r/KubernetesCerts

CKA, CKAD, CKS trifecta

I passed all three CKA,CKAD and CKS in 2 months given i have been working extensively on EKS/GKE for the past 3 years. Got 88%in CKA, 73% in CKAD messed up here because of overconfidence and 85% in CKS. Passed all in 1st attempt and now am planning to give KCNA and KCSA to secure the kubestronaut badge. Ask me anything. Thnks

reddit.com
u/Chionophile_2911 — 1 day ago

CKS Exam Experience 2026: What Helped, What Didn’t, and the Mistake That Cost Me Time

https://preview.redd.it/qzotj3kgx9kh1.png?width=1246&format=png&auto=webp&s=d399d023247591e1f99eebdd0128cf1b6bfb0151

Today, I passed CKS with 75% (not a good score) and wrote a detailed blog about my exam experience, preparation approach, the resources I used, and the Kubernetes security topics that helped me the most.

DMs are open if you are preparing for the exam. I can help with whatever is still fresh in my memory.

My biggest takeaway: CKS is noticeably harder than CKAD and CKA. It is not only about knowing Kubernetes commands. You need to understand why a configuration is insecure, how to fix it, and how to verify that your change actually worked.

The biggest mistake I made was spending around 10–15 minutes too long on one question because I felt I was close to solving it. That created unnecessary pressure towards the end and probably led to a couple of avoidable mistakes.

So my strongest advice is: if you are stuck and don’t see a clear path after a few minutes, mark the question and move on.

A few things that helped me:

Don’t memorise solutions. Understand the security reasoning behind them. If a NetworkPolicy, API server flag, securityContext, audit policy, or admission control changes slightly, memorised YAML will not help much.

Always verify your work. Security changes can easily break workloads or cluster components. Check Pods, control-plane components, logs, services, NetworkPolicy connectivity, admission behaviour, audit logs, node readiness, and systemd services wherever required.

Be comfortable with Linux as well as Kubernetes. CKS can require you to work with configuration files, systemd services, container runtimes, permissions, certificates, and node-level settings.

Use documentation whenever required instead of trying to remember every flag or custom resource.

Topics I would strongly recommend practicing:

  • Kubelet and etcd hardening
  • kube-apiserver authentication and authorization
  • Admission controls and ImagePolicyWebhook
  • Secure Dockerfiles and non-root containers
  • Container immutability and securityContext
  • Audit policies and API server logging
  • NetworkPolicy
  • HTTPS Ingress and TLS
  • ServiceAccount token security
  • Worker node administration and upgrades
  • SBOM and software supply-chain security
  • Restricted Pod Security Standard
  • Docker/container runtime hardening
  • Istio STRICT mTLS
  • Cilium network security
  • CIS benchmarks and kube-bench remediation

Resources I used:

  • KodeKloud CKS course
  • KodeKloud Ultimate Mock Exam Series
  • iximiuz Labs
  • KillerKoda
  • Killer[.]sh  CKS simulator
  • ChatGPT/Claude for topics that needed a simpler explanation or extra practice scenarios

Between the KodeKloud course mocks and Ultimate Mock Exam Series, I had around six mock exams. I found them very useful and reasonably close to the level of difficulty you should prepare for.

Killer

[.]sh felt a little off-track compared with the actual exam in some areas, but I would still recommend doing it. It is useful for practicing under time pressure, discovering knowledge gaps, and improving troubleshooting skills.

I also used ChatGPT and Claude quite a lot during preparation. CKS has many small security topics, and sometimes a course or lab explanation may not immediately click. In those cases, asking AI to explain the concept differently, compare configurations, or generate a small practice scenario was very useful.

The simplest advice I can give is: practice a lot, understand the security reasoning behind what you are doing, verify every change, and don’t let one difficult question consume your exam time.

I also wrote a full blog with more details on my preparation strategy, resources, task areas, mistakes, and lessons from the exam.

Blog: https://blog.prateekjain.dev/cks-exam-experience-2026-preparation-strategy-and-lessons-learned-1fad785a430b?sk=52b58a9c6d812444bc1340f15eda7dd6

reddit.com
u/root0ps — 1 day ago

For those who passed the CKA, when did you feel ready to schedule the exam?

Hey everyone! I’d like to hear from people who have already passed the CKA. At what point did you feel confident enough to schedule the exam? Was it after reaching a certain score on practice exams, finishing some study material, or simply when you started feeling comfortable solving the questions?

I’d also like to know which resources, labs, or practice exams you used and felt were a good match for the real exam.

I’ve currently finished the DumbITGuy questions and found them very easy, with no difficulty understanding them. What would you recommend doing next?

reddit.com
u/pdrmenna — 3 days ago

Need to be a genius to pass CKS?

Hi,

I want to know the truth, how hard is the CKS really?

It took me two attempts to pass CKA and three attempts to pass CKAD. I studied about two months for each of them. I barely passed them, achieved a low score just enough to pass.

I haven't tested my IQ but I know I'm not a genius.

I want to go for the CKS but I'm afraid it's above my level.

Thanks for your insight.

reddit.com
u/Neat-Obligation-6077 — 4 days ago

Studying for CKS and ended up building an iOS app for it

I’ve been studying for CKS and generally trying to stay sharp on Kubernetes but most of my study time ends up being at night on my phone while lying in bed. So I built an iOS app for myself to stay sharp on concepts, quiz myself (multiple choice, command builder, YAML fill-in-the-blank). It’s free, no ads, no paywalled content, no account, no data collection. Wasn’t originally planning to share it, but figured it might be useful to someone else in the same boat.

Note: this is not intended to be a supplement for deeper, hands-on courses or guides. Rather a helpful companion app to keep you sharp.

https://apps.apple.com/us/app/k8s-guide/id6787748279

u/braundmeier — 3 days ago

Cleared CKS 72% first attempt

this was a hard exam but i managed to clear it first time. some of the questions take a lot of time and its easy to get stuck unless you have repeatedly practiced resolving issues and configuring them. i passed the cka on my third attempt but my cks on my first.

i saw another post of what came up and this what what i recall.

  1. kubelet hardening
  2. cluster rolebinding
  3. configure admission controller and webhook
  4. dockerfile hardening
  5. falco configuration
  6. hardening pod immutable fs/prevent priv escalation
  7. configure aduit policy
  8. network policies
  9. ingress cilium
  10. service account token/hardening
  11. upgrade kubeadm cluster
  12. bom/spdx to idenity package
  13. pss configuration for pod
  14. docker daemon update permissions
  15. istio/mtls configuration
  16. create a tls secret

wish you good luck with this one. its very hard!

reddit.com
u/nopasswordhotspot — 5 days ago

Certified Kubernetes Administrator Completed

I wanted to share some good news — I’ve successfully passed the Certified Kubernetes Administrator (CKA) exam with 76%! 🎉

I bought the exam over a year ago and have been studying on and off for the last year. I’m not going to lie, it was a tough journey.

During that time, I had two close family funerals, went through ACL surgery and 4+ months of recovery, and obviously had work alongside it all. There were plenty of times when studying was the last thing I wanted to do. A big thank you to the Linux Foundation as well for kindly giving me an extension on my exam.

So I’m honestly really happy that I stuck with it and finally got it done.

I’m sure this is the right place to flex a little 😂 — I definitely didn’t want to do it on LinkedIn, so Reddit gets the flex instead!

What I used

  • Mumshad Mannambeth / KodeKloud Udemy course
  • DumbITGuy playlist
  • Prepium.sh — I got a free exam from them last week through this community at exactly the right time. Really appreciated it and would definitely recommend checking them out.

A massive thank you to everyone in this community who shares their experiences, tips and resources. It genuinely helped me a lot.

If you’re currently preparing and struggling, keep going. It might take longer than you expected, and life might get in the way, but that doesn’t mean you’ve failed.

Good luck to everyone preparing!

#CKA #Kubernetes #CertifiedKubernetesAdministrator #LinuxFoundation #DevOps #CloudEngineering #KubernetesAdministrator #DevOpsJourney #Certification #KeepGoing

u/Shankkky — 8 days ago

How I Prepared for CKAD After Failing — And Passed on My Retry

So, CKAD is not rocket science.

And I believe anyone preparing for the CKAD can clear the exam with laser-focused practice.

But maybe you're doing what I did before my first attempt.

And that got me to fail smart.

I used almost every practice set I could find.

KodeKloud. Killer.sh. Practice exams.

I love KodeKloud, especially if you don't have much Kubernetes experience. I believe it's one of the best places to start.

I even subscribed to an exam prep for around $25.

Worth it?

Yes.

Did it help me pass on my first attempt?

No.

The problem wasn't that I didn't practice.

I was scoring above 90% in practice exams.

So naturally, I was puffed up 😂

I thought I had the exam at my fingertips.

Then the real exam humbled me.

And that's when I noticed something.

The exam wasn't trying to test how smart I was.

It wasn't trying to trick me either.

A lot of it came down to whether I could actually deploy, configure, troubleshoot and maintain applications in a Kubernetes environment — under time pressure.

That changed how I prepared for my retry.

Instead of trying to do more and more practice exams, I became very intentional about the areas I needed to master.

And I passed.

So if you're preparing for CKAD, learn from my mistake instead of making the same one.

A wise man learns from the mistakes of others instead of making them himself.

If you're going to sit the exam, bro, master these topics:

🔐 Secrets & Environment Variables

You should be comfortable taking hardcoded environment variables and moving them into Secrets.

Know how to use secretKeyRef.

These can be easy points when you're calm and know exactly what you're doing.

🌐 Ingress

Be comfortable with both sides of this:

Fixing a broken Ingress

  • Wrong Service name
  • Wrong port
  • Missing or incorrect pathType

Creating an Ingress

  • Add the hostname
  • Route / or /app correctly
  • Point it to the correct Service and port

This was one of my weak points initially.

One thing that helped me:

Read the Service first. Then work on the Ingress.

🔒 NetworkPolicy

You need to understand this beyond memorizing YAML.

For example, you may have multiple NetworkPolicies already created and you're not allowed to modify them.

Your job could simply be to understand their selectors and label the correct Pods so that the required communication works.

If you understand labels and selectors properly, this becomes much easier.

📦 Resources

Know how to:

  • Set resource requests and limits
  • Update them on existing workloads
  • Work with ResourceQuota
  • Understand the relationship between requests and limits

Don't just memorize where resources: goes in the YAML.

Understand what you're changing.

🐳 Docker

Don't forget Docker.

Know how to:

  • Build an image
  • Tag the image correctly
  • Save/export the image

Nothing exotic.

But you don't want to be figuring out basic Docker commands during the exam.

🐦 Canary Deployment

Understand how to create a second version of an application while keeping the stable version running.

Think:

Stable:

version=v1

Canary:

version=v2

Then understand how replicas, labels and the Service selector work together.

🔁 Service Selectors

Service exists.

Pods exist.

But traffic isn't flowing.

What do you check?

Selectors.

Get comfortable checking endpoints too:

kubectl get endpoints

Sometimes the problem is much simpler than it looks.

⏰ CronJobs

Know how to create and troubleshoot CronJobs.

And understand something important:

The Job needs to finish.

If your container keeps running forever, you have a problem.

Understand things like activeDeadlineSeconds and how Jobs actually terminate.

This one tripped me before.

It won't again.

🔐 SecurityContext

Be comfortable editing an existing Deployment and adding something like:

runAsUser: 10000

But here's the important part:

There may already be a securityContext there.

Don't blindly delete what already exists.

Merge your changes intelligently.

🧑‍💼 RBAC

This is where many people lose time.

You might see something like this in the logs:

forbidden: User cannot list pods

Don't panic.

The error is already giving you a clue.

You may need to:

  • Create a ServiceAccount
  • Create or reuse the correct Role
  • Create the RoleBinding
  • Assign the ServiceAccount to the Deployment
  • Check the logs again

Read the logs.

They often tell you exactly which permission is missing.

🩺 Probes

Know how to add a readinessProbe.

Understand the basic HTTP probe structure and where it belongs in the container spec.

🔄 Deployment Rollback

Know how to:

  • Make/update a Deployment
  • Identify when something has gone wrong
  • Check rollout history
  • Roll back
  • Verify that the application recovered

⚠️ Deprecated APIs

You may come across manifests using deprecated API versions or fields.

You should be comfortable identifying the problem, fixing the manifest and applying it successfully.

The biggest thing I changed for my retry wasn't the number of practice exams I did.

It was how I practiced.

I stopped using a high practice score as proof that I was ready.

Instead, I focused on whether I could solve these tasks quickly, troubleshoot when something didn't work, and move on without wasting time.

If you're preparing for CKAD, I hope my first failure can save you from making some of the same mistakes.

I've also recorded a free YouTube series where I go through these CKAD topics and practice them.

You can watch the full series here:

https://www.youtube.com/playlist?list=PLszh7fnNwdwjjhX1Wxw8flmXMQk4O6SNw

u/Defiant-Chard-2023 — 7 days ago
▲ 243 r/KubernetesCerts+1 crossposts

🎉 Finally earned my CKA!

I’m happy to share that I’ve officially earned the Certified Kubernetes Administrator (CKA) certification! ☸️
The preparation was a great hands-on learning experience, especially around:
- Kubernetes administration & troubleshooting
- Networking & Services
- Storage & PVCs
- Security & RBAC
- Scheduling & workloads
- Cluster maintenance and troubleshooting
A big thanks to Mumshad Mannambeth for the excellent Kubernetes courses and Killer Shell for the hands-on practice environment. 🙌
Now looking forward to putting these skills into practice and continuing deeper into the Kubernetes/cloud-native ecosystem.

#CKA #Kubernetes #DevOps #CloudNative #K8s #Linux #CNCF #KillerShell #KubernetesAdministrator

u/Ok-Cycle6962 — 11 days ago

CKAD & CKS

Hey everyone,

I’m trying to figure out if it’s worth pushing forward and pursuing the CKAD and CKS certifications.

For some background, my company recently sponsored my KCNA, KCSA, and CKA, so I have those under my belt.

To be completely honest, the CKA was rough. I passed it on my second attempt with exactly the minimum required score. The main issue wasn't necessarily the technical material—the PSI testing platform was incredibly laggy and performed terribly, which burned a lot of my time and added unnecessary stress.

A few questions for those who have taken them:

Difficulty Level: How do the CKAD and CKS compare to the CKA? I've heard CKS is an absolute beast, but how does CKAD stack up for someone already familiar with CKA concepts?

Study Tips: Are there any specific resources, mock exams, or labs you highly recommend for either of these?

Surviving PSI: Any practical tips for dealing with the PSI platform lag during these specific exams? Does the strict time crunch in CKAD/CKS make the bad exam environment even more of a nightmare?

Thanks in advance for any advice!

reddit.com
u/ElectronicHall4183 — 11 days ago

Don't Fail the CKA Network Policy Question (Calico Setup)

You might get a question of this during the exam:

Install a CNI plugin. Choose one of the following: Flannel (v0.26.1) or Calico (v3.28.2)

with a requirement about network policy enforcement.

Flannel doesn't do network policy. That's not something you work out during the exam, it's something you know before you sit down. You see Flannel, you pick the other one, you move on.

That's the easy part. Everybody gets that part right. Then you run the right command, you watch it say created, and you still lose the marks. So here's what to actually look out for.

Step 1 — get the podSubnet before you install anything

k get cm kubeadm-config -n kube-system -o yaml | grep podSubnet

Depends on the cluster config, but you'll get something like:

podSubnet: 10.244.0.0/16

podSubnet is what the cluster hands out. The Calico manifest ships with its own default and it has never seen your cluster. This value got set when somebody ran kubeadm init, probably months ago, probably not by you. It's the range every pod IP on this cluster comes from, and the CNI you're about to install has to agree with it. Read the number now, before you install anything.

Step 2 — install the operator

you don't need those urls memorized. the exam gives you what you need in the question itself.

k create -f https://raw.githubusercontent.com/projectcalico/calico/v3.28.2/manifests/tigera-operator.yaml

Notice I used create here, not apply. The CRDs bundled inside that operator file are massive. If you use apply, kubectl tries to shove the whole file into a last-applied-configuration annotation, blows past the 256k limit, and throws an error right in your face. Use create and keep moving.

Don't believe me? Here's the output:

root@controlplane:~$ kubectl apply -f https://raw.githubusercontent.com/projectcalico/calico/v3.28.2/manifests/tigera-operator.yaml
namespace/tigera-operator created
customresourcedefinition.apiextensions.k8s.io/bgpconfigurations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/bgpfilters.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/bgppeers.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/blockaffinities.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/caliconodestatuses.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/clusterinformations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/felixconfigurations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/globalnetworkpolicies.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/globalnetworksets.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/hostendpoints.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipamblocks.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipamconfigs.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipamhandles.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ippools.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/ipreservations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/kubecontrollersconfigurations.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/networkpolicies.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/networksets.crd.projectcalico.org created
customresourcedefinition.apiextensions.k8s.io/apiservers.operator.tigera.io created
customresourcedefinition.apiextensions.k8s.io/imagesets.operator.tigera.io created
customresourcedefinition.apiextensions.k8s.io/tigerastatuses.operator.tigera.io created
serviceaccount/tigera-operator created
clusterrole.rbac.authorization.k8s.io/tigera-operator created
clusterrolebinding.rbac.authorization.k8s.io/tigera-operator created
deployment.apps/tigera-operator created
The CustomResourceDefinition "installations.operator.tigera.io" is invalid: metadata.annotations: Too long: may not be more than 262144 bytes

Step 3 — the operator is not the CNI

This is the one that got me. The operator is the thing that installs the CNI. It is not the CNI. It's just a controller sitting there waiting to be told what to build, and nothing has told it anything yet. No Calico, no CNI binary on disk, and your nodes are still NotReady.

You can check it yourself:

k get pods -n tigera-operator    # No resoucrce found
k get pods -n calico-system      # No resources found

That's what a half-finished install looks like.

Step 4 — download the custom resources and check the CIDR

you don't need those urls memorized. the exam gives you what you need in the question itself.

curl -sLO https://raw.githubusercontent.com/projectcalico/calico/v3.28.2/manifests/custom-resources.yaml

This is the file that actually tells the operator what to install. Don't pipe it straight into kubectl create. Download it, because you want to look at it first.

# This section includes base Calico installation configuration.
# For more information, see: https://docs.tigera.io/calico/latest/reference/installation/api#operator.tigera.io/v1.Installation
apiVersion: operator.tigera.io/v1
kind: Installation
metadata:
  name: default
spec:
  # Configures Calico networking.
  calicoNetwork:
    ipPools:
    - name: default-ipv4-ippool
      blockSize: 26
      cidr: 192.168.0.0/16   <-------------Here is what u need to change
      encapsulation: VXLANCrossSubnet
      natOutgoing: Enabled
      nodeSelector: all()

---

# This section configures the Calico API server.
# For more information, see: https://docs.tigera.io/calico/latest/reference/installation/api#operator.tigera.io/v1.APIServer
apiVersion: operator.tigera.io/v1
kind: APIServer
metadata:
  name: default
spec: {}

Final Step:

k create -f custom-resources.yaml

And now the operator actually has its instructions.

Step 5 — verify

k get tigerastatus
k get pod test-pod -o wide

There you go that is the whole process, I hope that will help you guys

u/Express_Text_8165 — 14 days ago