Sequence a kubeadm upgrade without losing the replica floor
A hands-on CKA lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Structured configuration
- Difficulty
- medium
- Estimated time
- 40 min
- Automated checks
- 10
The brief
Repair upgrade.json: steps is an ordered array of {host,command} records, at most 80. Hosts are cp-a and worker-a/b/c. All kubeadm/kubelet/kubectl packages start held at 1.34.7. Install only approved pins NAME=1.35.4-1.1. Review the primary target upgrade plan before first apply; use upgrade node for workers after the API upgrade. Configure and complete drain of each node before its kubelet minor package change. Use daemon-reload then restart, observe target health before uncordon, restore all package holds, and finish with kubectl get nodes after all target packages/config/running kubelets, four Ready replicas and scheduling are restored. Every command must succeed; do not bypass the PDB. No transition may drop below three Ready replicas. Package preparation may be staged or just in time; worker order is free when safe. Commands are inert. Supported forms, optionally prefixed sudo: apt-mark hold|unhold PACKAGE...; apt-get update; apt-get install -y PIN...; kubeadm version; kubeadm upgrade plan|node; kubeadm upgrade apply v1.35.4; kubectl drain NODE --ignore-daemonsets (also parses --disable-eviction to expose its violation); kubectl uncordon NODE; kubectl wait --for=condition=Ready node/NODE --timeout=120s; kubectl get nodes; systemctl daemon-reload; systemctl restart|status kubelet. One command per record, no shell chaining. This fixture reschedules evicted replicas immediately into free Ready uncordoned slots, sampling each eviction first. Matched target config/package restart immediately succeeds; wait or supplied successful status records confirmed target health. Status alone does not prove Ready on a real cluster. Static control-plane Pods are outside ordinary drain; kubelet restart does not stop the API. Repositories and credentials are prepared; HA, etcd and runtime timing are excluded. Inspect node versions, replica counts and failed transition evidence, then repair without Reset.
What the checks verify
Your work is graded on 10 independent properties, not on matching one reference answer.
- The inert runbook has valid supplied host identities and supported single-command syntax.
- The primary target plan is successfully reviewed before first apply.
- The API target precedes worker target configuration, which precedes kubelet target installation.
- All pins use the approved target/revision and no running kubelet leads the API minor.
- Drain completes before kubelet change/restart; reload and observed target health precede return.
- All voluntary ordinary workload disruptions use eviction without bypassing the PDB.
- At least three replicas remain Ready at every sampled transition.
- Every supplied Kubernetes package is held again when maintenance ends.
- Every recognized command succeeds in the supplied inventory.
- All target packages/configuration/running kubelets, scheduling and four Ready replicas are restored and finally inspected.
Where this sits in the CKA blueprint
- Domain
- Cluster Architecture, Installation and Configuration
- Objective
- Cluster Lifecycle Management
- Skill
- Upgrade, Drain and Recovery
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.