Courseiva
Application Deployment →mediumMultiple Choice

CKAD Application Deployment Practice Question

You want to perform a blue-green deployment using Deployments and Services. You have two Deployments: 'app-blue' (current) and 'app-green' (new). The Service 'app-service' currently selects pods with label 'version: blue'. What kubectl command should you run to switch traffic to the green deployment?

⚠ Common exam trap

CKAD often tests whether candidates know that Service selectors are mutable via patch and that delete/recreate breaks the ClusterIP, so the trap is choosing the destructive recreate option or an invalid subcommand like 'set selector'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl patch service app-service -p '{"spec":{"selector":{"version":"green"}}}'

A Kubernetes Service routes traffic based on its label selector, so blue-green switching is achieved by changing the Service's selector to point at the new pods. The kubectl patch command with a strategic merge patch on spec.selector updates the selector in place, instantly redirecting traffic to pods labeled version: green without recreating the Service or changing its ClusterIP. This is the canonical, non-disruptive way to flip traffic between blue and green Deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl patch service app-service -p '{"spec":{"selector":{"version":"green"}}}'

    Why this is correct

    The patch command mutates the existing Service's selector in place, updating the label selector from version=blue to version=green. Because the Service object is not deleted, its ClusterIP and NodePort are preserved, and Kubernetes immediately reconciles the Endpoints to include the green pods and exclude blue pods. This is the canonical zero-downtime traffic shift in a blue-green deployment, as it requires no file creation and only a single atomic API call.

  • ✗

    kubectl delete service app-service --ignore-not-found && kubectl create service app-service --selector version=green

    Why it's wrong here

    Deleting the Service before recreating it introduces a window where the Service is absent, causing DNS resolution failures and dropping existing connections that rely on the stable ClusterIP. Even with --ignore-not-found, the delete is not atomic with the create, so clients will see an unknown host or connection refused during the gap. Recreating the Service may also allocate a different ClusterIP, breaking any hard-coded references, whereas a patch keeps the Service identity intact.

  • ✗

    kubectl set selector service/app-service version=green

    Why it's wrong here

    The kubectl set command supports subcommands such as image, resources, and env, but there is no 'selector' subcommand in the kubectl set verb for any resource type. Running this command will fail immediately with an error because kubectl set does not recognize 'selector' as a valid subcommand. To change a Service's selector, you must use kubectl patch, kubectl edit, or kubectl apply with a complete manifest—there is no imperative one-liner like set selector.

  • ✗

    kubectl apply -f service.yaml where service.yaml has the new selector

    Why it's wrong here

    While kubectl apply -f service.yaml can update the Service if the file contains a complete and accurate Service manifest with the new selector, this approach relies on maintaining a separate file and requires the file to fully match the existing object's spec to avoid unintended changes. It is not a self-contained single command in the same way as a patch; it depends on external state and is slower for an imperative blue-green switch. The patch command is preferred because it surgically changes one field without needing the entire definition.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.