Preserve a base through Kustomize overlay and generated-reference transforms

A hands-on CKA lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll CKA practice

Certification
CKA
Format
Artifact workspace
Difficulty
hard
Estimated time
35 min
Automated checks
9

The brief

Repair kustomization.yaml using immutable reporter-base@1 at local path base. the original apps/v1 Deployment reporter has namespace base, one replica, image example.invalid/reporter:1.0, Pod label app:reporter and matching selector. Its container envFrom references report-settings. The original v1 ClusterIP Service reporter also selects app:reporter and retains TCP8080 to TCP8080. Compose resources:[base]; do not rewrite the base. Put every rendered resource in analytics. Isolate this instance using either namePrefix:blue- with no suffix, or nameSuffix:-blue with no prefix. Images and replicas match original identities: use images name:example.invalid/reporter with newTag:'2.4', or digest:sha256:ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff; replicas name:reporter must preserve two to five Pods. An unmatched image leaves the old image; an unmatched replica workload target blocks rendering. Add labels pairs:{environment:blue} to all resource metadata and the Pod template. includeTemplates:true propagates only to templates as well as metadata; includeSelectors:true also updates the Deployment and Service selectors and implies template propagation. Preserve app:reporter in Pods and selectors. Metadata-only labels do not place the label on Pods. Either propagation strategy is valid. Generate report-settings from literals TENANT=analytics and MODE=live. Built-in name references must rewrite envFrom to the transformed, hashed ConfigMap in the same namespace. Keep the automatic name suffix hash enabled: a controlled MODE literal edit must change the generated name and Pod template reference. A stable reference can consume correct current data while failing that revision safeguard. Only these built-in fields are supported; no remote resources, patches, plugins, files/env generators or Helm inflation. Inspect rendered names, label scopes, consumed map and changed-data reference witnesses; repair a newly visible mistake without Reset.

What the checks verify

Your work is graded on 9 independent properties, not on matching one reference answer.

  • The artifact uses the selected typed local Kustomization transformations and supported literal generator.
  • The rendered graph contains the original Deployment and Service from the immutable local base.
  • Every rendered resource occupies the intended analytics namespace.
  • The original base and generated resources use a consistent allowed blue-prefix or blue-suffix instance scope.
  • The image transformer matches the original repository and renders the independently accepted tag or digest identity.
  • The replica transformer matches the original Deployment and preserves at least two desired replicas.
  • Resource metadata and Pod template carry the intended overlay label while the original app selector identity remains consistent.
  • The actual envFrom reference resolves the generated same-namespace TENANT=analytics/MODE=live map after name transformations.
  • A controlled literal edit changes the generated ConfigMap name and actual Pod template reference.

Where this sits in the CKA blueprint

Domain
Cluster Architecture, Installation and Configuration
Objective
Helm and Kustomize
Skill
Rendering and Release Configuration

Part of CKA preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.