Recover namespace-aware discovery and resilient corporate DNS

A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.

Try this labAll CKA practice

Certification
CKA
Format
Artifact workspace
Difficulty
hard
Estimated time
40 min
Automated checks
10

The brief

Repair dns.yaml: preserve reports/reporter, hostNetwork:true, reporter image example.invalid/reporter:2 and Always restart policy. Keep PAYMENTS_HOST wired to reports/dns-app's PAYMENTS_HOST key and Corefile in kube-system/coredns. Host resolver 198.51.100.53 cannot serve cluster names; reachable cluster resolver is 10.96.0.10. Use ClusterFirstWithHostNet or None with explicit resolver/search configuration. Namespace search defaults are reports.svc.cluster.local, svc.cluster.local, cluster.local; ClusterFirst on this host-network Pod falls back to host DNS. The supported probe uses ndots/search order; use-vc selects TCP. PAYMENTS_HOST must discover finance/payments, not the reports/payments decoy. Preserve short-name inventory in reports and kubernetes.default discovery. Service A records have normal→maintenance addresses: finance/payments 10.96.20.40→10.96.20.41; reports/payments 10.96.30.90; reports/inventory 10.96.30.50→10.96.30.51; default/kubernetes 10.96.0.1. Never pin these addresses in application settings. Serve cluster.local authoritatively, including NXDOMAIN for unallocated names; never forward cluster queries outside or back into the cluster resolver. api.corp.example must use 192.0.2.53 (answer 192.0.2.80). Its UDP path works normally but fails in maintenance; TCP works in both. status.public.example must use 198.51.100.53 (answer 203.0.113.80), both transports available. Use appropriate zone or ordered forward rules, preserving public DNS. Run tests, compare resolver/query/forwarding witnesses, and repair both phases without Reset.

What the checks verify

Your work is graded on 10 independent properties, not on matching one reference answer.

  • Supported typed Pod, ConfigMap and Corefile fields parse without hidden coercion.
  • Preserve the reporting Pod, host-network/image/restart contract and required ConfigMap identities and reference.
  • The derived Pod resolver set contains exactly the supplied cluster resolver, excluding node/external DNS.
  • Each independently observed Service A record is answered by Kubernetes cluster-zone authority.
  • The application discovers finance/payments rather than the reports/payments decoy in both phases.
  • The same resolver discovers local inventory and kubernetes.default in both phases.
  • Corporate lookup reaches its supplied corporate upstream and answer in the normal phase.
  • Corporate lookup still succeeds when its UDP upstream path is unavailable and TCP remains available.
  • Public status lookup retains the general upstream's expected answer in both phases.
  • Cluster-zone queries including absent names never leave Kubernetes authority, and no observed forwarding loops exist.

Where this sits in the CKA blueprint

Domain
Services and Networking
Objective
CoreDNS
Skill
Service Discovery and DNS Paths

Part of CKA preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.