Courseiva

CKA Practice Question: Cluster Architecture, Installation and Configuration

You are preparing to upgrade a Kubernetes cluster from v1.27 to v1.28 using kubeadm. What is the correct order of operations for upgrading the control plane nodes?

⚠ Common exam trap

Many exam-takers think upgrading all nodes simultaneously is faster or that worker nodes should be upgraded first to avoid downtime, but the CKA expects strict adherence to the kubeadm upgrade workflow where control plane nodes must be upgraded before worker nodes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Upgrade the first control plane node, then upgrade the remaining control plane nodes, then upgrade worker nodes.

The recommended upgrade order for a kubeadm-managed cluster is to upgrade the first control plane node (using `kubeadm upgrade apply`), then the remaining control plane nodes (using `kubeadm upgrade node`), and finally the worker nodes. This ensures the cluster's control plane components (etcd, kube-apiserver, kube-controller-manager, kube-scheduler) are updated first, maintaining cluster stability and API server availability during the process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Upgrade all worker nodes first, then upgrade the control plane nodes.

    Why it's wrong here

    Upgrading worker nodes before the control plane violates Kubernetes version skew policies. The kubelet on a worker node must not be newer than the kube-apiserver, as the control plane components cannot manage newer worker node APIs. Therefore, the control plane must always be upgraded to the target version before any worker nodes are updated.

  • ✓

    Upgrade the first control plane node, then upgrade the remaining control plane nodes, then upgrade worker nodes.

    Why this is correct

    This sequence aligns with the official Kubernetes upgrade workflow using kubeadm. You must first run kubeadm upgrade apply on a primary control plane node to update cluster-wide configurations and the local control plane. Afterward, you execute kubeadm upgrade node on the remaining control plane instances before safely upgrading the worker nodes.

  • ✗

    Upgrade all nodes simultaneously by running kubeadm upgrade apply on all nodes at once.

    Why it's wrong here

    Attempting a simultaneous upgrade across all nodes will cause severe cluster downtime and database corruption within the etcd quorum. The kubeadm upgrade apply command is designed to run exclusively on the first control plane node to bootstrap the upgrade. Other nodes must be upgraded sequentially using kubeadm upgrade node to maintain high availability.

  • ✗

    Upgrade worker nodes, then upgrade the control plane nodes, then drain the worker nodes.

    Why it's wrong here

    This strategy incorrectly sequences the node upgrades and performs the node draining too late. Nodes must be drained before they are upgraded to safely evict running workloads and prevent application disruption. Additionally, upgrading the workers prior to the control plane violates the Kubernetes API compatibility guarantees.

About these practice questions

One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.