An administrator creates a Pod with an ephemeral container using 'kubectl debug my-pod -it --image=busybox --target=my-container'. The ephemeral container shares the same process namespace as the target container. Which flag enables this?
--target is the correct flag because it tells kubectl debug which container within the target Pod should serve as the namespace source for the ephemeral container. Without --target, the ephemeral container is created with its own network and process namespaces, so it cannot see the processes or network interfaces of other containers, severely limiting debugging. The flag's value must match a container name in the Pod spec, and it is supported only in kubectl debug, not in kubectl exec.
Why this answer
The `--target` flag in `kubectl debug` specifies the target container within the Pod for the ephemeral container. When used, the ephemeral container shares the same process namespace as the target container, allowing tools like `ps` to see processes from the target container. This is essential for debugging scenarios where you need to inspect or interact with the target container's processes.
Exam trap
The CKAD exam often tests the distinction between Pod-level process namespace sharing (via `shareProcessNamespace` in the Pod spec) and the ephemeral container's `--target` flag, leading candidates to mistakenly choose `--share-process-namespace` when the question specifically asks about `kubectl debug`.
How to eliminate wrong answers
Option B is wrong because `--container` is used to specify the container name when attaching or executing commands in a Pod, not to enable process namespace sharing with an ephemeral container. Option C is wrong because `--namespace` is a kubectl flag for specifying the Kubernetes namespace of the resource, not for process namespace sharing. Option D is wrong because `--share-process-namespace` is a Pod-level field in the Pod spec (not a kubectl debug flag) that enables process namespace sharing between regular containers in the same Pod, not specifically for ephemeral containers created via `kubectl debug`.