Courseiva
Application Deployment →mediumMultiple Choice

CKAD Application Deployment Practice Question

You need to perform a canary deployment where 10% of traffic goes to the new version. You have a Deployment 'app-v1' with 9 replicas and 'app-v2' with 1 replica. What must be true for the Service to distribute traffic roughly 90/10?

⚠ Common exam trap

Many candidates think a Service needs separate selectors for each version or that session affinity controls traffic splitting, when in fact the Service simply selects all matching Pods and traffic ratio follows replica count.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Service selector must include a label that both Deployments share, e.g., 'app: myapp'

A Kubernetes Service distributes traffic across all Pods matching its label selector. For a canary deployment with 90/10 traffic split, both Deployments must share a common label (e.g., 'app: myapp') so the Service selects all 10 Pods (9 from v1, 1 from v2), achieving roughly 90% traffic to v1 and 10% to v2 based on replica count. The Service uses round-robin or random load balancing by default, so the ratio of replicas directly determines traffic distribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Service must have 'sessionAffinity: ClientIP' to ensure sticky sessions

    Why it's wrong here

    Setting sessionAffinity: ClientIP on the Service is unnecessary for a canary rollout and would actually harm it. ClientIP affinity makes a client stick to one backend pod, so a given user would see either the old or new version consistently, not a 10/90 traffic split across the user base. The Service's default round-robin load balancing already distributes requests across all selected pods; the proportion of traffic to each Deployment is determined by the number of ready pods, not by session affinity.

  • ✗

    The Service must not have any selectors, and endpoints must be manually managed

    Why it's wrong here

    Configuring a selectorless Service with manually managed Endpoints is overly complex and not needed for a canary deployment. Without a selector, the Service will not automatically discover pods; you must create and update an Endpoints object listing individual pod IPs, which breaks down as pods scale or restart. The entire point of a label selector is to let the Service dynamically include pods from both Deployments, so manual endpoint management adds no benefit and creates operational risk.

  • ✗

    The Service selector must include only 'version: v2'

    Why it's wrong here

    Restricting the Service selector to only version: v2 would make the Service target exclusively the canary Deployment's pods, sending 100% of traffic to v2 instead of 10%. To achieve the intended split, the selector must match pods from both versions, typically using a shared label like app: myapp, optionally with version labels only if you deliberately target one version. Using only version:v2 excludes the v1 pods entirely, so the canary would never receive a small slice of traffic.

  • ✓

    The Service selector must include a label that both Deployments share, e.g., 'app: myapp'

    Why this is correct

    The Service selector must include a label common to both Deployments—such as app: myapp—so that its endpoints automatically include pods from the stable and canary versions. Once the Service selects both sets of pods, Kubernetes round-robins requests across all available endpoints, and the proportion of traffic to each version roughly equals the ratio of ready pod counts (e.g., 9 v1 pods and 1 v2 pod for ~10% canary traffic). This shared-label selector is what enables a simple, replica-count-based canary without external traffic-weighting tools.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.