Week 2— Cluster Setup · Cluster Hardening
10 days- Study →
Cluster Setup
Cluster Setup is 15% of the CKS exam and covers hardening the Kubernetes control plane and worker nodes. You will perform live tasks in a terminal: applying NetworkPolicies, configuring API server admission controls, securing Ingress, and running kube-bench or CIS benchmark checks. Expect hands-on editing of manifests and verifying behaviour with kubectl rather than multiple-choice recall.
📅 Days 10–14🎯 ~2 questions/day⚖ 15% of exam- ✓Creating NetworkPolicy objects to restrict pod ingress and egress by namespace, label, and port
- ✓Enabling and configuring admission controllers such as NodeRestriction and PodSecurity admission on the API server
- ✓Hardening Ingress with TLS, and restricting access using NetworkPolicy or Ingress annotations
- Study →
Cluster Hardening
Cluster Hardening covers the controls that keep a Kubernetes cluster's own components and API surface resistant to compromise. For the CKS exam you work hands-on inside a live cluster: restricting API access, tightening RBAC, protecting kubelet endpoints, and upgrading components safely. Tasks are performance-based, so you must know the exact kubectl, kubeadm and systemd commands and apply them under time pressure.
📅 Days 10–14🎯 ~1 questions/day⚖ 15% of exam- ✓Minimising RBAC permissions by removing wildcards, cluster-admin bindings and unnecessary default ServiceAccount rights
- ✓Securing the kubelet API with authentication, authorization and read-only port disabled via kubelet config
- ✓Restricting API server access using anonymous-auth, authorization modes and network exposure controls