CKAD Application Design and Build Practice Question
You run 'kubectl run debug-pod --image=busybox -it --restart=Never -- sh' but the pod starts and immediately exits. You want to keep the container running to execute commands later. What flag should you add?
⚠ Common exam trap
The CKAD exam often tests the misconception that `--stdin=true` or `-it` alone keeps the pod running, but without a long-running command, the shell exits immediately, and the pod terminates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-- sleep infinity
Adding `-- sleep infinity` to the `kubectl run` command overrides the default entrypoint (`sh`) with a command that runs `sleep infinity`, which keeps the container alive indefinitely. Without this, the interactive shell (`sh`) exits immediately when it has no input, causing the pod to terminate. The `--` separator passes the command to the container image's entrypoint, ensuring the process runs in the foreground and does not exit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--stdin=true
Why it's wrong here
The `-i` flag already sets `--stdin=true`, so explicitly adding it is redundant and changes nothing. Even with stdin kept open, the busybox image's default entrypoint (`/bin/sh`) immediately exits when it receives no input or when stdin is closed after the command completes, because there is no long-running process to keep PID 1 alive. The container's lifecycle follows the main process; if `sh` exits, the container exits regardless of stdin state.
- ✗
--command
Why it's wrong here
The `--command` flag is only necessary when you want to override the image's configured entrypoint and run a command directly; without it, arguments are still appended to the entrypoint, and for a simple busybox image that still means running `sh`. You are not trying to change the entrypoint rules here—you just need to supply a blocking command. Adding `--command` by itself, without a valid long-running command, does not prevent the container from exiting; it only changes how arguments are interpreted.
- ✓
-- sleep infinity
Why this is correct
By placing `--` followed by `sleep infinity` after the image name, you tell `kubectl run` to use that as the container's command, replacing the default `sh` from busybox. `sleep` is a process that suspends execution for the given interval; `infinity` means it never returns, so the main process never exits and the container remains in Running state indefinitely. This gives you a stable debug Pod you can `kubectl exec` into to run troubleshooting commands without worrying about the container dying.
- ✗
--attach
Why it's wrong here
The `--attach` flag merely connects your local terminal to the container's stdin/stdout/stderr streams after the container is created; it has no influence on what process runs as PID 1. If the container's command terminates, the container stops and your attach session ends immediately. To get an interactive, long-lived session, you'd combine `-it` with a blocking command like `sleep infinity`; attach alone cannot override the container's default behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.