Points lost for nothing
The problem. Most lost points are not missing knowledge: they are the right fix on the wrong cluster, in the wrong namespace, or never checked. A short routine per task removes them.
What you need to know already: contexts and kubeconfig (15.1), namespaces (15.26), ssh to nodes and sudo -i (18.1).
These are the mistakes that cost passing candidates their margin and failing candidates the exam. None of them is about Kubernetes knowledge.
1. Wrong context, wrong host
The task said ssh cka7021 (or use-context hk8s); you stayed where the previous task left you. Every command works, the task looks done, it scores zero because the grader looks at the other cluster.
# the pattern (wk8s, hk8s are placeholders for the contexts a task names)
$ k config current-context
wk8s
$ k config use-context hk8s
Switched to context "hk8s".
The fix is mechanical: the first line of every task is its context/ssh line, typed before reading the rest. In this chapter every drill round starts you in the wrong context deliberately, and "Done in context X" is an objective of its own.
On ssh-based exams the mirror image: you are still on the previous task's host (the prompt says so - read it), or you forgot to ssh at all and k does not exist:
# the pattern (NS, RES, N, hk8s are placeholders for what a task names)
k get pods
k: command not found
2. Wrong namespace
$ k create deploy api --image=nginx:1.27
deployment.apps/api created
$ k get deploy api -n project-tiger
Error from server (NotFound): deployments.apps "api" not found
It went to default. Either -n NS on every command, or, for a task with many commands:
$ k config set-context --current --namespace=project-tiger
Context "hk8s" modified.
...and remember that this now applies to every later task on that context. Generated YAML without -n has no namespace field and lands wherever the current context points when you apply it; with -n NS the generator writes namespace: NS into the YAML - safer.
Cluster-scoped objects (PV, StorageClass, ClusterRole, Node) ignore -n; namespaced ones need it. A RoleBinding in the wrong namespace grants nothing where the task checks.
3. Not verifying
The grader checks state, and you only know state by looking. The five verifications that catch almost everything:
# the pattern (NS, VERB, RES, SUBJECT, N are placeholders for what a task names)
$ k get pods -n NS # Running, READY 1/1, RESTARTS 0
$ k auth can-i VERB RES -n NS --as=SUBJECT # yes, and a no
$ k exec -n NS toolbox -- wget -qO- -T 2 http://svc # traffic actually flows
$ k get pvc -n NS # Bound
$ cat /opt/course/N/file # the answer, not the command
A typo in an image tag shows up only as ImagePullBackOff a few seconds later. A Service with the wrong targetPort has endpoints and still refuses connections. Only a check catches them.
4. The wrong file, the wrong format
"Write it to /opt/course/5/pods" - you wrote /opt/course/5/pod.txt. "Only the name" - the file contains the header line too:
# the pattern (NS, RES, N, hk8s are placeholders for what a task names)
k top pod -n shop --sort-by=memory | head -1 > /opt/course/5/pod
cat /opt/course/5/pod
NAME CPU(cores) MEMORY(bytes)
--no-headers (or tail -n +2) and cat afterwards. Remember that ssh host cmd > file writes the file on the machine you typed it on, not on the host - often exactly what the task wants, sometimes not.
5. Fixing by recreating
"Fix Deployment X" - you deleted it and made a new one. It may pass; it may not (the grader may check the revision history, the uid, labels you did not copy). Fix in place: set, patch, edit, rollout undo. Same for taints: a task that says "make the pod run on the tainted node" is not solved by removing the taint - the grader checks the taint is still there.
6. Doing more than asked
"Allow only role=frontend" - you also allowed the monitoring namespace, just in case. "Exactly get, list" - you added watch. Extra permissions, extra policy peers and extra fields fail "exactly" checks. Read the adverbs: only, exactly, all, without.
7. Leaving things half-way on a node
# the pattern (NS, RES, N, hk8s are placeholders for what a task names)
mv /etc/kubernetes/manifests/kube-apiserver.yaml /tmp/
...and then the task time ran out. You took a component down and did not bring it back; every later task on that cluster fails too. Before editing a static pod manifest, copy it (cp kube-apiserver.yaml /root/kube-apiserver.yaml.bak) and edit in place rather than moving it out and back. After a node task: exit the root shell and the ssh session - the next task's ssh from a task host is nested ssh, which the exam does not support.
8. Forgetting the last step
- drain -> upgrade -> uncordon
- kubelet config change -> daemon-reload + restart kubelet
- a new default StorageClass -> the old one no longer default
- etcd restore -> the manifest's hostPath changed (not just the restore command run)
- swapoff -> /etc/fstab too (or it is back after a reboot)
The pre-flight for each task, in one line
Context, namespace, names copied, generator, verify, cat the file, exit the node.