Setting Up Kubectl After Kubeadm Init
You are using kubeadm to initialize a cluster. After running 'kubeadm init', you follow the instructions to set up the kubeconfig for the regular user. Which of the following commands should you run to allow kubectl to communicate with the cluster?
Quick Answer
The answer is to run sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config. This command is correct because after kubeadm init, the admin.conf file is generated in /etc/kubernetes/ containing the cluster’s CA certificate, client certificate, and the API server endpoint, which together grant full administrative privileges to the cluster. Copying this file to the user’s $HOME/.kube/config directory allows kubectl to authenticate and communicate with the newly initialized cluster. On the CKA exam, this step tests your understanding of post-initialization configuration and the critical distinction between the admin.conf and the default kubeconfig; a common trap is attempting to use the bootstrap token or a different config file, which lacks the necessary credentials. Remember the memory tip: “Admin is the only admin” — only the admin.conf file provides the full cluster access needed for kubectl to work after kubeadm init.
⚠ Common exam trap
Candidates often confuse the various kubeconfig files generated by kubeadm (each tied to a specific control plane component) and mistakenly copy a component-specific config (like controller-manager.conf or kubelet.conf) instead of the admin.conf, which is the only one designed for administrative kubectl access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config
After running 'kubeadm init', the admin.conf file is generated in /etc/kubernetes/ and contains the cluster CA certificate, client certificate, and API server endpoint. This is the only kubeconfig file that grants full administrative access to the cluster, making it the correct file to copy to the user's $HOME/.kube/config for kubectl to communicate with the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
sudo cp /etc/kubernetes/controller-manager.conf $HOME/.kube/config
Why it's wrong here
controller-manager.conf authenticates the controller manager component, not a regular user, so kubectl would present the wrong identity. It is tempting because kubeadm does generate that file for component use, but the user kubeconfig is created by copying /etc/kubernetes/admin.conf to $HOME/.kube/config.
- ✗
sudo cp /etc/kubernetes/scheduler.conf $HOME/.kube/config
Why it's wrong here
scheduler.conf authenticates the kube-scheduler component, not a regular user, so kubectl would present the wrong identity and lack user permissions. It is tempting because kubeadm does place component kubeconfigs in /etc/kubernetes, but the correct file for user access is admin.conf.
- ✓
sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config
Why this is correct
The admin.conf file holds the cluster's certificate authority data and admin credentials, so copying it into the regular user's $HOME/.kube/config gives kubectl the endpoint and authentication it needs. This satisfies the requirement to let kubectl communicate with the freshly initialised cluster.
- ✗
sudo cp /etc/kubernetes/kubelet.conf $HOME/.kube/config
Why it's wrong here
kubelet.conf carries the node's kubelet identity, so copying it grants node-level credentials rather than the cluster-admin access a regular user needs. It is tempting since kubeadm generates it during init, but admin.conf is the file intended for the user's $HOME/.kube/config.
Go deeper
Related to this question
Learn chapter
Installing Kubernetes with kubeadm
Key term
kubeadm Cluster Setup
kubeadm is a command-line tool that helps you create and manage a Kubernetes cluster by automating the setup of control plane and worker nodes.
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are setting up a new Kubernetes cluster using kubeadm. After running 'kubeadm init', you want to start using the cluster with kubectl. Which of the following commands should you run to configure kubectl for the admin user?
easy- ✓ A.mkdir -p $HOME/.kube && sudo cp /etc/kubernetes/admin.conf $HOME/.kube/config && sudo chown $(id -u):$(id -g) $HOME/.kube/config
- B.sudo kubeadm reset --force
- C.sudo cp /etc/kubernetes/admin.conf /root/.kube/config
- D.sudo cp /etc/kubernetes/pki/admin.conf $HOME/.kube/config
Why A: After running 'kubeadm init', the admin kubeconfig file is generated at /etc/kubernetes/admin.conf. To use kubectl as a regular (non-root) user, you must copy this file to the user's $HOME/.kube/config directory and then change its ownership to the current user. This ensures kubectl can authenticate to the cluster using the admin certificate and key embedded in the config file.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.