CKAD Application Design and Build Practice Question
A developer runs 'kubectl run mypod --image=nginx --restart=Never' and the pod is created. However, when the container exits, the pod terminates. Which restart policy ensures the pod does NOT restart after completion?
⚠ Common exam trap
In the CKAD exam, the trap here is that candidates often confuse the `--restart` flag in `kubectl run` with the pod's restart policy, or mistakenly think `OnFailure` prevents all restarts, when in fact it only restarts on non-zero exit codes, and `Never` is the only policy that guarantees no restart after any completion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Never
The `--restart=Never` flag sets the pod's restart policy to `Never`, which means the kubelet will not restart the container when it exits. Since the pod was created with `kubectl run` and `--restart=Never`, it runs as a standalone pod (not managed by a controller), and when the container exits, the pod enters the `Succeeded` or `Failed` phase and is not restarted. This is the only restart policy that guarantees the pod does not restart after completion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Always
Why it's wrong here
Always is the default restart policy for Pods, but it is incorrect here because it would cause the kubelet to restart the container indefinitely, even after a successful completion. Since the developer's command is intended to run a one-off `mypod` that should stop and remain in the Completed phase, Always would keep the container alive in a continuous loop, never allowing the Pod to reach Succeeded. Thus, Always does not match the desired behavior of a non-restarting Pod.
- ✗
OnFailure
Why it's wrong here
OnFailure is a valid restart policy that would restart the container only when it exits with a non-zero exit code, leaving a Pod with a successful exit in Succeeded. However, the correct policy for this scenario is Never, because the Pod should not be restarted under any circumstances, including failures. If OnFailure were used, a failing container would be restarted, which contradicts the intent of a single-run Pod that should fail into a Failed state without intervention.
- ✗
AlwaysFail
Why it's wrong here
AlwaysFail is not a recognized Kubernetes restart policy. The valid values for the `restartPolicy` field are only `Always`, `OnFailure`, and `Never` (case-sensitive). Using an invalid value such as AlwaysFail would cause the API server to reject the Pod creation with a validation error, meaning no Pod would ever be created. Therefore, AlwaysFail is not merely wrong in behavior; it is an invalid input.
- ✓
Never
Why this is correct
Never is the correct restart policy because it instructs the kubelet to not restart the container after it exits, regardless of the exit code. This allows the Pod to remain in the Succeeded phase if the container completed successfully, or Failed if it returned a non-zero exit code. For a one-off Pod like `mypod` that is intended to run to completion and stop, Never ensures the Pod does not restart, matching the developer's expectation.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.