certslothcertsloth
CKA/Topic 01

CNCF / Administrator

Cluster Lifecycle, RBAC and Extensions

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: API decides; controllers reconcile; nodes execute.

Must remember

The API server validates requests and exposes cluster state; etcd persists it. The scheduler assigns unscheduled Pods to nodes; controllers reconcile desired state. Node kubelets supervise Pods through a CRI runtime; CNI provides networking and CSI storage integration.

Before kubeadm installation, verify hostnames, addresses, time, ports, container runtime/cgroups and the version-specific swap requirements. kubeadm init creates a control plane; join information adds nodes. A highly available control plane needs multiple control-plane instances, a stable API endpoint/load balancer and a quorum-safe etcd design. A load balancer alone does not replicate etcd.

Upgrade deliberately: inspect version compatibility and kubeadm's upgrade plan, upgrade control-plane nodes in the documented order, then workers. Drain a node before disruptive maintenance, accounting for PodDisruptionBudgets and local data, and uncordon afterward. Do not force a blocked drain without understanding which workload guarantee it protects. Back up etcd and practise version-appropriate recovery in a sandbox.

RBAC grants verbs on API resources. A Role is namespaced; a ClusterRole can describe broader permissions. A RoleBinding can reference a ClusterRole while granting its namespaced permissions only in the binding's namespace. A ClusterRoleBinding grants cluster-wide scope. Bind users, groups or service accounts; inspect with kubectl auth can-i using the required identity/context.

RBAC permissions are additive: there is no ordinary RBAC deny rule to cancel another grant. Core resources use apiGroups: [""]; Deployments use apps; Pod logs are the separate pods/log subresource. Test the precise verb, resource and namespace, for example kubectl auth can-i get pods --as=system:serviceaccount:team:reader -n team. Impersonation itself requires permission; testing as the administrator does not prove the workload identity can perform the operation.

Helm templates and packages charts into releases with values; inspect rendered manifests, release history and upgrades. Kustomize transforms base YAML with overlays and patches without template substitution; inspect kubectl kustomize PATH. A CRD adds an API kind; an operator includes a controller that acts on custom resources. Installing a CRD alone does not implement reconciliation.

Practical drill: explain the path from an authenticated Deployment request to running containers, naming which component handles each step.

Choose under exam pressure

Requirement Choice and reason
Grant one namespace access A RoleBinding with only the required verbs/resources.
Configure a packaged application Helm values and a controlled release.
Patch environment-specific YAML Kustomize overlays.
Automate custom-resource behavior Install the matching operator, not just its CRD.

Traps

  • Namespaces do not by themselves enforce network isolation.
  • Deleting or editing etcd data is not an ordinary application troubleshooting step.

Active recall

1. Who selects a node for a Pod?

The scheduler; the kubelet on that node then manages execution.

2. Can RoleBinding reference ClusterRole?

Yes; the binding limits applicable namespaced permissions to its namespace.

3. Why is a CRD alone insufficient?

It extends the API schema but supplies no reconciliation controller.

4. Why drain before node maintenance?

It coordinates eviction of eligible Pods while respecting constraints such as disruption budgets.

5. Does a second API server eliminate etcd quorum requirements?

No. API availability and consistent etcd storage are separate requirements.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.