CKA Practice Question: Cluster Architecture, Installation and Configuration
Which THREE components must be present in a high-availability control plane setup?
⚠ Common exam trap
CNCF often tests the distinction between control plane components and node-level agents, so candidates mistakenly include kubelet or kube-proxy as part of the control plane because they are essential to cluster operation, but they are not part of the control plane's high-availability architecture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-controller-manager
In a highly available Kubernetes control plane, the three essential components are the kube-controller-manager (C), etcd (D), and kube-apiserver (E). The kube-apiserver (E) is the central management endpoint that all clients and internal components communicate with, and it must be replicated behind a load balancer for HA. etcd (D) is the distributed key-value store that holds all cluster state; running it as an odd-numbered quorum across multiple nodes provides fault tolerance. The kube-controller-manager (C) runs the control loops that reconcile cluster state, and in HA it is typically deployed on multiple control-plane nodes with leader election so one active instance drives reconciliation. kubelet (A) and kube-proxy (B) are node-level components that run on every worker node, not control-plane HA components, so they are not required for a high-availability control plane setup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubelet
Why it's wrong here
The kubelet is the primary node agent that runs on every cluster node, including workers and control plane nodes, and is responsible for registering the node and managing Pod lifecycle by talking to the local container runtime. It is not part of the Kubernetes control plane, nor is it involved in cluster-wide decision making or state persistence, so a HA control plane can function without it being counted among its components. Its absence on a control plane node would only affect that node's own workloads, not the control plane's availability.
- ✗
kube-proxy
Why it's wrong here
kube-proxy is a network proxy that runs on each node to maintain network rules for Service IPs, typically using iptables or IPVS, and handles the data path for cluster networking. It is a node-level addon rather than a control plane core component; control plane HA does not depend on it because kube-proxy's job is to implement Service routing on nodes, not to serve the API, schedule workloads, or store state. Thus even if kube-proxy is absent, the API server, etcd, and controller-manager can still form a highly available control plane.
- ✓
kube-controller-manager
Why this is correct
The kube-controller-manager bundles the core control loops that reconcile the cluster's actual state toward the desired state, such as node lifecycle, replication, and endpoint management. It is essential for a HA control plane because in that setup you run multiple replicas with leader election, so only one instance actively runs controllers while the others stand by, but at least one must be reachable via the API server. Without it, no automated corrections would be made to workloads, making it an indispensable control-plane component.
- ✓
etcd
Why this is correct
etcd is the distributed consistent key-value store that holds the entire cluster state, including all API objects and metadata; it is the source of truth Kubernetes relies on to function. In a HA control plane, etcd must run as an odd-numbered cluster (typically 3 or 5 members) to establish quorum and tolerate machine failures, because any write requires a majority of members to agree. Since the API server reads and writes all cluster data to etcd, it is one of the three non-negotiable components.
- ✓
kube-apiserver
Why this is correct
The kube-apiserver is the front-end of the control plane and the only component that all clients and other control-plane components communicate with directly; it validates, processes, and serves RESTful requests and watches. In HA, multiple kube-apiserver instances are load-balanced behind a VIP or DNS, and they can run in active mode simultaneously because they are stateless and delegate persistence to etcd. This makes it an essential component, as no cluster management operation can be performed without an API server accessible.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Kubernetes Node Roles
Kubernetes Node Roles are labels assigned to machines in a cluster that define whether a node runs application containers (worker) or manages the cluster (control plane).
About these practice questions
Courseiva writes every CKA question from scratch — 726 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.