Kubernetes & CKA Concepts

The container orchestration domain of the Digital Brain. Curated for the CKA Certification journey.

Core Concepts

PageDescription
CKA CertificationExam structure, domains, and preparation strategy
CKA Study RoadmapThe 40-day learning plan and daily schedule
CKA Practice TasksComprehensive hands-on drill index for every CKA topic
Why Kubernetes?Why K8s exists: problems it solves and when NOT to use it
Kubernetes NamespacesLogical isolation, multi-tenancy, resource quotas, and default namespaces

Prerequisites

Architecture & Installation

PageDescription
Kubernetes ArchitectureControl Plane, Worker Nodes, component deep-dive, communication flows
Kind Cluster SetupLocal multi-node K8s cluster with Kind (Kubernetes IN Docker)
Kubeadm Cluster SetupProduction cluster installation: ports, containerd, CNI, certificates, upgrades
Kubernetes Cluster UpgradeRolling update strategy, kubeadm commands, and worker-node sequencing
Node MaintenanceDrain, cordon, uncordon: safe node evacuation and scheduling gates
Versioning & Version SkewRelease cadence, support lifecycle, and component compatibility rules
ETCD Backup & RestoreSnapshot, restore, certificate paths, and stacked vs external ETCD
Disaster RecoveryDR hierarchy, RTO/RPO, persistent data protection, and cluster reconstruction

(More to be populated as ingestion progresses)

  • High Availability (HA) Clusters

Workloads & Scheduling

PageDescription
Pod FundamentalsPods: the smallest deployable unit, imperative vs declarative, YAML basics
Multi-Container PodsSidecar, init, adapter, and ambassador patterns; shared namespaces and volumes
Init ContainersPre-start setup, validation, and migration containers
Sidecar PatternAuxiliary containers for logging, monitoring, proxying, and TLS termination
Kubernetes Environment VariablesConfigMap, Secret, Downward API, and literal injection patterns
Pod Commands and ArgumentsOverriding ENTRYPOINT and CMD in container specs
Deployment, ReplicaSet & Replication ControllerWorkload controllers: self-healing, scaling, rolling updates, and rollback
Kubernetes DaemonSetNode-level workload: one Pod per node for monitoring, CNI, and agents
Kubernetes JobsBatch execution: finite tasks that run to completion with retry logic
Kubernetes CronJobsScheduled batch: time-based Job creation with cron expressions
Kubernetes Static PodsNode-local Pods managed by kubelet, used for control plane bootstrapping
Kubernetes Labels and SelectorsMetadata and query system that binds Services, controllers, and Pods
Kubernetes Manual SchedulingBypassing the scheduler with nodeName, nodeSelector, and taints/tolerations
Kubernetes Taints and TolerationsNegative scheduling: node taints, Pod tolerations, effects, and built-in taint catalog
Kubernetes Node AffinityAdvanced positive scheduling: rich operators, soft/hard constraints, and the taints+affinity production pattern
Kubernetes Resource Requests and LimitsCPU/memory requests, limits, Metrics Server, OOMKilled, and Pending resource failures
Kubernetes AutoscalingHPA, VPA, Cluster Autoscaler, Node Auto-Provisioning: scaling mechanisms at Pod and cluster level
Horizontal Pod Autoscaler (HPA)CPU/memory-based replica scaling, YAML anatomy, and imperative commands
Vertical Pod Autoscaler (VPA)Resource right-sizing: Off, Initial, and Auto modes
Kubernetes Health ProbesLiveness, readiness, and startup probes: mechanisms, parameters, and troubleshooting
Kubernetes ConfigMaps and SecretsConfigMap and Secret objects: creation, volume mounting, env injection, and security

(More to be populated as ingestion progresses)

  • StatefulSets
  • ResourceQuotas and LimitRanges
  • Ingress & Ingress Controllers

Services & Networking

PageDescription
Kubernetes ServicesService abstraction, port concepts, Endpoints, and imperative commands
Kubernetes Service TypesDeep dive into ClusterIP, NodePort, LoadBalancer, and ExternalName
Kubernetes Network PoliciesCNI support matrix, default deny patterns, ingress/egress whitelist design, and exam troubleshooting
CoreDNSKubernetes cluster DNS: Corefile, plugins, service discovery, and troubleshooting
Kubernetes CNIContainer Network Interface: plugins, cross-node routing, IPAM, and cluster bootstrap
Kubernetes IngressLayer 7 HTTP/HTTPS routing, Ingress Controllers, path types, TLS termination

Package Management & Application Delivery

PageDescription
HelmThe package manager for Kubernetes: charts, repositories, releases, and templating
Helm ChartsChart anatomy, Go templates, values design, and dependency management
Helm Release ManagementInstall, upgrade, rollback, and revision history

(More to be populated as ingestion progresses)

Storage

PageDescription
Docker StoragePrerequisite: Docker layered architecture, volume drivers, bind mounts, and the Kubernetes storage bridge
Kubernetes StoragePVs, PVCs, StorageClasses, access modes, reclaim policies, emptyDir, and hostPath

Security

PageDescription
TLS FundamentalsCertificates, handshake, cipher suites, PKI, and Kubernetes-specific TLS patterns

(More to be populated as ingestion progresses)

  • Kubernetes Authentication & Authorization — The two-gate security model: authn → authz → admission
  • Kubernetes Admission Controllers — Validating/mutating webhooks, built-in controllers, and the governance enforcement gate
  • Kyverno — Dynamic admission controller: YAML policies for validate, mutate, generate, and image verification
  • Falco — Runtime security engine: eBPF syscall monitoring and declarative rule alerts, deployed as a DaemonSet or host agent. Source: Falco CKS Scenarios
  • Runtime Security — Detecting threats while workloads execute; the detective complement to admission-time prevention.
  • CKS Certification — Certified Kubernetes Security Specialist: the security follow-up to CKA, covering hardening, supply chain, and Falco scenarios.
  • Kubernetes RBAC — Roles, ClusterRoles, RoleBindings, ClusterRoleBindings, and rule anatomy
  • Kubernetes Kubeconfig — clusters, users, contexts, and imperative kubectl config commands
  • Kubernetes Service Account — In-cluster identity, token mounting, RBAC binding, and imagePullSecrets
  • Pod Security Standards

Troubleshooting

(To be populated as ingestion progresses)

kubectl & CLI

(To be populated as ingestion progresses)

  • Essential kubectl Commands
  • kubectl Cheatsheet
  • Imperative vs Declarative Management

Tags: kubernetes cka devops containers scheduling networking security troubleshooting