learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

kubeadm: Install & Upgrade (CKA)

Bootstrap a cluster, join nodes, and upgrade it one minor version at a time.

An interactive Kubernetes lesson: 24 steps, about 35 minutes, on a live simulation in your browser.

The shop is moving off a managed service. You have been given three fresh Linux machines, cp-1, node-a and node-b, and one task: turn them into a Kubernetes cluster running v1.34, then take it to v1.35.

The stage shows the first machine, cp-1. Every control-plane box is dark. There is no API server, so there is nothing for kubectl to talk to.

What you will learn

  1. Prepare the machines

    • Three empty machines: kubeadm bootstraps Kubernetes on machines you have prepared. The machine, the runtime and the network plugin are your job.
    • Prepare the operating system
    • Install a container runtime: The kubelet and the container runtime must use the same cgroup driver. On a systemd machine, that driver is systemd.
    • Install kubeadm, kubelet, kubectl
  2. kubeadm init

    • kubeadm init: kubeadm init is a list of phases: certificates, kubeconfigs, static pod manifests, start the kubelet, then a token so others can join.
    • What init left on disk
    • Tell kubectl where the cluster is
    • Why is the node NotReady?: A kubeadm cluster is not finished until a CNI plugin is installed. NotReady plus Pending CoreDNS right after init means: install the network.
  3. Join the workers

    • Join a worker: The token proves the node to the cluster. The CA hash proves the cluster to the node. After the join, neither is needed again.
    • Yesterday's token
    • The cluster does its job
  4. Upgrade, one minor at a time

    • Plan the upgrade: Upgrade order never changes: one minor at a time, control plane before workers, kubeadm before kubelet.
    • Upgrade the control plane
    • What version is cp-1 now?: kubeadm upgrades the control-plane pods. The kubelet is a package on each machine, upgraded by you, and it is what VERSION shows.
    • Mixed versions on purpose: Nothing may be newer than the API server. The kubelet may lag it by up to three minors; kubectl may be one either side.
    • Drain a worker: drain = cordon + evict. The node stays in the cluster, empty and unschedulable, until you uncordon it.
    • Upgrade the worker's kubelet
    • Break it: the forgotten uncordon
    • Finish the upgrade
  5. Certificates & drills

    • Break it: a year without an upgrade
    • Drill: a fresh join command
    • Drill: empty a node safely
  6. Recap & playground

    • Cheat sheet
    • Playground