CKAD Application Deployment Practice Question
You want to perform a canary deployment where 10% of traffic goes to the new version. You have a Deployment 'app-v1' with 10 replicas. You create a second Deployment 'app-v2' with 1 replica and a new Service. What Kubernetes resource is typically used to split traffic between the two Services?
⚠ Common exam trap
Many exam-takers confuse Ingress with Service-level traffic splitting, forgetting that a standard Kubernetes Service does not support weighted routing between multiple Deployments, while an Ingress with a canary annotation does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress resource with a canary annotation
An Ingress resource with a canary annotation (e.g., `nginx.ingress.kubernetes.io/canary-weight: "10"`) allows you to split traffic between two Services by weight. This is the standard Kubernetes approach for canary deployments, where the Ingress controller (like NGINX) routes a specified percentage of traffic to the canary Service (app-v2) and the rest to the primary Service (app-v1).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A single Service with multiple selectors
Why it's wrong here
A single Service uses a label selector to create a flat pool of Pods, and it load-balances to every Pod in that pool with equal weight. Adding multiple selector terms only filters or expands the set of matched Pods; it cannot assign a 10% weight to one subset. Therefore, if stable and canary Pods both match, they receive roughly equal traffic, not a controlled 10% canary share.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy is an imperative firewall that governs which Pods can communicate with one another based on labels, namespaces, and ports. It can block or allow connections, but it has no notion of request routing or weighted distribution, so it cannot forward only a fraction of traffic to a canary. Since its verdict is binary allow/deny, it is fundamentally unsuited for percentage-based canary traffic.
- ✓
Ingress resource with a canary annotation
Why this is correct
Ingress controllers such as NGINX, Traefik, and HAProxy implement canary annotations (for example, nginx.ingress.kubernetes.io/canary-weight) that instruct the controller to send a specified percentage, e.g. 10%, of requests to a secondary canary Service while the rest go to the stable Service. The annotation can also be based on headers or cookies for test-specific routing. This gives a control plane at the edge to adjust weight dynamically without redeploying Services.
- ✗
HorizontalPodAutoscaler
Why it's wrong here
HorizontalPodAutoscaler monitors metrics like CPU utilization or request latency and automatically adjusts the replica count of a Deployment. It only affects how many instances of the same Pod are running; it does not distinguish between versions or route traffic proportionally. Even if it scales the canary to one out of ten replicas, the Service still round-robins across all Pods, so you cannot guarantee an exact 10% split.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.