path the task asks for. - Setting only
commanddiscards the image CMD rather than appending it. And--commandon kubectl run decides whether the words after--land in command or args. - Look for the clue words: 'one per node' means DaemonSet, 'stable identity or ordered' means StatefulSet, 'runs to completion' means Job, 'on a schedule' means CronJob, and 'scalable stateless app' means Deployment.
- Know the defaults (completions 1, parallelism 1, backoffLimit 6) and that activeDeadlineSeconds wins over backoffLimit. Also remember Never gives new Pods on retry while OnFailure restarts the same Pod.
- The command to trigger a CronJob by hand is
kubectl create job <new-name> --from=cronjob/<cronjob-name>. Also remember that restartPolicy sits in the innermost Pod template. - If a Pod is stuck in
Init:status, the problem is an init container: check it withkubectl logs <pod> -c <init-name>. A native sidecar lives under initContainers but has restartPolicy: Always. - Secret volumes use
secretName, notname, and projected sources usenamefor both. Also remember env vars do not update when a ConfigMap changes, but mounted files (without subPath) do. - Pods reference PVCs, not PVs. For a static PV and PVC to bind, storageClassName, access mode and capacity (PV at least as large as the request) must all be compatible.
- A volume needs both halves: an entry in spec.volumes and a matching volumeMounts entry in each container. subPath mounts do not auto-update from ConfigMaps or Secrets.
Key terms
- Base image
- The image named in FROM that supplies the starting filesystem and runtime for your build.
- Layer
- A cached, read-only filesystem change produced by an instruction such as RUN or COPY.
- Multi-stage build
- A Dockerfile with several FROM stages where only selected artifacts are copied into the final image.
- ENTRYPOINT
- The fixed executable the container runs at start.
- CMD
- Default arguments (or a default command if there is no ENTRYPOINT) that are replaced by arguments given at run time.
- Build context
- The directory sent to the builder whose files COPY and ADD can reach.
- Tag
- A human-readable, movable label such as 1.0 that points to an image.
- Digest
- The immutable sha256 content hash that uniquely identifies an image.
- docker save / load
- Commands that export images with all layers and metadata to a tar archive and import them again.
- command
- Container field that replaces the image ENTRYPOINT.
- args
- Container field that replaces the image CMD.
- $(VAR) expansion
- Kubernetes substitution of container environment variables inside command and args, done without a shell.
- Deployment
- Controller for stateless, interchangeable replicas with rolling updates and rollback.
- StatefulSet
- Controller giving each replica a stable name, ordered start-up and its own persistent storage.
- DaemonSet
- Controller that runs one Pod per eligible node.
- Job / CronJob
- Controllers for run-to-completion work, once or on a schedule.
- completions
- Number of successful Pod runs required for the Job to finish (default 1).
- parallelism
- Maximum number of the Job's Pods running at once (default 1).
- backoffLimit
- Number of retries before the Job is marked Failed (default 6).
- activeDeadlineSeconds
- Maximum run time for the whole Job, after which its Pods are stopped and it fails.
- schedule
- Five-field cron expression: minute, hour, day of month, month, day of week.
- concurrencyPolicy
- Allow, Forbid or Replace: what to do if a run is due while the previous one is still active.
- History limits
- successfulJobsHistoryLimit and failedJobsHistoryLimit, the number of finished Jobs kept.
- jobTemplate
- The Job specification that the CronJob stamps out for each run.
- Init container
- A container that runs to completion, in order, before the app containers start.
- Sidecar
- A helper container that runs alongside the main container for the Pod's lifetime.
- Native sidecar
- An init container with restartPolicy: Always, started before and stopped after the main containers.
- Adapter
- A helper that converts the main container's output to a standard format.
- Ambassador
- A helper that proxies the app's connections to external services via localhost.
- emptyDir
- A Pod-lifetime scratch volume, empty at start and shared by the Pod's containers.
- medium: Memory
- Makes an emptyDir a RAM-backed tmpfs that counts toward memory usage.
- Projected volume
- A volume that combines configMap, secret, downwardAPI and serviceAccountToken sources in one directory.
- Ephemeral volume
- Storage whose lifetime is tied to the Pod and is deleted with it.
- PersistentVolume (PV)
- A cluster-scoped object representing a piece of real storage.
- PersistentVolumeClaim (PVC)
- A namespaced request for storage that binds to a matching PV.
- StorageClass
- A named type of storage with a provisioner used for dynamic provisioning.
- Access mode
- RWO, ROX, RWX or RWOP: how many nodes or Pods may mount the volume and whether they can write.
- Reclaim policy
- Delete or Retain: what happens to a PV's storage after its claim is released.
- volumeMounts
- Per-container list linking a Pod volume to a path inside that container.
- mountPath
- The absolute path in the container where the volume appears, hiding anything already there.
- subPath
- Mounts a single file or subdirectory of a volume instead of its whole root.
- readOnly
- Mount option that blocks writes from that container to the volume.
Domain 2: Application Deployment (20%)
Exam tips
- If
kubectl applyfails with 'selector does not match template labels', make spec.selector.matchLabels a subset of spec.template.metadata.labels. The selector cannot be changed later in apps/v1. - Do the arithmetic: max Pods = replicas + maxSurge, minimum available = replicas - maxUnavailable. Pick Recreate when a task says old and new versions must never run together.
- In
kubectl set image, the left side is the container name. Usekubectl get deploy web -o jsonpath='{.spec.template.spec.containers[*].name}'if you are unsure. - The switch happens in the Service, not the Deployments. Make sure the version label is on the Pod template and that the Service selector includes it.
- Percent to canary is canary replicas divided by total replicas. The Service selector must match a label shared by both Deployments and must not include the track label.
- Always pass the right
-nnamespace to helm list, upgrade, rollback and uninstall, and usehelm list -Awhen you do not know where a release lives. - Find the exact key path with
helm show valuesbefore using --set. A wrong key is silently ignored, so verify withhelm get valuesorhelm template. - The
imagesname matches the image as written in the manifest, not the container name. Generated ConfigMaps have a hash suffix, so look them up withkubectl get cmrather than guessing the name. -ktakes a directory, not a file, andkubectl kustomize(no apply) is the safe preview. Usekubectl diff -kto see exactly what will change.
Key terms
- ReplicaSet
- Controller that keeps a set number of identical Pods running; normally managed by a Deployment.
- Pod template
- The Pod metadata and spec inside a controller from which every replica is created.
- Label selector
- A query on labels, such as matchLabels app: web, that decides which Pods an object manages or targets.
- pod-template-hash
- Label added by the Deployment to tell Pods of different ReplicaSets apart.
- RollingUpdate
- Default Deployment strategy that replaces Pods gradually while the app keeps serving.
- maxSurge
- How many Pods above the desired count may exist during an update (default 25%).
- maxUnavailable
- How many Pods below the desired count may be unavailable during an update (default 25%).
- minReadySeconds
- How long a new Pod must stay ready before it counts as available.
- Recreate
- Strategy that terminates all old Pods before creating new ones, causing brief downtime.
- Revision
- A numbered version of a Deployment's Pod template kept for rollback.
- rollout undo
- Returns the Deployment to the previous or a chosen revision by reapplying its template.
- rollout pause / resume
- Temporarily stops and restarts rollouts so several changes can be applied as one.
- change-cause
- The kubernetes.io/change-cause annotation shown in rollout history.
- Blue/green deployment
- Running old and new versions in full side by side and switching all traffic at once.
- Service selector
- Label query that decides which Pods receive a Service's traffic.
- Cut-over
- The moment traffic moves from the old version to the new one.
- Canary release
- Sending a small share of traffic to a new version to test it with real users.
- Track label
- A label such as track: canary used to tell the two Deployments' Pods apart without affecting the Service.
- Replica weighting
- Using the ratio of Pod counts to approximate a traffic split behind one Service.
- Chart
- A Helm package of templated Kubernetes manifests plus default values.
- Repository
- A server hosting an index of charts, added locally with helm repo add.
- Release
- A named, installed instance of a chart in a namespace, with revision history.
- helm rollback
- Returns a release to an earlier revision, recorded as a new revision.
- values.yaml
- The chart's default configuration file read by its templates.
- --set
- Command-line override of individual values using dotted keys.
- -f / --values
- Supplies a YAML file of value overrides; can be repeated.
- helm template
- Renders chart manifests locally without installing anything.
- kustomization.yaml
- The file that lists resources and the transformations Kustomize applies to them.
- namePrefix
- Text added to the start of every resource name, with references updated.
- labels / commonLabels
- Fields that add labels to all resources; commonLabels also changes selectors and is deprecated.
- patches
- Partial changes (strategic merge or JSON 6902) applied to selected resources.
- configMapGenerator
- Creates ConfigMaps from literals, files or env files, with a content hash in the name.
- Base
- A kustomization directory holding shared manifests that overlays build upon.
- Overlay
- A kustomization that references a base and adds environment-specific changes.
- kubectl apply -k
- Builds the kustomization in a directory and applies the result to the cluster.
- kubectl kustomize
- Builds a kustomization and prints the resulting YAML without applying it.
Domain 3: Application Observability and Maintenance (15%)
Exam tips
- 'no matches for kind X in version Y' almost always means the API version was removed.
kubectl api-resources | grep -i <kind>gives the right one in seconds. - For Ingress, changing only the apiVersion is not enough: fix the backend format and add pathType. For CronJob, the apiVersion change is usually all that is needed.
- Know the defaults: period 10s, timeout 1s, failureThreshold 3, successThreshold 1, initialDelay 0. For slow starters, the preferred answer is a startup probe, not a huge initialDelaySeconds.
- Liveness fails: container restarts. Readiness fails: Pod leaves the Service but keeps running. If a question mentions restarts climbing, think liveness; if it mentions no traffic but no restarts, think readiness.
gettells you what,describeand events tell you why,toptells you how much. Ifkubectl toperrors, metrics-server is missing or not ready yet.- For crashing containers, reach for
--previousfirst. For multi-container Pods,-cis required to get the right container. - Map status to the next command: Pending and ImagePullBackOff lead to
describe, CrashLoopBackOff leads tologs --previous, and OOMKilled leads to the memory limit. - Remember
--rm -it --restart=Neverfor throwaway test Pods, and that port-forward to a Service still reaches only one Pod. - For
kubectl get pods(a list) jsonpath starts at.items, but--sort-bypaths are relative to each item. Always single-quote jsonpath expressions.
Key terms
- apiVersion
- The API group and version of an object, such as apps/v1; core objects use just v1.
- Deprecation
- An API version is marked for future removal; it still works but produces warnings.
- kubectl api-resources
- Lists resource types with short names, API version, namespaced flag and kind.
- kubectl explain
- Shows documentation and field structure for a resource type and version.
- networking.k8s.io/v1
- Stable API group/version for Ingress and NetworkPolicy.
- pathType
- Required Ingress path field in v1: Prefix, Exact or ImplementationSpecific.
- autoscaling/v2
- Stable HPA version with a metrics list supporting resource, pods, object and external metrics.
- batch/v1
- Stable group/version for Job and CronJob.
- Liveness probe
- Checks whether a container should be restarted.
- Readiness probe
- Checks whether a container should receive Service traffic.
- Startup probe
- Checks whether a slow container has started, holding off the other probes until it has.
- failureThreshold
- Consecutive failures needed before the probe is considered failed (default 3).
- Probe handler
- The check method: httpGet, tcpSocket, exec or grpc.
- Restart
- The liveness/startup failure action: the kubelet kills the container and starts it again in the same Pod.
- Not ready
- The readiness failure state: the Pod stays running but is removed from Service endpoints.
- Ready condition
- Pod status condition shown in the READY column that decides whether the Pod receives Service traffic.
- kubectl describe
- Detailed view of one object including related status and recent events.
- Event
- A short-lived record of something that happened to an object, such as a scheduling failure or image pull.
- metrics-server
- Cluster add-on that collects CPU and memory usage from kubelets for kubectl top and the HPA.
- kubectl top
- Shows current CPU and memory usage of nodes or Pods from the Metrics API.
- -c
- Selects which container's logs to show in a multi-container Pod.
- --previous
- Shows logs from the last terminated instance of the container.
- -f
- Follows the log stream as new lines are written.
- -l
- Selects Pods by label to show logs from several Pods at once.
- Pending
- Pod accepted but containers not running yet, often unscheduled or still creating.
- ImagePullBackOff
- The image cannot be pulled and Kubernetes is backing off between retries.
- CrashLoopBackOff
- The container keeps exiting after start and is restarted with increasing delays.
- OOMKilled
- The container was killed for exceeding its memory limit, usually with exit code 137.
- Exit code 128+n
- A process killed by signal n, such as 137 for SIGKILL or 143 for SIGTERM.
- kubectl exec
- Runs a command, or an interactive shell with -it, inside a running container.
- Ephemeral container
- A temporary debugging container added to a running Pod by kubectl debug.
- kubectl debug --copy-to
- Creates a modified copy of a Pod for troubleshooting.
- kubectl port-forward
- Tunnels a local port to a port on a Pod through the API server.
- -o wide
- Adds extra columns such as Pod IP, node and images.
- -o yaml
- Prints the complete object, including status and defaults.
- jsonpath
- Output template that extracts specific fields from the object tree.
- --sort-by
- Orders list output by a field given as a JSONPath expression.
- custom-columns
- Output format that builds a table from named field paths.
Domain 4: Application Environment, Configuration and Security (25%)
Exam tips
- The CRD name is
<plural>.<group>, and custom resources useapiVersion: <group>/<version>.kubectl api-resourcestells you the exact plural and short names to use. - Order: authentication, authorization, mutating admission, validation, validating admission. 401 means identity, 403 with 'cannot' means RBAC, and quota or PodSecurity messages mean admission.
- Core resources use apiGroups [""], and --serviceaccount takes namespace:name. A ClusterRole bound by a RoleBinding only grants access in that binding's namespace.
- Guaranteed needs requests equal to limits for both CPU and memory in every container. CPU over limit means throttling; memory over limit means OOMKilled.
- A compute quota forces every new Pod to declare that resource; a LimitRange default is the usual fix. Quota errors for Deployments show up on the ReplicaSet, not the Deployment.
- --from-file=app.env makes one key holding the whole file; --from-env-file=app.env makes one key per line. And env values do not update until the Pod restarts.
- Base64 is encoding, not encryption. Know the three create types (generic, docker-registry, tls) and that secret volumes use
secretName. - The Pod field is
serviceAccountName(olderserviceAccountis deprecated), the Pod-level automount setting overrides the ServiceAccount's, and you cannot change a running Pod's ServiceAccount. - fsGroup is Pod-level only; readOnlyRootFilesystem, allowPrivilegeEscalation, capabilities and privileged are container-level only. Container values override Pod values.
- Capabilities are container-level only and written without CAP_. PSA errors for Deployments appear on the ReplicaSet, and restricted requires drop ALL, runAsNonRoot, allowPrivilegeEscalation false and a RuntimeDefault or Localhost seccomp profile.
Key terms
- CustomResourceDefinition (CRD)
- An object that registers a new resource type with the Kubernetes API.
- Custom resource
- An object of a type defined by a CRD, managed with kubectl like built-in objects.
- Controller
- A program that watches objects and acts to make actual state match their spec.
- Operator
- A controller plus CRDs that automate running a specific application.
- Authentication
- Establishing who is making the request; failure returns 401.
- Authorization
- Deciding whether the identity may perform the verb on the resource; failure returns 403.
- Mutating admission
- Admission step that can modify an object before it is stored.
- Validating admission
- Admission step that accepts or rejects an object without changing it.
- Role
- Namespaced set of allowed verbs on resources.
- ClusterRole
- Non-namespaced set of permissions, usable cluster-wide or bound per namespace.
- RoleBinding
- Grants a Role or ClusterRole to subjects within one namespace.
- ClusterRoleBinding
- Grants a ClusterRole to subjects across the whole cluster.
- kubectl auth can-i --as
- Checks whether a user or ServiceAccount may perform an action, using impersonation.
- Request
- Resources reserved for a container and used by the scheduler for placement.
- Limit
- Maximum resources a container may use; CPU is throttled and memory overuse is killed.
- Millicore (m)
- One thousandth of a CPU core; 500m is half a core.
- Mi / Gi
- Binary memory units based on powers of 1024.
- QoS class
- Guaranteed, Burstable or BestEffort, derived from requests and limits and used for eviction order.
- ResourceQuota
- Namespace-wide cap on total resource usage and object counts.
- LimitRange
- Namespace policy that sets default and minimum/maximum resources per container, Pod or PVC.
- defaultRequest / default
- LimitRange fields giving the request and the limit applied when a container omits them.
- count/<resource>
- Quota key that limits how many objects of a type may exist in the namespace.
- ConfigMap
- An object holding non-secret configuration as key-value pairs.
- --from-env-file
- Creates one ConfigMap key per KEY=value line in a file.
- configMapKeyRef
- Sets one environment variable from one ConfigMap key.
- envFrom
- Imports all keys of a ConfigMap or Secret as environment variables.
- Opaque
- Default Secret type for arbitrary user data, created with kubectl create secret generic.
- kubernetes.io/dockerconfigjson
- Secret type holding registry credentials, used via imagePullSecrets.
- kubernetes.io/tls
- Secret type holding tls.crt and tls.key for certificates.
- Base64
- Reversible text encoding used for Secret data; it provides no confidentiality.
- secretKeyRef
- Sets one environment variable from one key of a Secret.
- ServiceAccount
- A namespaced identity for processes running in Pods.
- serviceAccountName
- Pod spec field choosing which ServiceAccount the Pod runs as.
- Bound (projected) token
- A short-lived, audience-scoped token tied to a Pod and refreshed by the kubelet.
- automountServiceAccountToken
- Setting on a ServiceAccount or Pod that controls whether the token is mounted.
- kubectl create token
- Command that issues a short-lived token for a ServiceAccount.
- runAsUser
- Numeric UID the container processes run as.
- runAsNonRoot
- Makes the kubelet refuse to start a container that would run as UID 0.
- fsGroup
- Pod-level supplementary group applied to containers and to ownership of supported volumes.
- readOnlyRootFilesystem
- Container-level setting that makes the container's root filesystem read-only.
- allowPrivilegeEscalation
- Container-level setting that, when false, stops processes gaining more privileges than their parent.
- Capability
- A named slice of root privilege, such as NET_BIND_SERVICE, that can be added to or dropped from a container.
- Pod Security Admission
- Built-in admission controller enforcing Pod Security Standards through namespace labels.
- Baseline
- Pod Security level that blocks known privilege escalations such as privileged containers and host namespaces.
- Restricted
- Strictest Pod Security level requiring non-root, no privilege escalation, dropped capabilities and a seccomp profile.
- enforce / audit / warn
- PSA modes that reject, log or warn about violating Pods.
Domain 5: Services and Networking (20%)
Exam tips
- Each type builds on the previous one: LoadBalancer includes a NodePort, which includes a ClusterIP. ExternalName and headless are the odd ones out: no proxying and no virtual IP.
- port is what clients call, targetPort is where the Pod listens, nodePort is on the nodes. Endpoints present but connections refused points to targetPort; no endpoints points to the selector or readiness.
- Empty endpoints means one of two things: no Pod matches the selector, or matching Pods are not ready. Check
kubectl get pods -l <selector>and the READY column. - A short Service name only resolves from the same namespace. Across namespaces, use at least
<service>.<namespace>. exposecopies the real selector;create serviceassumes app=<name>.exposehas no flag for a specific nodePort, so generate YAML and add it.- Policies only add allowances; being selected is what isolates.
podSelector: {}means all Pods, whileingress: [{}]means allow all, the opposite of no rules. - One dash with both selectors means AND; two dashes means OR. After adding an egress policy, always allow port 53 UDP and TCP for DNS.
- If an exam-style question asks why a correct NetworkPolicy has no effect, the answer is that the cluster's CNI plugin does not enforce NetworkPolicy.
- Prefix matches whole path segments (
/apidoes not match/apiv2); Exact matches one path only. Inkubectl create ingress, a trailing*means Prefix. - 404 from the controller means no rule matched (host, path or class); 503 means the rule matched but the Service has no ready endpoints. Always set the Host header when testing by IP.
Key terms
- ClusterIP
- Default Service type with an internal virtual IP reachable only inside the cluster.
- NodePort
- Service type that also opens a port (default range 30000-32767) on every node.
- LoadBalancer
- Service type that provisions an external load balancer through the cloud provider or an add-on.
- ExternalName
- Service type that returns a DNS CNAME to an external host, without proxying.
- Headless Service
- Service with clusterIP: None whose DNS returns individual Pod IPs.
- port
- The port the Service listens on at its ClusterIP and DNS name.
- targetPort
- The Pod port traffic is forwarded to; defaults to port, may be a named port.
- Named port
- A containerPort with a name that a Service can reference as its targetPort.
- EndpointSlice
- An object listing the addresses, ports and readiness of Pods backing a Service.
- kubernetes.io/service-name
- Label linking an EndpointSlice to its Service.
- Ready condition
- Endpoint flag showing whether a backend Pod should receive traffic.
- CoreDNS
- The DNS server that normally provides cluster DNS for Services and Pods.
- Service FQDN
- The fully qualified Service name <service>.<namespace>.svc.cluster.local.
- Search domains
- Suffixes in a Pod's resolv.conf that let short names like web resolve within its namespace.
- ndots
- Resolver option setting how many dots a name needs before it is tried as absolute first.
- kubectl expose
- Creates a Service for an existing resource, copying its selector.
- kubectl create service
- Creates a Service of a given type from scratch, with selector app=<name>.
- --tcp=port:targetPort
- Flag for create service that sets the Service port and target port.
- kubectl port-forward
- Temporary tunnel from a local port to one Pod; creates no Service.
- NetworkPolicy
- Namespaced object that restricts traffic to and from selected Pods.
- podSelector
- Chooses the Pods a policy applies to; {} selects all Pods in the namespace.
- policyTypes
- Ingress, Egress or both: which directions the policy isolates.
- Isolated Pod
- A Pod selected by a policy for a direction, which then only allows traffic explicitly permitted.
- Default deny
- A policy selecting all Pods with no allow rules, blocking all traffic in the listed directions.
- namespaceSelector
- Peer that matches Pods in namespaces with the given labels.
- ipBlock
- Peer that matches a CIDR range, with optional except ranges, usually for external traffic.
- AND semantics
- namespaceSelector and podSelector in the same peer item must both match.
- OR semantics
- Separate peer items or separate rules each allow traffic independently.
- kubernetes.io/metadata.name
- Automatic namespace label holding the namespace's name.
- CNI (Container Network Interface)
- The standard interface Kubernetes uses to have a plugin set up Pod networking.
- Network plugin
- The CNI implementation that provides Pod networking and, if supported, enforces NetworkPolicy.
- Calico / Cilium
- Widely used network plugins that enforce NetworkPolicy.
- eBPF
- Linux kernel technology for running small verified programs, used by some plugins to filter traffic.
- Ingress
- An object defining host- and path-based HTTP(S) routing rules to Services.
- ingressClassName
- Field selecting which IngressClass (controller) implements the Ingress.
- pathType Prefix
- Matches the path and anything below it, element by element.
- pathType Exact
- Matches only the exact URL path.
- defaultBackend
- Service that receives requests matching no rule.
- Ingress controller
- The component that watches Ingress objects and runs the proxy that routes traffic.
- IngressClass
- Object identifying a controller that Ingresses select with ingressClassName.
- Host header
- HTTP header naming the requested host, used by Ingress host rules.
- curl --resolve
- Makes curl connect to a chosen IP for a host name, keeping the correct name for TLS.
Study CKAD for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CKAD study planLessons, quizzes, exam simulations and hands-on labs.