Recover a selectorless Service's external EndpointSlice port path
A hands-on CKA lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 8
The brief
Repair external.yaml: preserve integrations/ledger, selectorless ClusterIP 10.96.0.60, entry port 443 named https with TCP, Cluster internal traffic policy and no session affinity. The manual EndpointSlices are discovery.k8s.io/v1, addressType IPv4, in integrations. Associate each intended Slice with kubernetes.io/service-name: ledger. Slice object names and managed-by labels do not select the Service. Name/protocol must match the Service port, and numeric Slice ports drive the external destination; editing Service targetPort alone cannot repair a Slice's wrong port. Required current backends: current-a 192.0.2.20 and current-b 192.0.2.21. Both are independently observed TCP listeners on 8443 in normal and maintenance. A also serves TCP443 in both phases; B serves TCP443 normally but loses it in maintenance. Every eligible destination must stay usable; keep both current identities covered. Either one shared 8443 Slice or separate A443/B8443 Slices can express a valid strategy. Endpoint ready:false removes that destination; marking a failed listener ready:true cannot make it usable. Duplicate network endpoints must deduplicate. Retired 192.0.2.22 still serves TCP8443; private 192.0.2.23 serves TCP9443. Neither may receive this Service's traffic. No unobserved address or Service VIP may substitute for a backend; other Service VIPs include 10.96.0.1 and 10.96.0.80. Loopback/link-local endpoints are invalid. Compare associated Slices, matched ports and each actual destination outcome. Repair the newly visible maintenance failure without Reset, preserving the two intended backends.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- Supported Service and EndpointSlice fields parse with real API types and valid unicast endpoint addresses.
- Preserve the selectorless original ClusterIP entry point, named TCP port and disclosed Cluster/no-affinity policy.
- Every intended Slice is in the Service namespace and carries the actual service-name association label.
- Each associated Slice provides a numeric port matching the Service port's name and protocol.
- The aggregated ready destinations preserve both original current external backend identities.
- Every eligible normal-phase network destination has the actual independently observed available listener.
- Every eligible destination remains usable after B's independent TCP443 listener loss.
- Eligible destinations contain only intended current backends, excluding retired/private/unobserved or Service VIP substitutes.
Where this sits in the CKA blueprint
- Domain
- Troubleshooting
- Objective
- Services and Network Diagnosis
- Skill
- Traffic Path and DNS Diagnosis
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.