Attach orders routes without broadening namespace or request access

A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.

Try this labAll CKA practice

Certification
CKA
Format
Artifact workspace
Difficulty
hard
Estimated time
45 min
Automated checks
10

The brief

Repair gateway.yaml using Gateway, HTTPRoute and ReferenceGrant v1 objects from the supplied v1.6.2 Standard bundle. Preserve net/edge, class supplied-http, HTTP listeners web:8080/api.example.test and admin:8081/admin.example.test. The observed class is available and supports Extended method matching and optional parent-port selection. Own one or more shop HTTPRoutes; attach them only to web. web must permit HTTPRoutes from shop only; admin remains same-namespace net only. Namespace labels include kubernetes.io/metadata.name=name; shop/archive have owner=commerce and net/backend owner=platform. Selectors must stay scoped even for another namespace with otherwise matching labels. Use Service backend/orders port 8080, response orders-current. backend also holds admin:9000/private-admin and old-orders:8080/orders-obsolete. A backend port is a Service port. Place the needed ReferenceGrant in backend, allowing only gateway.networking.k8s.io HTTPRoutes from shop to the core Service named orders. Other source kinds/namespaces, target objects and unnamed all-Service grants violate the boundary. Required requests to web/api.example.test carry x-tenant:shop: GET /orders, /orders/42 and /orders/42/lines; HEAD /orders and /orders/42. Every positive-weight outcome must deliver orders-current from the required Service/port. Do not forward POST /orders, GET /orders-debug, GET /admin, GET /orders with missing or x-tenant:platform, GET /orders on evil.example.test, or GET /orders through admin:8081/admin.example.test. PathPrefix matches path elements; method/header/path combine by AND and matches by OR. Run tests, inspect attachment/reference/request witnesses and repair saved mistakes without Reset.

What the checks verify

Your work is graded on 10 independent properties, not on matching one reference answer.

  • Selected v1.6.2 standard Gateway, HTTPRoute and ReferenceGrant API fields are well formed.
  • Preserve the supplied Gateway identity, class, two named HTTP listener ports and hostnames.
  • Keep learner-owned HTTPRoutes within the original shop namespace.
  • Listener route admission permits exactly shop on web and net on admin, with no symbolic other-namespace grant.
  • Every authored route attaches only to web through valid parent, namespace, kind and hostname intersection.
  • Every named backend, including zero-weight references, resolves through valid namespace grants and observed Service ports.
  • Every grant is in backend and permits only shop HTTPRoutes to the named core orders Service.
  • All required GET paths and tenant headers deliver the current orders response from the required Service/port.
  • Both required HEAD paths and tenant headers deliver the current orders response from the required Service/port.
  • Forbidden methods, sibling/admin paths, tenants, hosts and admin-listener requests never forward to a backend.

Where this sits in the CKA blueprint

Domain
Services and Networking
Objective
Gateway API
Skill
Route Attachment and Backend Access

Part of CKA preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.