Share E-Book

Certified Kubernetes Application Developer (CKAD) Study Guide, 2nd Edition In-Depth Guidance and Practice (Benjamin Muschko)(Z-Library)

Author Benjamin Muschko

devops
Language English

Developers with the ability to operate, troubleshoot, and monitor applications in Kubernetes are in high demand today. To meet this need, the Cloud Native Computing Foundation created a certification exam to establish a developer's credibility and value in the job market for work in a Kubernetes environment. The Certified Kubernetes Application Developer (CKAD) exam format is different from the typical multiple-choice format of other certifications. Instead, the CKAD is performance-based and requires deep knowledge under immense time pressure. Updated to reflect revisions to the official curriculum made in September 2021, this revised study guide takes you through all the topics you need to fully prepare for the exam. Author Benjamin Muschko also shares his personal experience and tips. New topics include: Deployment strategies, Custom Resource Definitions (CRDs), authentication, authorization, and admission control, Ingress, and more. Learn when and how to apply Kubernetes's concepts to manage an application Understand the objectives, abilities, tips, and tricks needed to pass the CKAD exam Explore the ins and outs of the kubectl command-line tool Solve real-world Kubernetes problems in a hands-on command-line environment Navigate and solve questions during the CKAD exam

Format PDF
Size 5.1 MB
7
Views
0
Downloads
0.00
Total Donations
(First 20 pages)

Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Page 1
Second Edition In-Depth Guidance and Practice Certif ied Kubernetes Application Developer (CKAD) Study Guide Benjamin Muschko Foreword by Chris Aniszczyk
Page 2
(This page has no text content)
Page 3
Praise for Certified Kubernetes Application Developer (CKAD) Study Guide Benjamin Muschko is a cloud native guru and has expanded and sharpened this CKAD study guide. There is much to learn in Kubernetes, yet Ben keeps his focus on the concepts that are expected in the exam. Add this guide to ease your journey toward certification or to simply be a well-informed cloud native developer. —Jonathan Johnson, Independent Software Architect A direct, example-driven guide essential for CKAD exam preparation. —Bilgin Ibryam, Coauthor of Kubernetes Patterns, Principal Product Manager at Diagrid As someone who oversaw the creation of the CKAD in CNCF, I’m happy to see an updated study guide that covers the latest version of the ever evolving certification. —Chris Aniszczyk, CTO and Cofounder, CNCF
Page 4
(This page has no text content)
Page 5
Benjamin Muschko Foreword by Chris Aniszczyk Certified Kubernetes Application Developer (CKAD) Study Guide In-Depth Guidance and Practice SECOND EDITION Boston Farnham Sebastopol TokyoBeijing
Page 6
978-1-098-16949-7 Certified Kubernetes Application Developer (CKAD) Study Guide by Benjamin Muschko Copyright © 2024 Automated Ascent LLC. All rights reserved. Printed in the United States of America. Published by O’Reilly Media, Inc., 1005 Gravenstein Highway North, Sebastopol, CA 95472. O’Reilly books may be purchased for educational, business, or sales promotional use. Online editions are also available for most titles (http://oreilly.com). For more information, contact our corporate/institutional sales department: 800-998-9938 or corporate@oreilly.com. Acquisitions Editor: John Devins Development Editor: Virginia Wilson Production Editor: Beth Kelly Copyeditor: Piper Editorial Consulting, LLC Proofreader: Helena Stirling Interior Designer: David Futato Cover Designer: Karen Montgomery Illustrator: Kate Dullea February 2021: First Edition June 2024: Second Edition Revision History for the Second Edition 2024-5-22: First Release See http://oreilly.com/catalog/errata.csp?isbn=9781098152864 for release details. The O’Reilly logo is a registered trademark of O’Reilly Media, Inc. Certified Kubernetes Application Devel‐ oper (CKAD) Study Guide, the cover image, and related trade dress are trademarks of O’Reilly Media, Inc. The views expressed in this work are those of the author and do not represent the publisher’s views. While the publisher and the author have used good faith efforts to ensure that the information and instructions contained in this work are accurate, the publisher and the author disclaim all responsibility for errors or omissions, including without limitation responsibility for damages resulting from the use of or reliance on this work. Use of the information and instructions contained in this work is at your own risk. If any code samples or other technology this work contains or describes is subject to open source licenses or the intellectual property rights of others, it is your responsibility to ensure that your use thereof complies with such licenses and/or rights.
Page 7
Table of Contents Foreword. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xv Preface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xvii Part I. Introduction 1. Exam Details and Resources. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Kubernetes Certification Learning Path 3 Kubernetes and Cloud Native Associate (KCNA) 4 Kubernetes and Cloud Native Security Associate (KCSA) 4 Certified Kubernetes Application Developer (CKAD) 4 Certified Kubernetes Administrator (CKA) 4 Certified Kubernetes Security Specialist (CKS) 4 Exam Objectives 5 Curriculum 5 Application Design and Build 6 Application Deployment 6 Application Observability and Maintenance 6 Application Environment, Configuration, and Security 6 Services and Networking 7 Involved Kubernetes Primitives 7 Documentation 8 Exam Environment and Tips 8 Candidate Skills 9 Time Management 10 Command-Line Tips and Tricks 11 Setting a Context and Namespace 11 v
Page 8
Using the Alias for kubectl 11 Using kubectl Command Auto-Completion 11 Internalize Resource Short Names 12 Practicing and Practice Exams 12 Summary 13 2. Kubernetes in a Nutshell. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 What Is Kubernetes? 15 Features 16 High-Level Architecture 17 Control Plane Node Components 18 Common Node Components 18 Advantages 19 Summary 20 3. Interacting with Kubernetes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 API Primitives and Objects 21 Using kubectl 23 Managing Objects 24 Imperative Object Management 24 Declarative Object Management 26 Hybrid Approach 28 Which Approach to Use? 29 Summary 29 Part II. Application Design and Build 4. Containers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Container Terminology 34 Containerizing a Java-Based Application 35 Writing a Dockerfile 35 Building the Container Image 36 Listing Container Images 36 Running the Container 37 Listing Containers 37 Interacting with the Container 37 Publishing the Container Image 38 Saving and Loading a Container Image 39 Going Further 40 Summary 40 vi | Table of Contents
Page 9
Exam Essentials 40 Sample Exercises 41 5. Pods and Namespaces. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 Working with Pods 43 Creating Pods 43 Listing Pods 46 Pod Life Cycle Phases 46 Rendering Pod Details 47 Accessing Logs of a Pod 48 Executing a Command in Container 48 Creating a Temporary Pod 49 Using a Pod’s IP Address for Network Communication 49 Configuring Pods 50 Deleting a Pod 53 Working with Namespaces 53 Listing Namespaces 54 Creating and Using a Namespace 54 Setting a Namespace Preference 55 Deleting a Namespace 55 Summary 55 Exam Essentials 56 Sample Exercises 56 6. Jobs and CronJobs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Working with Jobs 59 Creating and Inspecting Jobs 60 Job Operation Types 61 Restart Behavior 62 Working with CronJobs 63 Creating and Inspecting CronJobs 64 Configuring Retained Job History 65 Summary 66 Exam Essentials 66 Sample Exercises 67 7. Volumes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69 Working with Storage 69 Volume Types 70 Ephemeral Volumes 70 Persistent Volumes 72 Table of Contents | vii
Page 10
Storage Classes 77 Summary 79 Exam Essentials 80 Sample Exercises 80 8. Multi-Container Pods. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83 Working with Multiple Containers in a Pod 83 Init Containers 84 The Sidecar Pattern 86 The Adapter Pattern 88 The Ambassador Pattern 90 Summary 93 Exam Essentials 93 Sample Exercises 94 9. Labels and Annotations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95 Working with Labels 95 Declaring Labels 96 Inspecting Labels 97 Modifying Labels for a Live Object 97 Using Label Selectors 98 Recommended Labels 100 Working with Annotations 101 Declaring Annotations 101 Inspecting Annotations 102 Modifying Annotations for a Live Object 102 Reserved Annotations 102 Summary 103 Exam Essentials 103 Sample Exercises 103 Part III. Application Deployment 10. Deployments. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107 Working with Deployments 107 Creating Deployments 108 Listing Deployments and Their Pods 110 Rendering Deployment Details 111 Deleting a Deployment 112 Performing Rolling Updates and Rollbacks 112 viii | Table of Contents
Page 11
Updating a Deployment’s Pod Template 113 Rolling Out a New Revision 113 Adding a Change Cause for a Revision 115 Rolling Back to a Previous Revision 115 Scaling Workloads 116 Manually Scaling a Deployment 116 Autoscaling a Deployment 117 Creating Horizontal Pod Autoscalers 118 Listing Horizontal Pod Autoscalers 119 Rendering Horizontal Pod Autoscaler Details 120 Defining Multiple Scaling Metrics 120 Summary 122 Exam Essentials 122 Sample Exercises 122 11. Deployment Strategies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 Rolling Deployment Strategy 126 Implementation 126 Use Cases and Trade-Offs 128 Fixed Deployment Strategy 128 Implementation 129 Use Cases and Trade-Offs 130 Blue-Green Deployment Strategy 130 Implementation 131 Use Cases and Trade-Offs 133 Canary Deployment Strategy 133 Implementation 134 Use Cases and Trade-Offs 135 Summary 135 Exam Essentials 135 Sample Exercises 136 12. Helm. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139 Managing an Existing Chart 139 Identifying a Chart 140 Adding a Chart Repository 141 Searching for a Chart in a Repository 143 Installing a Chart 143 Listing Installed Charts 145 Upgrading an Installed Chart 145 Uninstalling a Chart 146 Table of Contents | ix
Page 12
Summary 146 Exam Essentials 146 Sample Exercises 147 Part IV. Application Observability and Maintenance 13. API Deprecations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151 Understanding the Deprecation Policy 151 Listing Available API Versions 152 Handling Deprecation Warnings 152 Handling a Removed or Replaced API 153 Summary 155 Exam Essentials 155 Sample Exercises 155 14. Container Probes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 157 Working with Probes 157 Probe Types 158 Health Verification Methods 159 Health Check Attributes 160 The Readiness Probe 160 The Liveness Probe 161 The Startup Probe 162 Summary 163 Exam Essentials 164 Sample Exercises 164 15. Troubleshooting Pods and Containers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165 Troubleshooting Pods 165 Retrieving High-Level Information 166 Inspecting Events 167 Using Port Forwarding 168 Troubleshooting Containers 169 Inspecting Logs 169 Opening an Interactive Shell 170 Interacting with a Distroless Container 171 Inspecting Resource Metrics 172 Summary 174 Exam Essentials 174 Sample Exercises 174 x | Table of Contents
Page 13
Part V. Application Environment, Configuration, and Security 16. CustomResourceDefinitions (CRDs). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179 Working with CRDs 179 Example CRD 180 Implementing a CRD Schema 181 Instantiating an Object for the CRD 182 Discovering CRDs 183 Implementing a Controller 184 Summary 184 Exam Essentials 185 Sample Exercises 185 17. Authentication, Authorization, and Admission Control. . . . . . . . . . . . . . . . . . . . . . . . . 187 Processing a Request 187 Authentication with kubectl 188 The Kubeconfig 188 Managing Kubeconfig Using kubectl 190 Authorization with Role-Based Access Control 191 RBAC Overview 191 Understanding RBAC API Primitives 192 Default User-Facing Roles 193 Creating Roles 193 Listing Roles 195 Rendering Role Details 195 Creating RoleBindings 195 Listing RoleBindings 196 Rendering RoleBinding Details 196 Seeing the RBAC Rules in Effect 197 Namespace-Wide and Cluster-Wide RBAC 198 Working with Service Accounts 198 The Default Service Account 199 Creating a Service Account 199 Setting Permissions for a Service Account 200 Admission Control 204 Summary 205 Exam Essentials 205 Sample Exercises 205 Table of Contents | xi
Page 14
18. Resource Requirements, Limits, and Quotas. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207 Working with Resource Requirements 208 Defining Container Resource Requests 208 Defining Container Resource Limits 209 Defining Container Resource Requests and Limits 210 Working with Resource Quotas 211 Creating ResourceQuotas 212 Rendering ResourceQuota Details 213 Exploring a ResourceQuota’s Runtime Behavior 213 Working with Limit Ranges 215 Creating LimitRanges 216 Rendering LimitRange Details 217 Exploring a LimitRange’s Runtime Behavior 217 Summary 219 Exam Essentials 220 Sample Exercises 220 19. ConfigMaps and Secrets. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223 Working with ConfigMaps 224 Creating a ConfigMap 224 Consuming a ConfigMap as Environment Variables 226 Mounting a ConfigMap as a Volume 226 Working with Secrets 228 Creating a Secret 229 Consuming a Secret as Environment Variables 232 Mounting a Secret as a Volume 233 Summary 235 Exam Essentials 235 Sample Exercises 236 20. Security Contexts. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237 Working with Security Contexts 238 Defining a Security Context on the Pod Level 239 Defining a Security Context on the Container Level 241 Defining a Security Context on the Pod and Container Level 242 Summary 243 Exam Essentials 244 Sample Exercises 244 xii | Table of Contents
Page 15
Part VI. Services and Networking 21. Services. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 247 Working with Services 248 Service Types 249 Port Mapping 250 Creating Services 251 Listing Services 253 Rendering Service Details 253 The ClusterIP Service Type 254 Creating and Inspecting the Service 255 Accessing the Service 256 The NodePort Service Type 258 Creating and Inspecting the Service 259 Accessing the Service 260 The LoadBalancer Service Type 260 Creating and Inspecting the Service 261 Accessing the Service 262 Summary 263 Exam Essentials 263 Sample Exercises 263 22. Ingresses. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 265 Working with Ingresses 266 Installing an Ingress Controller 266 Deploying Multiple Ingress Controllers 267 Configuring Ingress Rules 267 Creating Ingresses 268 Defining Path Types 269 Listing Ingresses 270 Rendering Ingress Details 270 Accessing an Ingress 272 Summary 273 Exam Essentials 273 Sample Exercises 273 23. Network Policies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275 Working with Network Policies 275 Installing an Network Policy Controller 276 Creating a Network Policy 276 Table of Contents | xiii
Page 16
Listing Network Policies 279 Rendering Network Policy Details 279 Applying Default Network Policies 280 Restricting Access to Specific Ports 282 Summary 283 Exam Essentials 283 Sample Exercises 283 A. Answers to Review Questions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285 B. Exam Review Guide. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339 xiv | Table of Contents
Page 17
Foreword The software development landscape is rapidly evolving, and cloud-native technolo‐ gies are at the forefront of this change. The Cloud Native Computing Foundation (CNCF) is one of the largest open source communities in the world with over 190 open source projects and has 200,000+ contributors worldwide improving the state of cloud native every day. From my experience as the cofounder and CTO, it can be fairly tricky to understand where you should begin to explore this vast cloud native landscape. This study guide prepares you well for the Certified Kubernetes Application Devel‐ oper (CKAD), which covers Kubernetes skills from the perspective of an application developer. In my opinion, having detailed examples is critical in passing the CKAD and this book has many of them. Ben covers all the topics required to successfully pass the certification and even lays some groundwork for future advanced certifica‐ tions like the Certified Kubernetes Security Specialist (CKS). What’s more, reading this book will give you the practice you need to become a more forward-thinking professional who embraces modern and open source development practices. Kubernetes is one project that is at the heart of the open source cloud native move‐ ment, enabling developers to build, deploy, and scale applications with agility. Kuber‐ netes certifications are incredibly popular with more than 100K+ registrations to date. We designed the CKAD certification to be focused on the application developer and provide a solid foundation for the fundamentals of Kubernetes and cloud native open source skills. Earning it validates your understanding of these critical technolo‐ gies, and signifies your commitment to continuous learning and staying ahead of the curve. Furthermore, the knowledge you gain here will empower you to effectively deploy and manage cloud native applications (a skill in high demand across various industries), help open doors to exciting career opportunities, and demonstrate your ability to thrive in the constant dynamic world of cloud native. xv
Page 18
I wish you luck in your cloud native career journey; and once you pass, come join us at the contribute.cncf.io community. — Chris Aniszczyk CTO and Cofounder, CNCF Austin, TX March 12, 2024 xvi | Foreword
Page 19
Preface Microservices architecture is one of the hottest areas of application development today, particularly for cloud-based, enterprise-scale applications. The benefits of building applications using small, single-purpose services are well documented. But managing what can be enormous numbers of containerized services is no easy task and requires the addition of an “orchestrator” to keep it all together. Kubernetes is among the most popular and broadly used tools for this job, so it’s no surprise that the ability to use, troubleshoot, and monitor Kubernetes as an application developer is in high demand. To provide job seekers and employers a standard means to demonstrate and evaluate proficiency in developing with a Kubernetes environment, the Cloud Native Computing Foundation (CNCF) developed the Certified Kuber‐ netes Application Developer (CKAD) program. To achieve this certification, you need to pass an exam. The CKAD is not to be confused with the Certified Kubernetes Administrator (CKA). While there is some topic overlap, the CKA focuses mostly on Kubernetes cluster administration tasks rather than developing applications operated in a cluster. In this study guide, I will explore the topics covered in the CKAD exam to fully pre‐ pare you to pass the certification exam. We’ll look at determining when and how you should apply the core concepts of Kubernetes to manage an application. We’ll also examine the kubectl command-line tool, a mainstay of the Kubernetes engineer. I will also offer tips to help you better prepare for the exam and share my personal experience with getting ready for all aspects of it. The CKAD is different from the typical multiple-choice format of other certifications. It’s completely performance based and requires you to demonstrate deep knowledge of the tasks at hand under immense time pressure. Are you ready to pass the test on the first go? xvii
Page 20
Who This Book Is For This book is for developers who want to prepare for the CKAD exam. The content covers all aspects of the exam curriculum, though basic knowledge of the Kubernetes architecture and its concepts is expected. If you are completely new to Kubernetes, I recommend that you first read Kubernetes: Up and Running by Brendan Burns, Joe Beda, Kelsey Hightower, and Lachlan Even‐ son (O’Reilly) or Kubernetes in Action by Marko Lukša (Manning Publications). What You Will Learn The content of the book condenses the most important aspects of the CKAD exam. Given the plethora of configuration options available in Kubernetes, it’s impossible to cover all use cases and scenarios without duplicating the official documentation. Test takers are encouraged to reference the Kubernetes documentation as the go-to com‐ pendium for broader exposure. The outline of the book follows the CKAD curriculum. While there might be a more natural, didactic structure for learning Kubernetes in general, the curriculum outline will help test takers prepare for the exam by focusing on specific topics. As a result, you will cross-reference other chapters of the book depending on your existing knowledge level. Be aware that this book covers only the concepts relevant to the CKAD exam. Refer to the Kubernetes documentation or other books if you want to dive deeper. Practical experience with Kubernetes is key to passing the exam. Each chapter con‐ tains a section named “Sample Exercises” with practice questions. Solutions to those questions can be found in Appendix A. What’s New in the Second Edition The CNCF periodically updates all Kubernetes certifications to keep up with the latest developments in the field. In September 2021, the CKAD curriculum received a major overhaul. The organization of existing topics has been changed, and new topics have been added, making the certification more relevant and applicable to Kubernetes practitioners in real-world scenarios. Compared to the first edition of the book, about 80% of the content hasn’t changed. The new curriculum includes the following topics: Deployment strategies The coverage of deployment strategies goes beyond the ones directly supported by the Deployment primitive. You will need to understand how to implement and manage blue/green deployments and canary deployments. xviii | Preface
The above is a preview of the first 20 pages. Register to read the complete e-book.

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
Back to List