Kubernetes & CKA Concepts
The container orchestration domain of the Digital Brain. Curated for the CKA Certification journey.
Core Concepts
| Page | Description |
|---|---|
| CKA Certification | Exam structure, domains, and preparation strategy |
| CKA Study Roadmap | The 40-day learning plan and daily schedule |
| CKA Practice Tasks | Comprehensive hands-on drill index for every CKA topic |
| Why Kubernetes? | Why K8s exists: problems it solves and when NOT to use it |
| Kubernetes Namespaces | Logical isolation, multi-tenancy, resource quotas, and default namespaces |
Prerequisites
- Docker Fundamentals — Containers, images, and the Docker workflow (Day 1 of CKA course)
Architecture & Installation
| Page | Description |
|---|---|
| Kubernetes Architecture | Control Plane, Worker Nodes, component deep-dive, communication flows |
| Kind Cluster Setup | Local multi-node K8s cluster with Kind (Kubernetes IN Docker) |
| Kubeadm Cluster Setup | Production cluster installation: ports, containerd, CNI, certificates, upgrades |
| Kubernetes Cluster Upgrade | Rolling update strategy, kubeadm commands, and worker-node sequencing |
| Node Maintenance | Drain, cordon, uncordon: safe node evacuation and scheduling gates |
| Versioning & Version Skew | Release cadence, support lifecycle, and component compatibility rules |
| ETCD Backup & Restore | Snapshot, restore, certificate paths, and stacked vs external ETCD |
| Disaster Recovery | DR hierarchy, RTO/RPO, persistent data protection, and cluster reconstruction |
(More to be populated as ingestion progresses)
- High Availability (HA) Clusters
Workloads & Scheduling
| Page | Description |
|---|---|
| Pod Fundamentals | Pods: the smallest deployable unit, imperative vs declarative, YAML basics |
| Multi-Container Pods | Sidecar, init, adapter, and ambassador patterns; shared namespaces and volumes |
| Init Containers | Pre-start setup, validation, and migration containers |
| Sidecar Pattern | Auxiliary containers for logging, monitoring, proxying, and TLS termination |
| Kubernetes Environment Variables | ConfigMap, Secret, Downward API, and literal injection patterns |
| Pod Commands and Arguments | Overriding ENTRYPOINT and CMD in container specs |
| Deployment, ReplicaSet & Replication Controller | Workload controllers: self-healing, scaling, rolling updates, and rollback |
| Kubernetes DaemonSet | Node-level workload: one Pod per node for monitoring, CNI, and agents |
| Kubernetes Jobs | Batch execution: finite tasks that run to completion with retry logic |
| Kubernetes CronJobs | Scheduled batch: time-based Job creation with cron expressions |
| Kubernetes Static Pods | Node-local Pods managed by kubelet, used for control plane bootstrapping |
| Kubernetes Labels and Selectors | Metadata and query system that binds Services, controllers, and Pods |
| Kubernetes Manual Scheduling | Bypassing the scheduler with nodeName, nodeSelector, and taints/tolerations |
| Kubernetes Taints and Tolerations | Negative scheduling: node taints, Pod tolerations, effects, and built-in taint catalog |
| Kubernetes Node Affinity | Advanced positive scheduling: rich operators, soft/hard constraints, and the taints+affinity production pattern |
| Kubernetes Resource Requests and Limits | CPU/memory requests, limits, Metrics Server, OOMKilled, and Pending resource failures |
| Kubernetes Autoscaling | HPA, VPA, Cluster Autoscaler, Node Auto-Provisioning: scaling mechanisms at Pod and cluster level |
| Horizontal Pod Autoscaler (HPA) | CPU/memory-based replica scaling, YAML anatomy, and imperative commands |
| Vertical Pod Autoscaler (VPA) | Resource right-sizing: Off, Initial, and Auto modes |
| Kubernetes Health Probes | Liveness, readiness, and startup probes: mechanisms, parameters, and troubleshooting |
| Kubernetes ConfigMaps and Secrets | ConfigMap and Secret objects: creation, volume mounting, env injection, and security |
(More to be populated as ingestion progresses)
- StatefulSets
- ResourceQuotas and LimitRanges
- Ingress & Ingress Controllers
Services & Networking
| Page | Description |
|---|---|
| Kubernetes Services | Service abstraction, port concepts, Endpoints, and imperative commands |
| Kubernetes Service Types | Deep dive into ClusterIP, NodePort, LoadBalancer, and ExternalName |
| Kubernetes Network Policies | CNI support matrix, default deny patterns, ingress/egress whitelist design, and exam troubleshooting |
| CoreDNS | Kubernetes cluster DNS: Corefile, plugins, service discovery, and troubleshooting |
| Kubernetes CNI | Container Network Interface: plugins, cross-node routing, IPAM, and cluster bootstrap |
| Kubernetes Ingress | Layer 7 HTTP/HTTPS routing, Ingress Controllers, path types, TLS termination |
Package Management & Application Delivery
| Page | Description |
|---|---|
| Helm | The package manager for Kubernetes: charts, repositories, releases, and templating |
| Helm Charts | Chart anatomy, Go templates, values design, and dependency management |
| Helm Release Management | Install, upgrade, rollback, and revision history |
(More to be populated as ingestion progresses)
Storage
| Page | Description |
|---|---|
| Docker Storage | Prerequisite: Docker layered architecture, volume drivers, bind mounts, and the Kubernetes storage bridge |
| Kubernetes Storage | PVs, PVCs, StorageClasses, access modes, reclaim policies, emptyDir, and hostPath |
Security
| Page | Description |
|---|---|
| TLS Fundamentals | Certificates, handshake, cipher suites, PKI, and Kubernetes-specific TLS patterns |
(More to be populated as ingestion progresses)
- Kubernetes Authentication & Authorization — The two-gate security model: authn → authz → admission
- Kubernetes Admission Controllers — Validating/mutating webhooks, built-in controllers, and the governance enforcement gate
- Kyverno — Dynamic admission controller: YAML policies for validate, mutate, generate, and image verification
- Falco — Runtime security engine: eBPF syscall monitoring and declarative rule alerts, deployed as a DaemonSet or host agent. Source: Falco CKS Scenarios
- Runtime Security — Detecting threats while workloads execute; the detective complement to admission-time prevention.
- CKS Certification — Certified Kubernetes Security Specialist: the security follow-up to CKA, covering hardening, supply chain, and Falco scenarios.
- Kubernetes RBAC — Roles, ClusterRoles, RoleBindings, ClusterRoleBindings, and rule anatomy
- Kubernetes Kubeconfig — clusters, users, contexts, and imperative
kubectl configcommands - Kubernetes Service Account — In-cluster identity, token mounting, RBAC binding, and imagePullSecrets
- Pod Security Standards
Troubleshooting
(To be populated as ingestion progresses)
- Node & Pod Failure Diagnostics
- Control Plane Troubleshooting
- Networking Issues
- Storage Failures
- Kubernetes Logging and Monitoring — Container/node/cluster logs, Metrics Server, and
kubectl toptroubleshooting - Kubernetes Application Troubleshooting — Systematic debugging chain: image pull, crash loops, service routing, rollout, and init container failures
- Kubernetes Control Plane Troubleshooting — kube-apiserver, etcd, scheduler, and controller-manager failure diagnosis, certificate expiry, and Static Pod recovery
- Kubernetes Worker Node Troubleshooting — kubelet, container runtime, CNI, kube-proxy, resource pressure, and automatic eviction
kubectl & CLI
(To be populated as ingestion progresses)
- Essential kubectl Commands
- kubectl Cheatsheet
- Imperative vs Declarative Management
Tags: kubernetes cka devops containers scheduling networking security troubleshooting