CKA App Lifecycle — the surge that is not a second cluster
Change the template. Watch two ReplicaSets. Stay above the floor. Do not clone the cluster.
<!-- hal:authoritative:yaml -->
Change the template. Watch two ReplicaSets. Stay above the floor. Do not clone the cluster.
§I — Frame
k8s_day_counter reads 12. Even is CKA. 08-16 closed Workloads and Scheduling 15% on the scheduler half: requests, limits, taints, PriorityClass, Q10 / Q4 / Q7 / Q5 as placement. The domain is 15%. The other half is App Lifecycle. That fire is this file.
CKS leftover entering today is System Hardening 15%. Official order can wait. Today is CKA. Do not spend this clock on AppArmor or seccomp. 08-25 closed Cluster Hardening Q04. Leave the flags there.
08-22 already spent Storage Q1 and Q14. 08-10 already spent Troubleshooting 30% including node NotReady. 08-04 already spent Cluster Architecture access control. 07-29 already spent Services. The unopened CKA surface on this arc is the rollout.
The day's Ops lesson is EKS: maxSurge as extra Pods on one cluster, not a second control plane. Poulton already told you a second ReplicaSet is how an image moves (Ch. 6, printed p. 64). The exam is not hosted. The exam is kubeadm. This file edits a Deployment and watches ReplicaSets. The fleet cannot grade you on aws eks create-cluster. The exam will not give you a second API. Learn both. Grade this file on the strategy block.
Coin it: the surge that is not a second cluster.
§II — Domain foundations
Workloads and Scheduling is 15%. 08-16 spent the Scheduling half. Four App Lifecycle moves remain.
- Declare a Deployment.
apps/v1. Selector matches template labels. Selector is immutable (Poulton Ch. 6, printed p. 73). - Change the Pod template. Image, env, resources, a sidecar. The change starts a rollout. Pods are replaced, not edited (Ch. 6, printed p. 71).
- Control the walk.
strategy.typeisRollingUpdateorRecreate.maxSurgeandmaxUnavailableare number or percent (K8sUR3 Ch. 9, pp. 157-159). - Observe and reverse.
kubectl rollout status.kubectl rollout history.kubectl rollout undo. Undo is an update in reverse (Poulton Ch. 6, printed p. 76).
Q18 spends move 2 and the availability clause of move 3 in one stem. The candidate patches CPU and memory with kubectl patch only. The Deployment must remain available at 2 replicas. The patch writes the template. The template change starts RollingUpdate. Availability is maxUnavailable, not a cloned control plane.
Q3 spends move 2 as a sidecar add. Adding busybox:stable with tail -F is a template change. A rollout starts. If the stem does not mention maxUnavailable, the default 25% is the floor. Do not switch to Recreate to "make the sidecar appear faster."
Q5 spends a different knob. HPA changes spec.replicas. RollingUpdate changes the template at a given replica count. 08-16 already taught that HPA does not place Pods. Today: HPA does not replace Pods for a new image. If both fire, CURRENT climbs and you will not know which loop did it.
Poulton's request of the app is two properties (Ch. 6, printed p. 63). Loose coupling via APIs. Backward and forward compatibility. K8sUR3 spends the same tax on the JavaScript client that called v2 (Ch. 9, pp. 155-156). The exam will not grade your API design. The exam will grade whether you left 2 replicas Available while the template changed.
Hold the three numbers in your head before you touch YAML. Desired is spec.replicas. Floor is desired minus maxUnavailable (or desired minus ceil(percent * desired)). Ceiling is desired plus maxSurge. A legal walk stays inside that band. A CURRENT of desired+maxSurge is success. A CURRENT of 2*desired with maxSurge 25% is a second controller (often HPA) or a second Deployment you did not mean to apply. Count Deployments before you count clusters.
minReadySeconds is how you keep a bad image from eating the set. Ten seconds in the book is a classroom number. If the stem gives you 30, use 30. If the stem is silent, do not invent a 300. Defaults exist. Changing a field the stem did not name is how Q18's "do not change requests" trap generalizes.
Recreate is the trap (Ch. 9, p. 155). It terminates every Pod, then builds the new image. Fast. Downtime. If the stem says "remain available," Recreate is a fail. If the stem is silent and the Service is public, Recreate is still a fail in production. On the exam, read the stem.
K8sUR3 p. 159: maxSurge 100% with maxUnavailable 0 is in-cluster blue/green. New set rises to the old count. Old set drops to zero. That is still one Deployment. That is the surge that is not a second cluster. If a practice prompt says "blue/green," check whether they want this pair of fields or a second object. The CKA wants the fields.
§III — Mechanism: the walk the exam can see
Create the object the way the book does. Then change one line.
apiVersion: apps/v1
kind: Deployment
metadata:
name: hello-deploy
spec:
replicas: 10
revisionHistoryLimit: 5
progressDeadlineSeconds: 300
minReadySeconds: 10
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
selector:
matchLabels:
app: hello-world
template:
metadata:
labels:
app: hello-world
spec:
containers:
- name: hello-pod
image: nigelpoulton/k8sbook:1.0
ports:
- containerPort: 8080
Poulton's printed pp. 65-66 are this block. revisionHistoryLimit: 5 keeps five old ReplicaSets. progressDeadlineSeconds: 300 is five minutes per new replica before Progressing goes False. minReadySeconds: 10 waits after Ready before the next replacement. maxUnavailable 1 and maxSurge 1 on desired 10 means you never sit below 9 or above 11. The walk moves two Pods at a time (Ch. 6, printed p. 72).
Change the image to nigelpoulton/k8sbook:2.0. Apply. --record is how the book stamps history. The flag is deprecated in newer kubectl and the annotation still works if you set kubernetes.io/change-cause yourself. The exam accepts either so long as rollout history shows two revisions.
kubectl apply -f deploy.yml
kubectl rollout status deployment hello-deploy
kubectl get rs
kubectl get deploy hello-deploy
Expected mid-walk: CURRENT 11, UP-TO-DATE climbing, two ReplicaSets. Poulton's table is DESIRED 10, CURRENT 11, UP-TO-DATE 5, AVAILABLE 11 (Ch. 6, printed p. 73). If AVAILABLE drops under 9, you broke the floor. Pause.
kubectl rollout pause deployment hello-deploy
K8sUR3 Ch. 9, p. 151: pause, inspect, resume. If the new Pods are CrashLoop, do not resume. Undo.
kubectl rollout undo deployment hello-deploy --to-revision=1
Undo uses the same maxUnavailable and maxSurge. It is not instant (Ch. 6, printed p. 76). Watch status again. Then edit the YAML so the next apply does not re-fight the undo. The exam grades the cluster, not your git. Your later Friday grades both.
kubectl rollout history deployment hello-deploy --revision=2 prints the Pod template for that revision (K8sUR3 Ch. 9, p. 151). Read the image line. Read the env. Read the resources. Undo to a revision you have read, not to a number you like. Revision 1 is not "safe" if revision 1 was the LabSetUp broken image.
If status hangs, do not Ctrl+C and walk away. The walk continues. kubectl get deploy and kubectl get rs are the mid-walk instruments. rollout status is a waiter. A waiter that you kill is not a rollback. Pause is the stop. Undo is the reverse. Delete of the Deployment is the nuclear option and it takes the Service's endpoints with it if the selector dies.
Q18's patch is the other way to start this walk.
kubectl patch deployment resource-app -n patch-ns \
--type=strategic \
-p '{"spec":{"template":{"spec":{"containers":[{"name":"nginx","resources":{"limits":{"cpu":"500m","memory":"512Mi"}}}]}}}}'
SolutionNotes: strategic merge matches the container by name. Requests stay 100m / 128Mi. Merge type that replaces the whole limits object still works if you include every limit. kubectl edit is banned by the stem. kubectl apply is banned by the stem. After the patch, kubectl get deploy resource-app -n patch-ns must still show 2 available. If you set strategy.rollingUpdate.maxUnavailable to 2 on a desired of 2, you may dip to 0. That fails the stem. Leave the strategy at default 25% unless the stem asks you to change it. 25% of 2 is 1 after rounding. One Pod may be down. One Pod stays Available. That is the floor.
§IV — Exam traps
Trap 1: Recreate for speed. The sidecar in Q3 "is not showing up." You set strategy.type: Recreate. The new Pods appear. The Service went dark. If the stem wanted availability, you failed. If the stem was silent, you still taught your hands a bad default.
Trap 2: scale instead of roll. You need a new image. You kubectl scale --replicas=20, then delete old Pods by hand. That is not RollingUpdate. That is a human ReplicaSet. HPA Q5 will fight you. The history will not have a revision for the image.
Trap 3: second cluster thinking. A practice blog says blue/green means two kubeconfigs. On CKA, blue/green is maxSurge 100% and maxUnavailable 0 (K8sUR3 p. 159). One context. Two ReplicaSets. If you spend twelve minutes creating a kind cluster, you will miss Q18.
Trap 4: editing a live Pod. kubectl edit pod hello-deploy-xxxx to change the image. The ReplicaSet reverts it. The Deployment is the object. The Pod is the evidence.
Trap 5: changing the selector. You rename a label to "match the new app." The selector is immutable. The apply fails. Or worse, you created a second Deployment that selects nothing. Leave the selector. Change the image.
**Trap 6: forgetting --record and then guessing revisions.** rollout history without a change-cause still numbers revisions. rollout history --revision=2 shows the Pod template. Read the image. Do not undo to 1 because 1 is "the first one" if 1 is the bad apply.
Trap 7: Q18 merge that drops requests. You used a merge patch and sent only limits. Requests vanished. The scheduler packs differently. 08-16 already failed a Pod for requests. Today the stem said do not change requests. Include them or use strategic.
§V — Connection to today's Ops and Dev
Ops coined the surge that is not a second cluster on EKS. ALB targets. Karpenter adding a node. Node group updateConfig.maxUnavailable as the wrong object. The exam will not give you those. The exam will give you kubectl get rs. Same two sets. Same floor.
Dev is the Python census. AppsV1Api. Print desired, current, updated, available. Do not patch. Q18 is the write Dev refuses. If you finish this file by pasting Dev's loop into the exam cluster, you will list the leftover and not change it. The stem wants the change. Stay in kubectl.
08-16 is the sibling domain file. Taints and PriorityClass decide whether the new surge Pod binds. A rollout that stalls on Pending is a scheduler problem. kubectl describe pod on the new set. If the event is FailedScheduling, open 08-16. If the event is Unhealthy on the probe, stay here.
08-10 is the sibling when the node is NotReady. A surge that cannot schedule because half the nodes are NotReady is Troubleshooting. Do not raise maxSurge to 100% to "get around" a dead kubelet.
08-25 is CKS. Anonymous-auth does not start a rollout. Do not open the static Pod.
08-22 is Storage. A rolling update of a Deployment that mounts a Retain PV will still replace the Pod. The volume is the leftover 08-22 named. If the stem is a stateless image change, do not touch the PVC. If the stem is a StatefulSet, you are in a different updateStrategy and a different Friday.
The EKS overlay lives in Ops. Remember one sentence of it so a cloud-flavored practice item does not steal the clock: the ALB target group growing by one IP is maxSurge working. aws eks create-cluster is not a CKA verb. If a vendor lab asks you to stand up a second managed cluster for a new tag, you are no longer in this blueprint.
§VI — Practice questions
hello-deploy desired 10, strategy maxUnavailable 1, maxSurge 1. You apply image 2.0. Mid-walk kubectl get deploy shows CURRENT 11, UP-TO-DATE 5, AVAILABLE 11. Are you over the floor?kubectl get rs for the second set.strategy.type: Recreate so the new image appears in one step. The Service drops to 0 endpoints for 40 seconds. Pass?kubectl edit the Deployment and set cpu limit 500m, memory limit 512Mi. Requests unchanged. Two replicas stay Available. Verify.bash greps for a patch event. Pass?maxUnavailable: 2 on a desired of 2 because "it will finish faster." During the walk AVAILABLE is 0. Pass?kubectl rollout status hangs. You raise maxSurge to 50%. The new Pods are still Pending. What file owns this, and what do you run first?kubectl describe pod on a new-set Pod. If FailedScheduling, check requests, taints, PriorityClass. maxSurge adds more Pending. It does not add a node on the exam.§VII — Close
Four moves. Declare. Change the template. Control the floor. Undo. Q18 is a patch that must keep 2 Available. Q3 is a sidecar that starts the same walk. Q5 is scale, not replace. Recreate is downtime. maxSurge 100% is blue/green inside one object.
Examine well. Two ReplicaSets is the pass. A second cluster is the blog.
Related
- Prior arc: CKA Workloads and Scheduling (2026-08-16)
- Domain hub: Cross-References/Certifications-Roadmap
- Grounding tome: Poulton Ch.6, Kubernetes Deployments, pp. 64-76