Recover namespace-aware discovery and resilient corporate DNS
A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- hard
- Estimated time
- 40 min
- Automated checks
- 10
The brief
Repair dns.yaml: preserve reports/reporter, hostNetwork:true, reporter image example.invalid/reporter:2 and Always restart policy. Keep PAYMENTS_HOST wired to reports/dns-app's PAYMENTS_HOST key and Corefile in kube-system/coredns. Host resolver 198.51.100.53 cannot serve cluster names; reachable cluster resolver is 10.96.0.10. Use ClusterFirstWithHostNet or None with explicit resolver/search configuration. Namespace search defaults are reports.svc.cluster.local, svc.cluster.local, cluster.local; ClusterFirst on this host-network Pod falls back to host DNS. The supported probe uses ndots/search order; use-vc selects TCP. PAYMENTS_HOST must discover finance/payments, not the reports/payments decoy. Preserve short-name inventory in reports and kubernetes.default discovery. Service A records have normal→maintenance addresses: finance/payments 10.96.20.40→10.96.20.41; reports/payments 10.96.30.90; reports/inventory 10.96.30.50→10.96.30.51; default/kubernetes 10.96.0.1. Never pin these addresses in application settings. Serve cluster.local authoritatively, including NXDOMAIN for unallocated names; never forward cluster queries outside or back into the cluster resolver. api.corp.example must use 192.0.2.53 (answer 192.0.2.80). Its UDP path works normally but fails in maintenance; TCP works in both. status.public.example must use 198.51.100.53 (answer 203.0.113.80), both transports available. Use appropriate zone or ordered forward rules, preserving public DNS. Run tests, compare resolver/query/forwarding witnesses, and repair both phases without Reset.
What the checks verify
Your work is graded on 10 independent properties, not on matching one reference answer.
- Supported typed Pod, ConfigMap and Corefile fields parse without hidden coercion.
- Preserve the reporting Pod, host-network/image/restart contract and required ConfigMap identities and reference.
- The derived Pod resolver set contains exactly the supplied cluster resolver, excluding node/external DNS.
- Each independently observed Service A record is answered by Kubernetes cluster-zone authority.
- The application discovers finance/payments rather than the reports/payments decoy in both phases.
- The same resolver discovers local inventory and kubernetes.default in both phases.
- Corporate lookup reaches its supplied corporate upstream and answer in the normal phase.
- Corporate lookup still succeeds when its UDP upstream path is unavailable and TCP remains available.
- Public status lookup retains the general upstream's expected answer in both phases.
- Cluster-zone queries including absent names never leave Kubernetes authority, and no observed forwarding loops exist.
Where this sits in the CKA blueprint
- Domain
- Services and Networking
- Objective
- CoreDNS
- Skill
- Service Discovery and DNS Paths
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.