Recover static API-server paths, TLS and persistent audit output
A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- hard
- Estimated time
- 40 min
- Automated checks
- 10
The brief
Repair apiserver.yaml for kube-system/kube-apiserver, its kube-apiserver container and image registry.k8s.io/kube-apiserver:v1.35.4. Preserve hostNetwork:true, Always restart, direct kube-apiserver execution, --advertise-address=192.0.2.10 and --secure-port=6443. Keep Node,RBAC authorization. The static manifest cannot depend on API ConfigMaps, Secrets or ServiceAccounts. Observed host inventory: /etc/kubernetes/pki/current has apiserver.crt/key (matching serving-current, cluster-ca issuer, serverAuth, SANs api.example.test and 192.0.2.10, validity 0..100 inclusive), ca.crt (cluster-ca), etcd-ca.crt (etcd-ca), and apiserver-etcd-client.crt/key (matching etcd-client, etcd-ca issuer, clientAuth, validity 0..100). /etc/kubernetes/pki/archive has an otherwise valid matching apiserver.crt/key pair expiring at 20. Independent cold starts occur at 10 and 30. Supply --tls-cert-file, --tls-private-key-file, --client-ca-file, --etcd-cafile, --etcd-certfile and --etcd-keyfile as readable container paths resolving to the correct host files. Required credential and policy mounts must be readOnly:true. Healthy etcd is https://127.0.0.1:2379 in both phases. /etc/kubernetes/audit/policy.yaml contains required metadata-policy. Resolve --audit-policy-file to it, and --audit-log-path to a writable file directly inside /var/log/kubernetes; preserve that host directory for persistence. Use existing File/Directory hostPath mounts, either directories or individual files. Container paths may vary. Compare resolved host paths, pair loadability, client TLS, etcd readiness and audit writability; repair the later cold start without Reset.
What the checks verify
Your work is graded on 10 independent properties, not on matching one reference answer.
- Supported static Pod API fields and direct API-server flags are typed and parseable.
- Preserve the static Pod identity, original image, host networking, restart, API address and secure port.
- Every credential/policy path resolves to its observed host-file kind and audit output resolves to existing host storage.
- All resolved credential and policy mounts are read-only, separately from the writable audit mount.
- The loaded API serving certificate and key have the same observed key identity.
- Both cold starts provide a valid cluster-issued serverAuth certificate for the required DNS and IP SANs.
- Client certificate authentication uses the supplied cluster CA and preserves Node,RBAC authorization.
- Both phases connect to the supplied healthy HTTPS etcd endpoint with its CA and a valid matched clientAuth pair.
- The correct observed audit policy is loaded and logs are writable directly inside the persistent host directory.
- Loadability, client TLS/authentication, etcd readiness and audit storage jointly converge in both phases.
Where this sits in the CKA blueprint
- Domain
- Troubleshooting
- Objective
- Cluster Components
- Skill
- Control Plane Dependency Diagnosis
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.