Courseiva

Setting Up Kubectl After Kubeadm Init

You are using kubeadm to initialize a cluster. After running 'kubeadm init', you follow the instructions to set up the kubeconfig for the regular user. Which of the following commands should you run to allow kubectl to communicate with the cluster?

Quick Answer

The answer is to run sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config. This command is correct because after kubeadm init, the admin.conf file is generated in /etc/kubernetes/ containing the cluster’s CA certificate, client certificate, and the API server endpoint, which together grant full administrative privileges to the cluster. Copying this file to the user’s $HOME/.kube/config directory allows kubectl to authenticate and communicate with the newly initialized cluster. On the CKA exam, this step tests your understanding of post-initialization configuration and the critical distinction between the admin.conf and the default kubeconfig; a common trap is attempting to use the bootstrap token or a different config file, which lacks the necessary credentials. Remember the memory tip: “Admin is the only admin” — only the admin.conf file provides the full cluster access needed for kubectl to work after kubeadm init.

⚠ Common exam trap

Candidates often confuse the various kubeconfig files generated by kubeadm (each tied to a specific control plane component) and mistakenly copy a component-specific config (like controller-manager.conf or kubelet.conf) instead of the admin.conf, which is the only one designed for administrative kubectl access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config

After running 'kubeadm init', the admin.conf file is generated in /etc/kubernetes/ and contains the cluster CA certificate, client certificate, and API server endpoint. This is the only kubeconfig file that grants full administrative access to the cluster, making it the correct file to copy to the user's $HOME/.kube/config for kubectl to communicate with the cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    sudo cp /etc/kubernetes/controller-manager.conf $HOME/.kube/config

    Why it's wrong here

    controller-manager.conf authenticates the controller manager component, not a regular user, so kubectl would present the wrong identity. It is tempting because kubeadm does generate that file for component use, but the user kubeconfig is created by copying /etc/kubernetes/admin.conf to $HOME/.kube/config.

  • ✗

    sudo cp /etc/kubernetes/scheduler.conf $HOME/.kube/config

    Why it's wrong here

    scheduler.conf authenticates the kube-scheduler component, not a regular user, so kubectl would present the wrong identity and lack user permissions. It is tempting because kubeadm does place component kubeconfigs in /etc/kubernetes, but the correct file for user access is admin.conf.

  • ✓

    sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config

    Why this is correct

    The admin.conf file holds the cluster's certificate authority data and admin credentials, so copying it into the regular user's $HOME/.kube/config gives kubectl the endpoint and authentication it needs. This satisfies the requirement to let kubectl communicate with the freshly initialised cluster.

  • ✗

    sudo cp /etc/kubernetes/kubelet.conf $HOME/.kube/config

    Why it's wrong here

    kubelet.conf carries the node's kubelet identity, so copying it grants node-level credentials rather than the cluster-admin access a regular user needs. It is tempting since kubeadm generates it during init, but admin.conf is the file intended for the user's $HOME/.kube/config.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are setting up a new Kubernetes cluster using kubeadm. After running 'kubeadm init', you want to start using the cluster with kubectl. Which of the following commands should you run to configure kubectl for the admin user?

easy
  • ✓ A.mkdir -p $HOME/.kube && sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config && sudo chown $(id -u):$(id -g) $HOME/.kube/config
  • B.sudo kubeadm reset --force
  • C.sudo cp /etc/kubernetes/admin.conf /root/.kube/config
  • D.sudo cp /etc/kubernetes/pki/admin.conf $HOME/.kube/config

Why A: After running 'kubeadm init', the admin kubeconfig file is generated at /etc/kubernetes/admin.conf. To use kubectl as a regular (non-root) user, you must copy this file to the user's $HOME/.kube/config directory and then change its ownership to the current user. This ensures kubectl can authenticate to the cluster using the admin certificate and key embedded in the config file.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.