Book Image

Certified Kubernetes Administrator (CKA) Exam Guide

By : Mélony Qin
4 (1)
Book Image

Certified Kubernetes Administrator (CKA) Exam Guide

4 (1)
By: Mélony Qin

Overview of this book

Kubernetes is the most popular container orchestration tool in the industry. The Kubernetes Administrator certification will help you establish your credibility and enable you to efficiently support the business growth of individual organizations with the help of this open source platform. The book begins by introducing you to Kubernetes architecture and the core concepts of Kubernetes. You'll then get to grips with the main Kubernetes API primitives, before diving into cluster installation, configuration, and management. Moving ahead, you’ll explore different approaches while maintaining the Kubernetes cluster, perform upgrades for the Kubernetes cluster, as well as backup and restore etcd. As you advance, you'll deploy and manage workloads on Kubernetes and work with storage for Kubernetes stateful workloads with the help of practical scenarios. You'll also delve into managing the security of Kubernetes applications and understand how different components in Kubernetes communicate with each other and with other applications. The concluding chapters will show you how to troubleshoot cluster- and application-level logging and monitoring, cluster components, and applications in Kubernetes. By the end of this Kubernetes book, you'll be fully prepared to pass the CKA exam and gain practical knowledge that can be applied in your day-to-day work.
Table of Contents (17 chapters)
1
Part 1: Cluster Architecture, Installation, and Configuration
5
Part 2: Managing Kubernetes
10
Part 3: Troubleshooting

Chapter 6 – Securing Kubernetes

You have two virtual machines: master-0 and worker-0, please complete the following mock scenarios.

Scenario 1

Create a new service account named packt-sa in a new namespace called packt-ns.

Use the following command to create a new service account in the targeting namespace:

kubectl create sa packt-sa -n packt-ns

Scenario 2

Create a Role named packt-role and bind it with the RoleBinding packt-rolebinding. Map the packt-sa service account with list and get permissions.

Use the following command to create a cluster role in the targeting namespace:

kubectl create role packt-role --verb=get --verb=list --resource=pods --namespace=packt-ns

Use the following command to create a Role binding in the targeting namespace:

kubectl create rolebinding packt-pods-binding --role=packt-role --user=packt-user -- namespace=packt-ns

To achieve the same result, you can create a yamldefinition called packt-role.yaml:

apiVersion...