Attach orders routes without broadening namespace or request access
A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- hard
- Estimated time
- 45 min
- Automated checks
- 10
The brief
Repair gateway.yaml using Gateway, HTTPRoute and ReferenceGrant v1 objects from the supplied v1.6.2 Standard bundle. Preserve net/edge, class supplied-http, HTTP listeners web:8080/api.example.test and admin:8081/admin.example.test. The observed class is available and supports Extended method matching and optional parent-port selection. Own one or more shop HTTPRoutes; attach them only to web. web must permit HTTPRoutes from shop only; admin remains same-namespace net only. Namespace labels include kubernetes.io/metadata.name=name; shop/archive have owner=commerce and net/backend owner=platform. Selectors must stay scoped even for another namespace with otherwise matching labels. Use Service backend/orders port 8080, response orders-current. backend also holds admin:9000/private-admin and old-orders:8080/orders-obsolete. A backend port is a Service port. Place the needed ReferenceGrant in backend, allowing only gateway.networking.k8s.io HTTPRoutes from shop to the core Service named orders. Other source kinds/namespaces, target objects and unnamed all-Service grants violate the boundary. Required requests to web/api.example.test carry x-tenant:shop: GET /orders, /orders/42 and /orders/42/lines; HEAD /orders and /orders/42. Every positive-weight outcome must deliver orders-current from the required Service/port. Do not forward POST /orders, GET /orders-debug, GET /admin, GET /orders with missing or x-tenant:platform, GET /orders on evil.example.test, or GET /orders through admin:8081/admin.example.test. PathPrefix matches path elements; method/header/path combine by AND and matches by OR. Run tests, inspect attachment/reference/request witnesses and repair saved mistakes without Reset.
What the checks verify
Your work is graded on 10 independent properties, not on matching one reference answer.
- Selected v1.6.2 standard Gateway, HTTPRoute and ReferenceGrant API fields are well formed.
- Preserve the supplied Gateway identity, class, two named HTTP listener ports and hostnames.
- Keep learner-owned HTTPRoutes within the original shop namespace.
- Listener route admission permits exactly shop on web and net on admin, with no symbolic other-namespace grant.
- Every authored route attaches only to web through valid parent, namespace, kind and hostname intersection.
- Every named backend, including zero-weight references, resolves through valid namespace grants and observed Service ports.
- Every grant is in backend and permits only shop HTTPRoutes to the named core orders Service.
- All required GET paths and tenant headers deliver the current orders response from the required Service/port.
- Both required HEAD paths and tenant headers deliver the current orders response from the required Service/port.
- Forbidden methods, sibling/admin paths, tenants, hosts and admin-listener requests never forward to a backend.
Where this sits in the CKA blueprint
- Domain
- Services and Networking
- Objective
- Gateway API
- Skill
- Route Attachment and Backend Access
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.