CKA · domain
Cluster Architecture, Installation & Configuration
This domain covers bootstrapping and maintaining Kubernetes control planes and nodes with kubeadm, plus static pod manifests, kubelet configuration, certificates, and cluster upgrades. CKA tasks here are hands-on: you run kubeadm commands, inspect kubelet and container runtime state, edit manifests under /etc/kubernetes/manifests, and repair broken control plane or node components.
Focused practice
Practice Cluster Architecture, Installation & Configuration questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cluster Architecture, Installation & Configuration
Be able to bootstrap a cluster with kubeadm, join nodes, and repair a NotReady control plane by reading kubelet logs and static pod manifests. The single most important thing: after any manifest or config change, verify the component actually restarted and the node returns to Ready.
Running kubeadm init, kubeadm join, and kubeadm token create --print-join-command for cluster membership
Inspecting kubelet health with systemctl status kubelet and journalctl -u kubelet for startup failures
Managing static pods in /etc/kubernetes/manifests for kube-apiserver, kube-controller-manager, kube-scheduler, and etcd
Performing kubeadm upgrade plan and kubeadm upgrade apply, then draining and upgrading nodes
Watch out for
Common Cluster Architecture, Installation & Configuration exam traps
- ▸Re-running kubeadm init on a dirty host without kubeadm reset, leaving stale certificates, etcd data, or CNI config that breaks the new control plane.
- ▸Editing static pod manifests directly but forgetting the kubelet restarts them automatically, so changes must be valid YAML or the component crash-loops.
- ▸Confusing kubelet service failures with container runtime failures; checking only kubectl output instead of journalctl and crictl to find the real cause.
Question index
All Cluster Architecture, Installation & Configuration questions (19)
Click any question to see the full explanation, or start a practice session above.
A system administrator needs to install a Kubernetes cluster using kubeadm. The control plane node must be initialized with a specific Pod network CIDR of 10.244.0.0/16 for Flannel. Which command should be used?
Easy2A Kubernetes cluster is running with a single control plane node. The administrator wants to add a second control plane node for high availability. What is the first step after the new node has been provisioned with the required software?
Medium3Refer to the exhibit. A Kubernetes cluster was initialized using kubeadm with the command shown. After initialization, the cluster nodes are in NotReady state. Which is the most likely missing step?
Hard4You are a cluster administrator managing a multi-node Kubernetes cluster version 1.22. The cluster runs critical applications in the 'production' namespace. You have been asked to upgrade the control plane node to version 1.23 while minimizing downtime. The cluster uses a single control plane node (not HA). You have already backed up etcd and verified the backup is valid. You have also reviewed the upgrade notes and there are no breaking changes that affect your workloads. You have drained the control plane node and ensured all pods are evicted. The node is now in 'Ready,SchedulingDisabled' state. You then run 'kubeadm upgrade plan' and see that upgrade to v1.23.0 is available. Next, you run 'kubeadm upgrade apply v1.23.0'. The command completes successfully. However, when you try to uncordon the node with 'kubectl uncordon <node>', you get an error: 'error: unable to update node: the object has been modified; please apply your changes to the latest version and try again'. What is the most likely cause and the correct next step?
Hard5Refer to the exhibit. A new worker node (node2) has been added to the cluster. It shows NotReady status, and a CertificateSigningRequest (CSR) is pending. What step must the cluster administrator take to make node2 ready?
Hard6A Kubernetes cluster has three control plane nodes and five worker nodes. The kube-apiserver is failing to start on one control plane node with the error 'etcdserver: request timed out'. The etcd cluster is healthy with three members. Which of the following is the most likely cause?
Hard7A DevOps engineer notices that the kubelet on a node is unable to register with the Kubernetes API server. The kubelet logs show 'Failed to get bootstrap CA certificate' and the node is not yet part of the cluster. What is the most likely cause?
Hard8A DevOps engineer is designing a Kubernetes cluster for a production environment. Which of the following is a best practice for etcd deployment?
Medium9A cluster administrator notices that nodes are not joining the cluster after a kubeadm init. The kubelet logs show: 'failed to run Kubelet: could not init service: open /var/lib/kubelet/config.yaml: permission denied'. What is the most likely cause?
Hard10An administrator runs 'kubeadm init' on a machine that previously had a Kubernetes cluster. The command fails with the above errors. What is the best course of action?
Hard11An administrator is tasked with setting up a new Kubernetes cluster using kubeadm. They have two nodes: one control plane and one worker. After initializing the control plane with 'kubeadm init', the worker node fails to join with the error 'error execution phase preflight: [preflight] Some fatal errors occurred: [ERROR CRI]: container runtime is not running'. What should the administrator check first?
Easy12An administrator is preparing a bare-metal node to join an existing kubeadm cluster. The node has containerd installed and running, swap disabled, and the required kernel modules loaded. Before running kubeadm join, which command should the administrator run to ensure the kubelet registers with the API server using the correct node name?
Easy13A user tries to create a pod with the YAML file that requests 2 CPUs as a limit. The cluster has a ResourceQuota named 'compute-quota' with limits.cpu: 2. The user sees the above error. What is the likely issue?
Medium14Refer to the exhibit. An administrator creates a token with TTL 0. What is the effect on the token?
Medium15Refer to the exhibit. The master node shows NotReady status. The kubelet is reporting 'container runtime is down'. Which command should be used to investigate and fix this issue?
Medium16An administrator needs to initialize a new Kubernetes control plane node using kubeadm. Which of the following is the correct command to initialize the control plane with a specific pod network CIDR of 10.244.0.0/16?
Easy17A Kubernetes cluster has been running for months. Recently, some pods are reporting 'FailedScheduling' due to insufficient memory. The administrator wants to add a new node with 32GB RAM. However, after joining the node, the new node shows 'NotReady' and the kubelet logs indicate 'Failed to update node status: context deadline exceeded'. What is the most likely cause?
Hard18During a 'kubeadm init', the administrator sees the message 'Your Kubernetes control-plane has been initialized successfully!' but the 'kubectl get nodes' shows the control plane node as 'NotReady'. What is the most likely missing step?
Easy19A team is configuring etcd for a multi-node Kubernetes cluster. They want to ensure that etcd data is encrypted at rest. Which approach should they use?
HardOther domains
All CKA exam domains
Frequently asked questions
- What does the Cluster Architecture, Installation & Configuration domain cover on the CKA exam?
- Be able to bootstrap a cluster with kubeadm, join nodes, and repair a NotReady control plane by reading kubelet logs and static pod manifests. The single most important thing: after any manifest or config change, verify the component actually restarted and the node returns to Ready.
- How many questions are in this domain?
- This page lists all 19 Cluster Architecture, Installation & Configuration questions in the CKA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cluster Architecture, Installation & Configuration questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.