Preserve a base through Kustomize overlay and generated-reference transforms
A hands-on CKA lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 9
The brief
Repair kustomization.yaml using immutable reporter-base@1 at local path base. the original apps/v1 Deployment reporter has namespace base, one replica, image example.invalid/reporter:1.0, Pod label app:reporter and matching selector. Its container envFrom references report-settings. The original v1 ClusterIP Service reporter also selects app:reporter and retains TCP8080 to TCP8080. Compose resources:[base]; do not rewrite the base. Put every rendered resource in analytics. Isolate this instance using either namePrefix:blue- with no suffix, or nameSuffix:-blue with no prefix. Images and replicas match original identities: use images name:example.invalid/reporter with newTag:'2.4', or digest:sha256:ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff; replicas name:reporter must preserve two to five Pods. An unmatched image leaves the old image; an unmatched replica workload target blocks rendering. Add labels pairs:{environment:blue} to all resource metadata and the Pod template. includeTemplates:true propagates only to templates as well as metadata; includeSelectors:true also updates the Deployment and Service selectors and implies template propagation. Preserve app:reporter in Pods and selectors. Metadata-only labels do not place the label on Pods. Either propagation strategy is valid. Generate report-settings from literals TENANT=analytics and MODE=live. Built-in name references must rewrite envFrom to the transformed, hashed ConfigMap in the same namespace. Keep the automatic name suffix hash enabled: a controlled MODE literal edit must change the generated name and Pod template reference. A stable reference can consume correct current data while failing that revision safeguard. Only these built-in fields are supported; no remote resources, patches, plugins, files/env generators or Helm inflation. Inspect rendered names, label scopes, consumed map and changed-data reference witnesses; repair a newly visible mistake without Reset.
What the checks verify
Your work is graded on 9 independent properties, not on matching one reference answer.
- The artifact uses the selected typed local Kustomization transformations and supported literal generator.
- The rendered graph contains the original Deployment and Service from the immutable local base.
- Every rendered resource occupies the intended analytics namespace.
- The original base and generated resources use a consistent allowed blue-prefix or blue-suffix instance scope.
- The image transformer matches the original repository and renders the independently accepted tag or digest identity.
- The replica transformer matches the original Deployment and preserves at least two desired replicas.
- Resource metadata and Pod template carry the intended overlay label while the original app selector identity remains consistent.
- The actual envFrom reference resolves the generated same-namespace TENANT=analytics/MODE=live map after name transformations.
- A controlled literal edit changes the generated ConfigMap name and actual Pod template reference.
Where this sits in the CKA blueprint
- Domain
- Cluster Architecture, Installation and Configuration
- Objective
- Helm and Kustomize
- Skill
- Rendering and Release Configuration
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.