OnCallReady

Lesson 19.6 · CKA Exam Drilling · 8 min read

Using the docs at exam speed

In plain words

Imagine an open-book exam where the book is a huge library, and you have seven minutes per question. You won't pass by browsing shelves. You pass by knowing exactly which book and which page has the recipe you need, and walking straight to it.

On the CKA you may use kubernetes.io/docs (with its search), the Kubernetes blog, the Helm docs and the Gateway API docs. The skill is knowing the handful of pages that hold a whole task: "Configure a Pod to Use a PersistentVolume for Storage" has the PV, PVC and pod; "Network Policies" has the examples; the kubectl Quick Reference has jsonpath and sort-by lines. For field names, kubectl explain --recursive is faster than any page, and for etcd's TLS flags, the manifest on the node is.

The docs are allowed - finding things in them is the skill

The problem. The docs are open during the exam, but searching them blindly eats minutes. Knowing which page holds which example turns the docs into a copy-paste source.

What you need to know already: the allowed sites (19.1); the objects the pages describe (chapters 15-18).

You may use kubernetes.io/docs (with its search), kubernetes.io/blog, helm.sh/docs and gateway-api.sigs.k8s.io. You do not have time to browse: know which page has the example you need, and get there with one search.

The pages that hold a whole task

you needsearch forthe pagewhat to copy
PV + PVC + pod"persistent volume storage"Configure a Pod to Use a PersistentVolume for Storageall three manifests
StorageClass fields"storage classes"Storage Classesthe example class, reclaimPolicy, volumeBindingMode, default annotation
NetworkPolicy"network policies"Network Policiesthe test-network-policy example; the "default deny" snippets
Ingress"ingress"Ingressthe minimal-ingress example, pathType
HTTPRoute(gateway-api.sigs.k8s.io) "HTTP routing"HTTP routing guidethe HTTPRoute with matches and backendRefs
Taints"taints tolerations"Taints and Tolerationsthe toleration block
Node affinity"assign pods nodes affinity"Assign Pods to Nodes using Node AffinityrequiredDuringScheduling... block
Probes"liveness readiness probes"Configure Liveness, Readiness and Startup ProbeshttpGet / tcpSocket examples
Sidecar"sidecar containers"Sidecar ContainersinitContainers + restartPolicy: Always
ConfigMap volume"configure pod configmap"Configure a Pod to Use a ConfigMapvolume + volumeMounts
Secret env"distribute credentials secrets"Distribute Credentials Securely Using Secretsenv valueFrom.secretKeyRef
etcd backup"etcd backup"Operating etcd clusters for Kubernetessnapshot save + restore commands
kubeadm upgrade"upgrading kubeadm clusters"Upgrading kubeadm clustersthe per-node command sequence
Certificates"certificate management kubeadm"Certificate Management with kubeadmcheck-expiration, renew
RBAC"using rbac"Using RBAC AuthorizationRole/ClusterRole examples, the kubectl create commands
kubectl output"kubectl cheat sheet"kubectl Quick Referencejsonpath, sort-by, custom-columns
JSONPath"jsonpath"JSONPath Supportrange/end syntax

The kubectl Quick Reference (cheat sheet) is worth reading once before the exam end to end - half the "write X to a file" tasks are a line from it.

Copy, then trim

Docs examples carry extra fields (labels, a second port, a comment). Paste into your file, then delete what the task does not ask for and change the names. Do not keep an example's namespace: default or its app: nginx labels by accident - they do not match your task's pods.

# an illustration: paste from the docs page into a file (nano here; vim on the exam)
cat > pv.yaml
(paste, Ctrl+Shift+V)
^D
vim pv.yaml       # names, size, class, path
k apply -f pv.yaml

In vim, :set paste before pasting stops the auto-indent from turning a pasted block into a staircase; :set nopaste after.

Faster than the docs

For field names, kubectl explain --recursive answers in two seconds with no search:

$ k explain cronjob.spec.jobTemplate.spec --recursive | grep -i deadline
  activeDeadlineSeconds	<integer>
$ k explain pod.spec.topologySpreadConstraints --recursive | head -20

For generator flags, k create role -h | grep -A3 Examples beats the web page.

What the docs will not tell you in time

The etcdctl TLS flags: they are in the etcd static pod manifest on the node, faster than any page:

# an illustration: paste from the docs page into a file (nano here; vim on the exam)
sudo grep -E 'listen-client|cert-file|key-file|trusted-ca' /etc/kubernetes/manifests/etcd.yaml
    - --cert-file=/etc/kubernetes/pki/etcd/server.crt
    - --key-file=/etc/kubernetes/pki/etcd/server.key
    - --listen-client-urls=https://127.0.0.1:2379,https://10.64.0.10:2379
    - --peer-cert-file=/etc/kubernetes/pki/etcd/peer.crt
    - --peer-key-file=/etc/kubernetes/pki/etcd/peer.key
    - --peer-trusted-ca-file=/etc/kubernetes/pki/etcd/ca.crt
    - --trusted-ca-file=/etc/kubernetes/pki/etcd/ca.crt

--trusted-ca-file -> --cacert, --cert-file -> --cert, --key-file -> --key, the first listen URL -> --endpoints. The same goes for any control-plane flag: the manifest on the node is the source of truth.

Practise with the docs, not from memory

In the drills, when a hint says "docs: Network Policies", open that page in a real browser and copy from it - build the reflex of which page, which example, where on the page. Before the exam, write your own list of the 15 pages above and open each once in the exam week.

Why it helps

Objects without generators (PV, PVC, StorageClass, NetworkPolicy, HTTPRoute) are where the docs earn their keep, and finding the right example in one search instead of three minutes of browsing is the difference between an eight-minute task and a fifteen-minute one. "Copy, then trim" also avoids the classic bug of keeping the example's app: nginx labels or namespace: default.

Beyond the exam, knowing the official docs well is a real job skill: when a teammate's NetworkPolicy doesn't work, the reference page and its examples are the fastest way to settle an argument. And the habit of reading config from the source of truth (the etcd manifest for its flags, kubectl explain for your cluster's schema) instead of from a blog post is how you avoid version-mismatched advice.

FAQ

Can I follow a search result to Stack Overflow or GitHub?

No. You may use the search on kubernetes.io/docs, but you may only open results on the allowed sites: kubernetes.io/docs, kubernetes.io/blog, helm.sh/docs and gateway-api.sigs.k8s.io. Following a link off those sites is against the rules. No notes, no other tabs.

Which docs page should I know best?

The kubectl Quick Reference (the cheat sheet). Half of the "write X to a file" tasks are a line from it: jsonpath expressions, --sort-by, custom-columns, context commands. Read it end to end once before the exam, and practise the lines you'd have trouble writing from memory.

Why does my pasted YAML turn into a staircase in vim?

vim's auto-indent adds indentation to every pasted line. Type :set paste before pasting and :set nopaste after, or set expandtab, tabstop=2 and shiftwidth=2 in ~/.vimrc and paste with care. In nano, set tabstospaces and tabsize 2 in ~/.nanorc. YAML breaks on tabs either way.

Where do I find the etcdctl certificate paths quickly?

In the etcd static pod manifest on the control-plane node: sudo grep -E 'listen-client|cert-file|key-file|trusted-ca' /etc/kubernetes/manifests/etcd.yaml. --trusted-ca-file becomes --cacert, --cert-file becomes --cert, --key-file becomes --key, and the first listen URL is --endpoints. It's faster than any docs page.

What should I change after copying a docs example?

Everything that's the example's, not yours: the names, the namespace (don't keep namespace: default), labels and selectors (the example's app: nginx won't match your pods), sizes, ports, storage class names. And delete extra fields the task didn't ask for, like a second port or an extra rule. Then k apply and verify.

In an interview Junior

How do you find information quickly when you are working with an unfamiliar Kubernetes feature?

In order of speed:

  1. kubectl explain - field names and shapes without leaving the terminal: k explain pod.spec.containers.livenessProbe --recursive; without --recursive you get descriptions and defaults.
  2. -h on the command - k create role -h shows the flags and examples.
  3. The source of truth on the machine - for control-plane components the static pod manifest (sudo grep cert-file /etc/kubernetes/manifests/etcd.yaml gives etcdctl's TLS flags faster than any page).
  4. The docs, by search, to a known page - "Configure a Pod to Use a PersistentVolume for Storage", "Network Policies", "Using RBAC Authorization", the kubectl Quick Reference. Know which page has the example you need.

Then copy and trim: paste the example, delete what the task does not ask for, rename everything - never keep the example's namespace or labels by accident.

Also asked: How do you write a NetworkPolicy under time pressure without mistakes? · Why prefer kubectl explain over the documentation website? · Which documentation pages would you bookmark for Kubernetes operations work?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.