Recover checkout endpoint selection
A hands-on CKA lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
- Certification
- CKA
- Format
- Artifact workspace
- Difficulty
- easy
- Estimated time
- 25 min
- Automated checks
- 8
The brief
Repair checkout.yaml: exactly checkout Deployment (apps/v1) and Service (v1), both explicitly in shop. Preserve two replicas, checkout container, registry.example/checkout:4 image, checkout-runtime service account, and template labels app=checkout,component=api,release=current; extra labels are allowed. The nonempty Deployment selector must match its template (matchLabels or matchExpressions). This reconstructed source is evaluated before application; changing an existing live Deployment selector requires replacement planning. Keep one internal, non-headless ClusterIP TCP port 80 targeting actual listener 8080, numerically or through a valid named container port. Select every intended Pod, including warming Pods, and no unrelated Pod. Route only to all ready intended Pods; do not publish unready addresses. Intended Pods inherit template labels plus observed track/state labels. Steady: api-a/api-b ready,track=stable,state=ready; api-warm unready,track=canary,state=warm. Replacement: api-b ready/stable, api-c ready/canary, api-warm2 unready/stable, with the same ready/warm state labels. Unrelated shop Pods: old-api (app=checkout,component=api,release=old,track=stable; ready; http=8090), diagnostic (app=checkout,component=diagnostic,release=current; unready; http=9000). Ready foreign-api in sandbox has the supplied identity labels and http=8080. Both stages must work. Listener ports and readiness are immutable observations. The model supports the supplied fields and selectors, not other Pod features or controller, probe, policy or packet execution. Inspect selected/eligible identities after each repair and recover without Reset.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- The artifact parses as bounded Kubernetes YAML without duplicate keys.
- Exactly the intended Deployment and Service retain their API versions and explicit namespace.
- Replica capacity, application image, service account and original Pod identity labels remain intact.
- The nonempty Deployment selector matches its own Pod template.
- The Service selects every intended Pod and no unrelated Pod across both inventories.
- Traffic endpoint eligibility exactly matches observed ready workload Pods in each stage.
- Every eligible backend resolves to its actual TCP application listener.
- One internal ClusterIP TCP port preserves the required client interface without external exposure.
Where this sits in the CKA blueprint
- Domain
- Workloads and Scheduling
- Objective
- Self Healing Workloads
- Skill
- Controllers, Health and Disruption
Part of CKA preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.