Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer needs to create a Kubernetes Secret for Docker registry authentication. The registry URL is 'myregistry.io', username 'user', password 'pass', email 'user@example.com'. Which command creates this Secret?

⚠ Common exam trap

Watch out — candidates often confuse the generic `kubectl create secret generic` command with the specialized `docker-registry` subcommand, or they may misremember the exact subcommand name as `registry` instead of `docker-registry`, leading them to pick option B or C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create secret docker-registry regcred --docker-server=myregistry.io --docker-username=user --docker-password=pass --docker-email=user@example.com

`kubectl create secret docker-registry` is the dedicated command for creating a Docker registry authentication secret, which automatically encodes the provided credentials into a `.dockerconfigjson` format. This secret type is specifically designed for pulling images from private registries, and the flags `--docker-server`, `--docker-username`, `--docker-password`, and `--docker-email` match the required fields for registry authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create secret tls regcred --cert=cert --key=key

    Why it's wrong here

    This command creates a TLS secret (kubernetes.io/tls), which is meant to store a certificate and private key for TLS termination—for example, an Ingress's HTTPS backend. A Docker registry credential secret must be of type kubernetes.io/dockerconfigjson and contain a .dockerconfigjson key with an 'auths' entry. Even if the flags succeed, kubelet will not treat a TLS secret as image pull credentials, so the registry login would not work for pulling images.

  • ✗

    kubectl create secret generic regcred --from-literal=username=user --from-literal=password=pass

    Why it's wrong here

    This creates an Opaque Secret with two separate keys, username and password, but Kubernetes looks for a single key named .dockerconfigjson when pulling images. That key must be the base64-encoded Docker config file (with an auths map), not individual literal fields. An Opaque secret with arbitrary keys is not recognized as a registry credential, so the image pull would fail with an authentication error, even though the secret is created successfully.

  • ✗

    kubectl create secret registry regcred --server=myregistry.io --username=user --password=pass

    Why it's wrong here

    The subcommand 'registry' does not exist; kubectl create secret accepts only generic, tls, and docker-registry. Additionally, the flags --server, --username, and --password are not valid for any secret subcommand; the docker-registry subcommand uses --docker-server, --docker-username, --docker-password, and --docker-email. Even if the command were syntactically corrected, it must generate a kubernetes.io/dockerconfigjson secret to work for image pulls.

  • ✓

    kubectl create secret docker-registry regcred --docker-server=myregistry.io --docker-username=user --docker-password=pass --docker-email=user@example.com

    Why this is correct

    This uses the dedicated docker-registry subcommand, which generates a kubernetes.io/dockerconfigjson Secret. Under the hood it constructs a .dockerconfigjson key containing a JSON object with an auths map, where the registry server is mapped to base64-encoded credentials (username:password). The resulting value is exactly what kubelet expects when a pod references this secret via imagePullSecrets, so the private registry becomes accessible for pulling images.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.