CKA Practice Question: Cluster Architecture, Installation & Configuration
A cluster administrator notices that nodes are not joining the cluster after a kubeadm init. The kubelet logs show: 'failed to run Kubelet: could not init service: open /var/lib/kubelet/config.yaml: permission denied'. What is the most likely cause?
⚠ Common exam trap
Many exam-takers confuse 'permission denied' with network connectivity issues or resource exhaustion, but the specific file path in the error message directly points to a filesystem permission problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The kubelet configuration file has incorrect ownership or permissions.
The error message 'open /var/lib/kubelet/config.yaml: permission denied' indicates that the kubelet process does not have the necessary read permissions to access its configuration file. This is typically caused by incorrect file ownership (e.g., owned by root instead of the kubelet user) or restrictive file permissions (e.g., 600 instead of 644). Since kubelet runs as a systemd service, it requires appropriate access to this file to initialize properly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The kubelet is running out of disk space.
Why it's wrong here
If the host runs out of disk space, the kubelet will typically trigger disk pressure taints or fail during write-heavy operations like container image pulling and logging. It would not produce a filesystem 'permission denied' error during the initial read of its static configuration files.
- ✗
The kubelet is not able to reach the API server.
Why it's wrong here
A failure to reach the Kubernetes API server due to network partitions, incorrect API endpoints, or firewall rules results in connection timeouts, 'connection refused' errors, or TLS handshake failures. It does not manifest as a local filesystem permission denied error when the kubelet process starts.
- ✗
The kubelet binary is missing.
Why it's wrong here
If the kubelet binary is absent from the host's executable paths, the systemd service manager will fail to launch the process entirely, reporting a 'file not found' or 'no such file or directory' error. It cannot execute far enough to encounter or report a permission denied error on its configuration.
- ✓
The kubelet configuration file has incorrect ownership or permissions.
Why this is correct
The kubelet service requires read access to its configuration file, typically located at `/var/lib/kubelet/config.yaml`. If this file has incorrect ownership or highly restrictive permissions (such as `0000`), the systemd service will fail to start, explicitly logging a 'permission denied' error when attempting to parse its startup parameters.
Go deeper
Related to this question
About these practice questions
This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.