CKA Prep


25년 2월 18일 변경 이후 시험 범위

  • Storage – 10%
    • Implement storage classes and dynamic volume provisioning
    • Configure volume types, access modes and reclaim policies
    • Manage persistent volumes and persistent volume claims
  • Troubleshooting – 30%
    • Troubleshoot clusters and nodes
    • Troubleshoot cluster components
    • Monitor cluster and application resource usage
    • Manage and evaluate container output streams
    • Troubleshoot services and networking
  • Workloads and Scheduling – 15%
    • Understand application deployments and how to perform rolling update and rollbacks
    • Use ConfigMaps and Secrets to configure applications
    • Configure workload autoscaling
    • Understand the primitives used to create robust, self-healing, application deployments
    • Configure Pod admission and scheduling (limits, node affinity, etc.)
  • Cluster Architecture, Installation and Configuration – 25%
    • Manage role based access control (RBAC)
    • Prepare underlying infrastructure for installing a Kubernetes cluster
    • Create and manage Kubernetes clusters using kubeadm
    • Manage the lifecycle of Kubernetes clusters
    • Implement and configure a highly-available control plane
    • Use Helm and Kustomize to install cluster components
    • Understand extension interfaces (CNI, CSI, CRI, etc.)
    • Understand CRDs, install and configure operators
  • Servicing and Networking – 20%
    • Understand connectivity between Pods
    • Define and enforce Network Policies
    • Use ClusterIP, NodePort, LoadBalancer service types and endpoints
    • Use the Gateway API to manage Ingress traffic
    • Know how to use Ingress controllers and Ingress resources
    • Understand and use CoreDNS

Storage 10%


1. Storage Class, PV, PVC

  • PVC 생성 (PV 와 SC 는 주어짐) + kubectl edit 또는 kubectl patch 로 용량 변경
  • PV - PVC - Pod 마운트
  • volume types, access modes and reclaim policies
  • StorageClass 는 보통 docs 복붙 후 필드 수정으로 간단함

Troubleshooting 30%


2. crictl, journalctl

3. Pod Troubleshooting

4. Node Troubleshooting

  • NotReady 상태 Ready 가 되도록 트러블슈팅
  • 보통 kubelet

5. etcd

  • etcd 인증 관련 이슈
  • etcd 마이그레이션

6. kubectl

  • Pod 로그 확인하여 특정 단어가 들어간 log grep 해서 파일로 저장
  • Taint 가 없는 노드 개수 파일로 저장
  • 노드 Ready 개수 파일로 저장
  • 사용률이 가장 높은 파드를 특정 label 로 조회해서 파일로 저장
  • explain 명령어로 특정 속성값 정보 파일에 저장하기
  • 11. K8s Advanced kubectl Commands

Workloads & Scheduling 15%


7. Static Pod

8. ConfigMap, Secret

9. Deployment

  • Deployment 생성 후 이미지 업그레이드
  • Deployment replica 수 수정
  • 파드 환경변수 주입 name/value, secret/configmap, 파드 자체의 정보를 환경 변수로 주입

10. Priority Class

  • Priority Class 만들어서 Pod 에 연결

11. Sidecar Container

  • 로그 수집 목적 사이드카 컨테이너 추가

12. Taint & Toleration, Node Affinity, Node Selector

  • Pod 에 nodeSelector (disktype=ssd) 추가하여 특정 Node 에 배포

13. HPA, VPA

  • 존재하는 deployment 에 알맞은 hpa 생성
  • CPU max/min 설정, Stabilization window 구현
  • 보통 docs 복붙 후 필드 수정으로 간단함

Cluster Architecture, Installation & Configuration 25%


14. kubeadm, kubelet, kubectl

  • 노드 drain 후 다른 노드로 파드 옮기기

15. ETCD snapshot save & restore

16. RBAC

  • ServiceAccount 생성
  • ClusterRole/Role 생성
  • ClusterRoleBinding 생성 후 확인

17. Helm

  • helm 으로 argocd 설치
  • helm install
  • helm upgrade
  • helm get values

18. CRI

  • dpkg -i 명령으로 .deb 파일 설치 후 systemctl
  • 설치 후 net.ipv4.ip_forward = 1 등 네트워크 설정 (sysctl -p /etc/sysctl.d/k8s.conf)

19. CNI

  • NetworkPolicy 적용이 가능한 Calico 설치

Services & Networking 20%


20. CoreDNS

21. Service

  • 이미 배포된 Deployment 의 ContainerPort 를 NodePort 로 expose
  • Pod (port 80) 생성 후 NodePort 타입의 Service 생성

22. Ingress

  • Ingress 생성 후 이미 생성되어 있는 서비스와 연결 후 확인

23. Gateway API

  • Ingress 설정을 GatewayAPI, HTTPRoute(TLS) 로 마이그레이션
  • TLS 연동 Gateway yaml

24. Network Policy

  • NetworkPolicy 를 생성해서 특정 namespace 의 Pod 만 특정 경로로 연결

References