CKA — Kubernetes Administrator
Investigating and Operating a Cluster
Goal
Get hands-on practice with the seven things you do when you first get into a cluster: investigation, namespaces, labels and annotations, context switching, node labeling, kubectl explain, and dry-run manifest generation.
Why it matters
The CKA is 17 problems in 120 minutes. That is 7 minutes per problem. If you write manifests by hand from scratch, you will run out of time. So extracting a skeleton with --dry-run=client -o yaml and editing only the fields you need is effectively the standard strategy.
kubectl explain is the other half. The only documentation you can see in the exam room is the official Kubernetes documentation, and explain is much faster for confirming the exact spelling and location of a single field. The difference between labels and annotations is in the same vein. A label is an identifier that a selector can pick, so Services and controllers refer to it; an annotation is extra information that cannot be selected, so tools use it to carry metadata. If you swap the two, nothing gets connected, and you get no error.
Steps
- Create the namespace
cka-basicsand attach the labelenv=lab. - Save the names of all nodes in the cluster to
/root/cka-basics/nodes.txt, one per line. The file must contain only names, with no header and nonode/prefix. - In
cka-basics, create the ConfigMapapp-meta. The data isenv=lab, the label istier=backend, and the annotation isowner=cka-student. - Create a context that uses
cka-basicsas its default namespace, namedcka-basics-ctx, reusing the cluster and user you are currently using, and switch to that context. - On the node
lab-node-1, attach the labelsdisktype=ssdandtopology.kubernetes.io/zone=rack-aand the annotationowner=cka-student. - Extract the description of the Pod toleration
effectfield withkubectl explainand save it to/root/cka-basics/explain.txt. - Use dry-run to generate a manifest for the Deployment
web(imagenginx:1.27, 3 replicas) and save it to/root/cka-basics/web.yaml. Do not apply it yet in this step. - Apply that manifest to
cka-basics, attach the labeltier=backendto the Deployment object, and confirm 3/3 Ready.
Reference
- There are options that drop the header, as in
kubectl get nodes -o custom-columns=NAME:.metadata.name --no-headers. - You create a context with
kubectl config set-context <이름> --cluster=... --user=... --namespace=...(where the placeholder is the context name) and switch to it withuse-context. - Common mistake 1: attaching the label only to the Pod template and not to the Deployment itself. Step 8 looks at the labels on the Deployment object.
- Common mistake 2: inventing new cluster or user names when creating the context. You must reuse the existing names so that the connection is kept.
Create a namespace and attach a label
Create the namespace cka-basics and attach the label env=lab.
You can create the namespace and then attach the label separately, or put it in the manifest from the start. The label goes under metadata.labels.
Extract the node list to a file
Save the names of all nodes in the cluster to /root/cka-basics/nodes.txt, one per line. The file must contain only names, with no header and no node/ prefix.
The file must contain only node names, one per line. Think about how to strip the header or the node/ prefix from the output. The range in jsonpath or -o custom-columns can help.
Attach a label and an annotation, keeping them distinct
In cka-basics, create the ConfigMap app-meta. The data is env=lab, the label is tier=backend, and the annotation is owner=cka-student.
A label is an identifier that a selector can pick, and an annotation is extra information that cannot be picked. They are stored in different places (metadata.labels and metadata.annotations).
Create and switch a kubeconfig context
Create a context that uses cka-basics as its default namespace, named cka-basics-ctx, reusing the cluster and user you are currently using, and switch to that context.
A context is a triple of cluster + user + namespace. You do not need to create a new cluster or user; reuse the existing names. First check the names with kubectl config get-clusters and get-users.
Attach labels and an annotation to a node
On the node lab-node-1, attach the labels disktype=ssd and topology.kubernetes.io/zone=rack-a and the annotation owner=cka-student.
A node is also an object, so the label and annotate commands work as they are. A key containing a slash can be used as is.
Extract a field description with kubectl explain
Extract the description of the Pod toleration effect field with kubectl explain and save it to /root/cka-basics/explain.txt.
explain follows nested fields with dot notation. Point to the field inside the tolerations array of the Pod spec.
Generate a manifest with dry-run
Use dry-run to generate a manifest for the Deployment web (image nginx:1.27, 3 replicas) and save it to /root/cka-basics/web.yaml. Do not apply it yet in this step.
If you add --dry-run=client -o yaml to a kubectl create command, it outputs only YAML without touching the API. You can give the replica count as a create option.
Apply it and finish with the label
Apply that manifest to cka-basics, attach the label tier=backend to the Deployment object, and confirm 3/3 Ready.
Apply the file you created in the earlier step as it is. The label must go on the Deployment object itself, not on the Pod template. It takes a moment for the Pods to become Ready.