The docs are allowed - finding things in them is the skill
The problem. The docs are open during the exam, but searching them blindly eats minutes. Knowing which page holds which example turns the docs into a copy-paste source.
What you need to know already: the allowed sites (19.1); the objects the pages describe (chapters 15-18).
You may use kubernetes.io/docs (with its search), kubernetes.io/blog, helm.sh/docs and gateway-api.sigs.k8s.io. You do not have time to browse: know which page has the example you need, and get there with one search.
The pages that hold a whole task
| you need | search for | the page | what to copy |
|---|---|---|---|
| PV + PVC + pod | "persistent volume storage" | Configure a Pod to Use a PersistentVolume for Storage | all three manifests |
| StorageClass fields | "storage classes" | Storage Classes | the example class, reclaimPolicy, volumeBindingMode, default annotation |
| NetworkPolicy | "network policies" | Network Policies | the test-network-policy example; the "default deny" snippets |
| Ingress | "ingress" | Ingress | the minimal-ingress example, pathType |
| HTTPRoute | (gateway-api.sigs.k8s.io) "HTTP routing" | HTTP routing guide | the HTTPRoute with matches and backendRefs |
| Taints | "taints tolerations" | Taints and Tolerations | the toleration block |
| Node affinity | "assign pods nodes affinity" | Assign Pods to Nodes using Node Affinity | requiredDuringScheduling... block |
| Probes | "liveness readiness probes" | Configure Liveness, Readiness and Startup Probes | httpGet / tcpSocket examples |
| Sidecar | "sidecar containers" | Sidecar Containers | initContainers + restartPolicy: Always |
| ConfigMap volume | "configure pod configmap" | Configure a Pod to Use a ConfigMap | volume + volumeMounts |
| Secret env | "distribute credentials secrets" | Distribute Credentials Securely Using Secrets | env valueFrom.secretKeyRef |
| etcd backup | "etcd backup" | Operating etcd clusters for Kubernetes | snapshot save + restore commands |
| kubeadm upgrade | "upgrading kubeadm clusters" | Upgrading kubeadm clusters | the per-node command sequence |
| Certificates | "certificate management kubeadm" | Certificate Management with kubeadm | check-expiration, renew |
| RBAC | "using rbac" | Using RBAC Authorization | Role/ClusterRole examples, the kubectl create commands |
| kubectl output | "kubectl cheat sheet" | kubectl Quick Reference | jsonpath, sort-by, custom-columns |
| JSONPath | "jsonpath" | JSONPath Support | range/end syntax |
The kubectl Quick Reference (cheat sheet) is worth reading once before the exam end to end - half the "write X to a file" tasks are a line from it.
Copy, then trim
Docs examples carry extra fields (labels, a second port, a comment). Paste into your file, then delete what the task does not ask for and change the names. Do not keep an example's namespace: default or its app: nginx labels by accident - they do not match your task's pods.
# an illustration: paste from the docs page into a file (nano here; vim on the exam)
cat > pv.yaml
(paste, Ctrl+Shift+V)
^D
vim pv.yaml # names, size, class, path
k apply -f pv.yaml
In vim, :set paste before pasting stops the auto-indent from turning a pasted block into a staircase; :set nopaste after.
Faster than the docs
For field names, kubectl explain --recursive answers in two seconds with no search:
$ k explain cronjob.spec.jobTemplate.spec --recursive | grep -i deadline
activeDeadlineSeconds <integer>
$ k explain pod.spec.topologySpreadConstraints --recursive | head -20
For generator flags, k create role -h | grep -A3 Examples beats the web page.
What the docs will not tell you in time
The etcdctl TLS flags: they are in the etcd static pod manifest on the node, faster than any page:
# an illustration: paste from the docs page into a file (nano here; vim on the exam)
sudo grep -E 'listen-client|cert-file|key-file|trusted-ca' /etc/kubernetes/manifests/etcd.yaml
- --cert-file=/etc/kubernetes/pki/etcd/server.crt
- --key-file=/etc/kubernetes/pki/etcd/server.key
- --listen-client-urls=https://127.0.0.1:2379,https://10.64.0.10:2379
- --peer-cert-file=/etc/kubernetes/pki/etcd/peer.crt
- --peer-key-file=/etc/kubernetes/pki/etcd/peer.key
- --peer-trusted-ca-file=/etc/kubernetes/pki/etcd/ca.crt
- --trusted-ca-file=/etc/kubernetes/pki/etcd/ca.crt
--trusted-ca-file -> --cacert, --cert-file -> --cert, --key-file -> --key, the first listen URL -> --endpoints. The same goes for any control-plane flag: the manifest on the node is the source of truth.
Practise with the docs, not from memory
In the drills, when a hint says "docs: Network Policies", open that page in a real browser and copy from it - build the reflex of which page, which example, where on the page. Before the exam, write your own list of the 15 pages above and open each once in the exam week.