CKAD Application Deployment Practice Question
A developer wants to perform a canary deployment where 10% of traffic goes to a new version (v2) of an application. They create two Deployments (app-v1 and app-v2) and a Service. The Service selector is configured to match labels: 'app: myapp, version: v1'. How can they route 10% of traffic to v2 with minimal changes?
⚠ Common exam trap
CKAD often tests the misconception that changing replica counts alone can route traffic to a new version when the Service selector still filters by version label, leading candidates to overlook the need to modify the selector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the Service selector to 'app: myapp' (remove version label) and set v1 replicas to 9 and v2 replicas to 1.
To achieve a canary deployment with 10% traffic to v2, the Service selector must match pods from both versions. By changing the selector to 'app: myapp' (removing the version label), the Service will load-balance across all pods with that label. Then, by setting v1 replicas to 9 and v2 replicas to 1, the total pods are 10, so v2 receives approximately 10% of traffic. This requires minimal changes: one selector update and replica adjustments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use kubectl rollout pause on the v2 Deployment.
Why it's wrong here
Running kubectl rollout pause on the v2 Deployment only prevents the Deployment controller from advancing its update; it does not tell the Service to send a fraction of traffic to v2. Even after a rollout is paused, any existing v2 pods are still in the same ReplicaSet and have the same labels, so the Service's traffic selection remains unchanged. Pausing is meant to inspect a deployment, not to implement canary traffic splitting.
- ✗
Set the v2 Deployment's spec.replicas to 10% of the total replicas and keep the Service selector unchanged.
Why it's wrong here
Simply setting the v2 Deployment's replicas to 10% is ineffective if the Service selector still pins to version=v1, because v2 pods won't be added to the Endpoints/EndpointSlice object and will receive zero connections. In Kubernetes, a Service forwards traffic only to ready pods whose labels match its selector; replica count alone does not influence selector matching. Additionally, even if the selector matched both versions, a Service load-balances evenly across ready endpoints, so you must adjust replica counts to achieve the desired ratio — but this option explicitly leaves the selector unchanged, leaving v2 outside the load-balancing set.
- ✓
Change the Service selector to 'app: myapp' (remove version label) and set v1 replicas to 9 and v2 replicas to 1.
Why this is correct
This works because removing the version label from the Service selector makes it match every pod labeled app: myapp, including both v1 and v2. With v1 replicas=9 and v2 replicas=1, the Service sees 10 ready endpoints, and the default load-balancing behavior sends roughly one-tenth of requests to v2. This replica ratio is the standard lightweight canary technique for a single Service, as long as both Deployments share the same app label and no other version-specific selector remains.
- ✗
Add a NetworkPolicy to limit traffic to v2 pods to 10%.
Why it's wrong here
A NetworkPolicy is a Kubernetes firewall that controls which sources can reach selected pods via ingress/egress rules; it cannot perform traffic proportioning or send a fixed 10% of Service requests to specific endpoints. NetworkPolicy rules are binary (allow/deny) per source and are not weighted across a set of pods. Because the Service still load-balances evenly across all matching endpoints, a NetworkPolicy cannot reduce v2's share to 10%; it would instead block or allow traffic to v2 entirely.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.