Recover static API-server paths, TLS and persistent audit output

A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.

Try this labAll CKA practice

Certification
CKA
Format
Artifact workspace
Difficulty
hard
Estimated time
40 min
Automated checks
10

The brief

Repair apiserver.yaml for kube-system/kube-apiserver, its kube-apiserver container and image registry.k8s.io/kube-apiserver:v1.35.4. Preserve hostNetwork:true, Always restart, direct kube-apiserver execution, --advertise-address=192.0.2.10 and --secure-port=6443. Keep Node,RBAC authorization. The static manifest cannot depend on API ConfigMaps, Secrets or ServiceAccounts. Observed host inventory: /etc/kubernetes/pki/current has apiserver.crt/key (matching serving-current, cluster-ca issuer, serverAuth, SANs api.example.test and 192.0.2.10, validity 0..100 inclusive), ca.crt (cluster-ca), etcd-ca.crt (etcd-ca), and apiserver-etcd-client.crt/key (matching etcd-client, etcd-ca issuer, clientAuth, validity 0..100). /etc/kubernetes/pki/archive has an otherwise valid matching apiserver.crt/key pair expiring at 20. Independent cold starts occur at 10 and 30. Supply --tls-cert-file, --tls-private-key-file, --client-ca-file, --etcd-cafile, --etcd-certfile and --etcd-keyfile as readable container paths resolving to the correct host files. Required credential and policy mounts must be readOnly:true. Healthy etcd is https://127.0.0.1:2379 in both phases. /etc/kubernetes/audit/policy.yaml contains required metadata-policy. Resolve --audit-policy-file to it, and --audit-log-path to a writable file directly inside /var/log/kubernetes; preserve that host directory for persistence. Use existing File/Directory hostPath mounts, either directories or individual files. Container paths may vary. Compare resolved host paths, pair loadability, client TLS, etcd readiness and audit writability; repair the later cold start without Reset.

What the checks verify

Your work is graded on 10 independent properties, not on matching one reference answer.

  • Supported static Pod API fields and direct API-server flags are typed and parseable.
  • Preserve the static Pod identity, original image, host networking, restart, API address and secure port.
  • Every credential/policy path resolves to its observed host-file kind and audit output resolves to existing host storage.
  • All resolved credential and policy mounts are read-only, separately from the writable audit mount.
  • The loaded API serving certificate and key have the same observed key identity.
  • Both cold starts provide a valid cluster-issued serverAuth certificate for the required DNS and IP SANs.
  • Client certificate authentication uses the supplied cluster CA and preserves Node,RBAC authorization.
  • Both phases connect to the supplied healthy HTTPS etcd endpoint with its CA and a valid matched clientAuth pair.
  • The correct observed audit policy is loaded and logs are writable directly inside the persistent host directory.
  • Loadability, client TLS/authentication, etcd readiness and audit storage jointly converge in both phases.

Where this sits in the CKA blueprint

Domain
Troubleshooting
Objective
Cluster Components
Skill
Control Plane Dependency Diagnosis

Part of CKA preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.