A node in your cluster shows status 'NotReady'. You have SSH access to the node. What is the first command you should run to check the kubelet status?
The kubelet is the primary node agent that communicates with the Kubernetes control plane to report node status and heartbeat. Running systemctl status kubelet immediately reveals whether the service is active, inactive, or failing, which is the most direct and efficient first step when troubleshooting a NotReady node via SSH.
Why this answer
When a node is NotReady, the first step is to check if the kubelet service is running, because the kubelet is the primary agent responsible for reporting node status to the control plane. Running `systemctl status kubelet` immediately shows whether the kubelet service is active, failed, or stopped, along with recent log snippets, making it the fastest diagnostic command.
Exam trap
The trap here is that candidates often jump to checking logs (option B or D) first, but the CKA exam expects you to follow a systematic troubleshooting hierarchy: start with service status, then logs, then runtime checks.
How to eliminate wrong answers
Option A is wrong because checking the container runtime (docker or containerd) is a secondary step; the node status is reported by the kubelet, not the runtime, and a runtime failure would manifest as pod issues, not necessarily a NotReady node. Option B is wrong because reading the full kubelet log file is a deeper investigation step after confirming the service status; it is not the first command and can be time-consuming. Option D is wrong because `journalctl -u kubelet` provides detailed logs but is more verbose and slower than `systemctl status kubelet` for an initial health check; the first command should be the service status command to quickly see if the kubelet is running or failed.