Hedronite · Cert Lesson · Cert-Prep / CNCF · Fri 2026-08-28

CKA App Lifecycle — the surge that is not a second cluster

Change the template. Watch two ReplicaSets. Stay above the floor. Do not clone the cluster.

Lesson Class: Cert (CKA Workloads App Lifecycle half of 15%)
Blueprint: App Lifecycle rollingUpdate. 08-16 closed scheduler half. CKS System Hardening 15% remains.
Paired Ops: EKS surge on one cluster; ALB targets; not a second API
Paired Dev: Python rollout census that will not patch
Grounding: CKA Q18 Questions + SolutionNotes · Q5/Q3 adjacent · K8sUR3 Ch.9 · Poulton Ch.6
Q18
Strategic patch of the template. Remain available at 2.
Q3 / Q5
Sidecar starts a walk. HPA changes desired, not the image.
Blue/green
maxSurge 100% + maxUnavailable 0. One context.
Change the template. Watch two ReplicaSets. Stay above the floor. Do not clone the cluster.

<!-- hal:authoritative:yaml -->

Change the template. Watch two ReplicaSets. Stay above the floor. Do not clone the cluster.

§I — Frame

k8s_day_counter reads 12. Even is CKA. 08-16 closed Workloads and Scheduling 15% on the scheduler half: requests, limits, taints, PriorityClass, Q10 / Q4 / Q7 / Q5 as placement. The domain is 15%. The other half is App Lifecycle. That fire is this file.

CKS leftover entering today is System Hardening 15%. Official order can wait. Today is CKA. Do not spend this clock on AppArmor or seccomp. 08-25 closed Cluster Hardening Q04. Leave the flags there.

08-22 already spent Storage Q1 and Q14. 08-10 already spent Troubleshooting 30% including node NotReady. 08-04 already spent Cluster Architecture access control. 07-29 already spent Services. The unopened CKA surface on this arc is the rollout.

The day's Ops lesson is EKS: maxSurge as extra Pods on one cluster, not a second control plane. Poulton already told you a second ReplicaSet is how an image moves (Ch. 6, printed p. 64). The exam is not hosted. The exam is kubeadm. This file edits a Deployment and watches ReplicaSets. The fleet cannot grade you on aws eks create-cluster. The exam will not give you a second API. Learn both. Grade this file on the strategy block.

Coin it: the surge that is not a second cluster.

§II — Domain foundations

Workloads and Scheduling is 15%. 08-16 spent the Scheduling half. Four App Lifecycle moves remain.

  1. Declare a Deployment. apps/v1. Selector matches template labels. Selector is immutable (Poulton Ch. 6, printed p. 73).
  2. Change the Pod template. Image, env, resources, a sidecar. The change starts a rollout. Pods are replaced, not edited (Ch. 6, printed p. 71).
  3. Control the walk. strategy.type is RollingUpdate or Recreate. maxSurge and maxUnavailable are number or percent (K8sUR3 Ch. 9, pp. 157-159).
  4. Observe and reverse. kubectl rollout status. kubectl rollout history. kubectl rollout undo. Undo is an update in reverse (Poulton Ch. 6, printed p. 76).

Q18 spends move 2 and the availability clause of move 3 in one stem. The candidate patches CPU and memory with kubectl patch only. The Deployment must remain available at 2 replicas. The patch writes the template. The template change starts RollingUpdate. Availability is maxUnavailable, not a cloned control plane.

Q3 spends move 2 as a sidecar add. Adding busybox:stable with tail -F is a template change. A rollout starts. If the stem does not mention maxUnavailable, the default 25% is the floor. Do not switch to Recreate to "make the sidecar appear faster."

Q5 spends a different knob. HPA changes spec.replicas. RollingUpdate changes the template at a given replica count. 08-16 already taught that HPA does not place Pods. Today: HPA does not replace Pods for a new image. If both fire, CURRENT climbs and you will not know which loop did it.

Poulton's request of the app is two properties (Ch. 6, printed p. 63). Loose coupling via APIs. Backward and forward compatibility. K8sUR3 spends the same tax on the JavaScript client that called v2 (Ch. 9, pp. 155-156). The exam will not grade your API design. The exam will grade whether you left 2 replicas Available while the template changed.

Hold the three numbers in your head before you touch YAML. Desired is spec.replicas. Floor is desired minus maxUnavailable (or desired minus ceil(percent * desired)). Ceiling is desired plus maxSurge. A legal walk stays inside that band. A CURRENT of desired+maxSurge is success. A CURRENT of 2*desired with maxSurge 25% is a second controller (often HPA) or a second Deployment you did not mean to apply. Count Deployments before you count clusters.

minReadySeconds is how you keep a bad image from eating the set. Ten seconds in the book is a classroom number. If the stem gives you 30, use 30. If the stem is silent, do not invent a 300. Defaults exist. Changing a field the stem did not name is how Q18's "do not change requests" trap generalizes.

Recreate is the trap (Ch. 9, p. 155). It terminates every Pod, then builds the new image. Fast. Downtime. If the stem says "remain available," Recreate is a fail. If the stem is silent and the Service is public, Recreate is still a fail in production. On the exam, read the stem.

K8sUR3 p. 159: maxSurge 100% with maxUnavailable 0 is in-cluster blue/green. New set rises to the old count. Old set drops to zero. That is still one Deployment. That is the surge that is not a second cluster. If a practice prompt says "blue/green," check whether they want this pair of fields or a second object. The CKA wants the fields.

§III — Mechanism: the walk the exam can see

Create the object the way the book does. Then change one line.

apiVersion: apps/v1
kind: Deployment
metadata:
  name: hello-deploy
spec:
  replicas: 10
  revisionHistoryLimit: 5
  progressDeadlineSeconds: 300
  minReadySeconds: 10
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxUnavailable: 1
      maxSurge: 1
  selector:
    matchLabels:
      app: hello-world
  template:
    metadata:
      labels:
        app: hello-world
    spec:
      containers:
      - name: hello-pod
        image: nigelpoulton/k8sbook:1.0
        ports:
        - containerPort: 8080

Poulton's printed pp. 65-66 are this block. revisionHistoryLimit: 5 keeps five old ReplicaSets. progressDeadlineSeconds: 300 is five minutes per new replica before Progressing goes False. minReadySeconds: 10 waits after Ready before the next replacement. maxUnavailable 1 and maxSurge 1 on desired 10 means you never sit below 9 or above 11. The walk moves two Pods at a time (Ch. 6, printed p. 72).

Change the image to nigelpoulton/k8sbook:2.0. Apply. --record is how the book stamps history. The flag is deprecated in newer kubectl and the annotation still works if you set kubernetes.io/change-cause yourself. The exam accepts either so long as rollout history shows two revisions.

kubectl apply -f deploy.yml
kubectl rollout status deployment hello-deploy
kubectl get rs
kubectl get deploy hello-deploy

Expected mid-walk: CURRENT 11, UP-TO-DATE climbing, two ReplicaSets. Poulton's table is DESIRED 10, CURRENT 11, UP-TO-DATE 5, AVAILABLE 11 (Ch. 6, printed p. 73). If AVAILABLE drops under 9, you broke the floor. Pause.

kubectl rollout pause deployment hello-deploy

K8sUR3 Ch. 9, p. 151: pause, inspect, resume. If the new Pods are CrashLoop, do not resume. Undo.

kubectl rollout undo deployment hello-deploy --to-revision=1

Undo uses the same maxUnavailable and maxSurge. It is not instant (Ch. 6, printed p. 76). Watch status again. Then edit the YAML so the next apply does not re-fight the undo. The exam grades the cluster, not your git. Your later Friday grades both.

kubectl rollout history deployment hello-deploy --revision=2 prints the Pod template for that revision (K8sUR3 Ch. 9, p. 151). Read the image line. Read the env. Read the resources. Undo to a revision you have read, not to a number you like. Revision 1 is not "safe" if revision 1 was the LabSetUp broken image.

If status hangs, do not Ctrl+C and walk away. The walk continues. kubectl get deploy and kubectl get rs are the mid-walk instruments. rollout status is a waiter. A waiter that you kill is not a rollback. Pause is the stop. Undo is the reverse. Delete of the Deployment is the nuclear option and it takes the Service's endpoints with it if the selector dies.

Q18's patch is the other way to start this walk.

kubectl patch deployment resource-app -n patch-ns \
  --type=strategic \
  -p '{"spec":{"template":{"spec":{"containers":[{"name":"nginx","resources":{"limits":{"cpu":"500m","memory":"512Mi"}}}]}}}}'

SolutionNotes: strategic merge matches the container by name. Requests stay 100m / 128Mi. Merge type that replaces the whole limits object still works if you include every limit. kubectl edit is banned by the stem. kubectl apply is banned by the stem. After the patch, kubectl get deploy resource-app -n patch-ns must still show 2 available. If you set strategy.rollingUpdate.maxUnavailable to 2 on a desired of 2, you may dip to 0. That fails the stem. Leave the strategy at default 25% unless the stem asks you to change it. 25% of 2 is 1 after rounding. One Pod may be down. One Pod stays Available. That is the floor.

§IV — Exam traps

Trap 1: Recreate for speed. The sidecar in Q3 "is not showing up." You set strategy.type: Recreate. The new Pods appear. The Service went dark. If the stem wanted availability, you failed. If the stem was silent, you still taught your hands a bad default.

Trap 2: scale instead of roll. You need a new image. You kubectl scale --replicas=20, then delete old Pods by hand. That is not RollingUpdate. That is a human ReplicaSet. HPA Q5 will fight you. The history will not have a revision for the image.

Trap 3: second cluster thinking. A practice blog says blue/green means two kubeconfigs. On CKA, blue/green is maxSurge 100% and maxUnavailable 0 (K8sUR3 p. 159). One context. Two ReplicaSets. If you spend twelve minutes creating a kind cluster, you will miss Q18.

Trap 4: editing a live Pod. kubectl edit pod hello-deploy-xxxx to change the image. The ReplicaSet reverts it. The Deployment is the object. The Pod is the evidence.

Trap 5: changing the selector. You rename a label to "match the new app." The selector is immutable. The apply fails. Or worse, you created a second Deployment that selects nothing. Leave the selector. Change the image.

**Trap 6: forgetting --record and then guessing revisions.** rollout history without a change-cause still numbers revisions. rollout history --revision=2 shows the Pod template. Read the image. Do not undo to 1 because 1 is "the first one" if 1 is the bad apply.

Trap 7: Q18 merge that drops requests. You used a merge patch and sent only limits. Requests vanished. The scheduler packs differently. 08-16 already failed a Pod for requests. Today the stem said do not change requests. Include them or use strategic.

§V — Connection to today's Ops and Dev

Ops coined the surge that is not a second cluster on EKS. ALB targets. Karpenter adding a node. Node group updateConfig.maxUnavailable as the wrong object. The exam will not give you those. The exam will give you kubectl get rs. Same two sets. Same floor.

Dev is the Python census. AppsV1Api. Print desired, current, updated, available. Do not patch. Q18 is the write Dev refuses. If you finish this file by pasting Dev's loop into the exam cluster, you will list the leftover and not change it. The stem wants the change. Stay in kubectl.

08-16 is the sibling domain file. Taints and PriorityClass decide whether the new surge Pod binds. A rollout that stalls on Pending is a scheduler problem. kubectl describe pod on the new set. If the event is FailedScheduling, open 08-16. If the event is Unhealthy on the probe, stay here.

08-10 is the sibling when the node is NotReady. A surge that cannot schedule because half the nodes are NotReady is Troubleshooting. Do not raise maxSurge to 100% to "get around" a dead kubelet.

08-25 is CKS. Anonymous-auth does not start a rollout. Do not open the static Pod.

08-22 is Storage. A rolling update of a Deployment that mounts a Retain PV will still replace the Pod. The volume is the leftover 08-22 named. If the stem is a stateless image change, do not touch the PVC. If the stem is a StatefulSet, you are in a different updateStrategy and a different Friday.

The EKS overlay lives in Ops. Remember one sentence of it so a cloud-flavored practice item does not steal the clock: the ALB target group growing by one IP is maxSurge working. aws eks create-cluster is not a CKA verb. If a vendor lab asks you to stand up a second managed cluster for a new tag, you are no longer in this blueprint.

§VI — Practice questions

Question 1
hello-deploy desired 10, strategy maxUnavailable 1, maxSurge 1. You apply image 2.0. Mid-walk kubectl get deploy shows CURRENT 11, UP-TO-DATE 5, AVAILABLE 11. Are you over the floor?
tap to reveal
No. 11 is maxSurge 1. AVAILABLE 11 is above 9. Poulton's table is this row (Ch. 6, printed p. 73). Let it finish. Watch kubectl get rs for the second set.
Question 2
Same Deployment. You set strategy.type: Recreate so the new image appears in one step. The Service drops to 0 endpoints for 40 seconds. Pass?
tap to reveal
No, if the stem required availability. Recreate terminates every Pod first (K8sUR3 Ch. 9, p. 155). RollingUpdate with maxUnavailable 1 was the walk that keeps 9.
Question 3
Q18. You kubectl edit the Deployment and set cpu limit 500m, memory limit 512Mi. Requests unchanged. Two replicas stay Available. Verify.bash greps for a patch event. Pass?
tap to reveal
No. The stem said ONLY kubectl patch. The cluster state can be right and the method still fails. Use the strategic merge in SolutionNotes.
Question 4
Q18. You strategic-patch limits. You also set maxUnavailable: 2 on a desired of 2 because "it will finish faster." During the walk AVAILABLE is 0. Pass?
tap to reveal
No. The stem said the Deployment must remain available (2 replicas). 25% default keeps one Pod. maxUnavailable 2 spends the whole count.
Question 5
A prompt says "blue/green the frontend." You create a second kind cluster and a second kubeconfig. Time expires. What did K8sUR3 already give you?
tap to reveal
maxSurge 100% and maxUnavailable 0 on the existing Deployment (Ch. 9, p. 159). New ReplicaSet rises to the old count. Old ReplicaSet drops to 0. One context. The surge that is not a second cluster.
Question 6
The new ReplicaSets Pods are Pending. kubectl rollout status hangs. You raise maxSurge to 50%. The new Pods are still Pending. What file owns this, and what do you run first?
tap to reveal
08-16 owns placement. kubectl describe pod on a new-set Pod. If FailedScheduling, check requests, taints, PriorityClass. maxSurge adds more Pending. It does not add a node on the exam.

§VII — Close

Four moves. Declare. Change the template. Control the floor. Undo. Q18 is a patch that must keep 2 Available. Q3 is a sidecar that starts the same walk. Q5 is scale, not replace. Recreate is downtime. maxSurge 100% is blue/green inside one object.

Examine well. Two ReplicaSets is the pass. A second cluster is the blog.

Related