CKAD, CKA and CKS exam blueprints, mapped to lessons
Every competency of the three Kubernetes certifications (Kubernetes v1.35), and the interactive lesson that teaches it.
Certified Kubernetes Application Developer (CKAD)
Build, configure and expose applications.
Application Design and Build · 20%
- Define, build and modify container images: Container Images
- Choose and use the right workload resource (Deployment, DaemonSet, CronJob, etc.): Pods, Choosing a Workload
- Understand multi-container Pod design patterns (e.g. sidecar, init and others): Multi-container Pods
- Utilize persistent and ephemeral volumes: Multi-container Pods, Storage
Application Deployment · 20%
- Use Kubernetes primitives to implement common deployment strategies (e.g. blue/green or canary): Blue/Green & Canary
- Understand Deployments and how to perform rolling updates: Deployments & Rollouts
- Use the Helm package manager to deploy existing packages: Helm & Kustomize
- Kustomize: Helm & Kustomize
Application Observability and Maintenance · 15%
- Understand API deprecations: CRDs, Operators & API Versions
- Implement probes and health checks: Probes & Health Checks
- Use built-in CLI tools to monitor Kubernetes applications: Logs & Debugging
- Utilize container logs: Logs & Debugging
- Debugging in Kubernetes: Logs & Debugging
Application Environment, Configuration and Security · 25%
- Discover and use resources that extend Kubernetes (CRD, Operators): CRDs, Operators & API Versions
- Understand authentication, authorization and admission control: SecurityContext & ServiceAccounts
- Understand requests, limits, quotas: Requests, Limits & Quotas
- Understand ConfigMaps: ConfigMaps & Secrets
- Define resource requirements: Requests, Limits & Quotas
- Create & consume Secrets: ConfigMaps & Secrets
- Understand ServiceAccounts: SecurityContext & ServiceAccounts
- Understand Application Security (SecurityContexts, Capabilities, etc.): SecurityContext & ServiceAccounts
Services and Networking · 20%
- Demonstrate basic understanding of NetworkPolicies: NetworkPolicies
- Provide and troubleshoot access to applications via services: Services & DNS
- Use Ingress rules to expose applications: Ingress
Certified Kubernetes Administrator (CKA)
Install, operate and repair clusters.
Cluster Architecture, Installation & Configuration · 25%
- Manage role based access control (RBAC): RBAC
- Prepare underlying infrastructure for installing a Kubernetes cluster: kubeadm: Install & Upgrade
- Create and manage Kubernetes clusters using kubeadm: kubeadm: Install & Upgrade
- Manage the lifecycle of Kubernetes clusters: kubeadm: Install & Upgrade
- Implement and configure a highly-available control plane: HA Control Plane & etcd
- Use Helm and Kustomize to install cluster components: Helm & Kustomize
- Understand extension interfaces (CNI, CSI, CRI, etc.): Cluster Architecture
- Understand CRDs, install and configure operators: CRDs, Operators & API Versions
Workloads & Scheduling · 15%
- Understand application deployments and rolling updates/rollbacks: Deployments & Rollouts
- Use ConfigMaps and Secrets to configure applications: ConfigMaps & Secrets
- Configure workload autoscaling: Autoscaling & Self-healing
- Understand primitives for robust, self-healing deployments: Autoscaling & Self-healing
- Configure Pod admission and scheduling (limits, node affinity, etc.): Scheduling
Services & Networking · 20%
- Understand connectivity between Pods: Pod Networking & CoreDNS
- Define and enforce Network Policies: NetworkPolicies
- Use ClusterIP, NodePort, LoadBalancer service types and endpoints: Pod Networking & CoreDNS
- Use the Gateway API to manage Ingress traffic: Gateway API
- Know how to use Ingress controllers and Ingress resources: Ingress
- Understand and use CoreDNS: Pod Networking & CoreDNS
Storage · 10%
- Implement storage classes and dynamic volume provisioning: Storage
- Configure volume types, access modes and reclaim policies: Storage
- Manage persistent volumes and persistent volume claims: Storage
Troubleshooting · 30%
- Troubleshoot clusters and nodes: Troubleshooting the Cluster
- Troubleshoot cluster components: Troubleshooting the Cluster
- Monitor cluster and application resource usage: Troubleshooting Workloads
- Manage and evaluate container output streams: Troubleshooting Workloads
- Troubleshoot services and networking: Troubleshooting Networking
Certified Kubernetes Security Specialist (CKS)
Harden clusters, workloads and the supply chain.
Cluster Setup · 15%
- Use Network security policies to restrict cluster level access: Network Lockdown
- Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi): CIS Benchmarks & API Hardening
- Properly set up Ingress with TLS: Network Lockdown
- Protect node metadata and endpoints: Network Lockdown
- Verify platform binaries before deploying: CIS Benchmarks & API Hardening
Cluster Hardening · 15%
- Use Role Based Access Controls to minimize exposure: Least Privilege
- Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones: Least Privilege
- Restrict access to Kubernetes API: CIS Benchmarks & API Hardening
- Upgrade Kubernetes to avoid vulnerabilities: CIS Benchmarks & API Hardening
System Hardening · 10%
- Minimize host OS footprint (reduce attack surface): Kernel & Host Hardening
- Using least-privilege identity and access management: Least Privilege
- Minimize external access to the network: Network Lockdown
- Appropriately use kernel hardening tools such as AppArmor, seccomp: Kernel & Host Hardening
Minimize Microservice Vulnerabilities · 20%
- Use appropriate pod security standards: Pod Security Standards
- Manage Kubernetes secrets: Secrets, Sandboxes & mTLS
- Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.): Secrets, Sandboxes & mTLS
- Implement Pod-to-Pod encryption (Cilium, Istio): Secrets, Sandboxes & mTLS
Supply Chain Security · 20%
- Minimize base image footprint: Image Footprint & Scanning
- Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories): Image Footprint & Scanning
- Secure your supply chain (permitted registries, sign and validate artifacts, etc.): Signed Images & Trusted Registries
- Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter): Image Footprint & Scanning
Monitoring, Logging and Runtime Security · 20%
- Perform behavioral analytics to detect malicious activities: Runtime Security with Falco
- Detect threats within physical infrastructure, apps, networks, data, users and workloads: Runtime Security with Falco
- Investigate and identify phases of attack and bad actors within the environment: Audit Logs & Investigation
- Ensure immutability of containers at runtime: Runtime Security with Falco
- Use Kubernetes audit logs to monitor access: Audit Logs & Investigation