CKA in 2026: What's Changed and What Hasn't
The Certified Kubernetes Administrator (CKA) exam remains the gold standard for proving Kubernetes operational competence. As someone who's written books on Kubernetes and trains enterprise teams, I see the CKA as more than a credential — it's a structured way to ensure you actually understand how Kubernetes works under the hood, not just how to copy YAML from Stack Overflow.
This guide reflects the current 2026 exam format and curriculum.
Exam Format Overview
- Duration: 2 hours
- Format: Performance-based (hands-on tasks in real Kubernetes clusters)
- Passing score: 66%
- Retake: One free retake included
- Environment: Remote proctored, PSI bridge
- Resources allowed: kubernetes.io/docs, kubernetes.io/blog, github.com/kubernetes (open during exam)
- Cost: $395 USD (includes one retake)
- Validity: 2 years
Curriculum Domains and Weights
25% — Cluster Architecture, Installation & Configuration
- Manage role-based access control (RBAC)
- Use kubeadm to install a basic cluster
- Manage a highly available Kubernetes cluster
- Provision underlying infrastructure to deploy a cluster
- Perform a version upgrade on a cluster using kubeadm
- Implement etcd backup and restore
Study tip: Practice kubeadm cluster creation from scratch at least 5 times. etcd backup/restore is almost guaranteed on the exam.
15% — Workloads & Scheduling
- Understand deployments and rolling updates/rollbacks
- Use ConfigMaps and Secrets
- Know how to scale applications
- Understand resource limits and pod scheduling (nodeSelector, affinity, taints, tolerations)
- Awareness of manifest management and templating tools
Study tip: Master kubectl create deployment, kubectl set image, and kubectl rollout — speed matters on the exam.
20% — Services & Networking
- Understand host networking configuration on cluster nodes
- Understand connectivity between Pods
- Understand ClusterIP, NodePort, LoadBalancer service types
- Know how to use Ingress controllers and Ingress resources
- Know how to configure and use CoreDNS
- Choose an appropriate container network interface plugin
Study tip: NetworkPolicies are frequently tested. Practice creating policies that allow/deny specific traffic patterns.
10% — Storage
- Understand storage classes, persistent volumes (PV), and persistent volume claims (PVC)
- Understand volume mode, access modes, and reclaim policies
- Know how to configure applications with persistent storage
30% — Troubleshooting
- Evaluate cluster and node logging
- Understand how to monitor applications
- Manage container stdout and stderr logs
- Troubleshoot application failure
- Troubleshoot cluster component failure
- Troubleshoot networking
Study tip: This is the largest domain. Practice debugging broken clusters: kubelet not starting, certificates expired, etcd unavailable, DNS not resolving, pod networking broken.
8-Week Study Plan
- Weeks 1-2: Cluster architecture + kubeadm installation. Build and tear down clusters repeatedly.
- Weeks 3-4: Workloads, scheduling, and storage. Create every resource type from kubectl and YAML.
- Weeks 5-6: Networking and services. Master NetworkPolicies, Ingress, and DNS troubleshooting.
- Weeks 7-8: Troubleshooting + full practice exams. Use killer.sh (included with exam purchase) for realistic practice.
Daily practice: 1-2 hours hands-on in a real cluster. Reading docs without typing commands doesn't prepare you for a performance-based exam.
Essential Tools and Resources
- Practice environment: kind (Kubernetes in Docker), minikube, or cloud-based labs
- killer.sh: Included with exam purchase — the closest simulation to the real exam
- kubectl aliases: Set up
alias k=kubectlandexport do="--dry-run=client -o yaml"— saves critical seconds - vim/nano proficiency: You'll edit YAML in the terminal. Be comfortable with your editor.
- Bookmarks: Pre-bookmark key docs pages — you can access kubernetes.io during the exam
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →From CKA to Enterprise Kubernetes
CKA validates that you can administer Kubernetes. But enterprise Kubernetes requires additional skills:
- Multi-cluster management — Fleet management, GitOps at scale, federation
- Security hardening — Pod security standards, OPA/Gatekeeper, network policies, supply chain security
- Observability — Prometheus, Grafana, distributed tracing, log aggregation
- Cost optimisation — Right-sizing, autoscaling, spot instances, FinOps
- Compliance — DORA, NIS2, SOC 2 controls on Kubernetes platforms
These are the skills we help enterprises build. CKA is the foundation — what you build on it determines your career trajectory.
Luca Berton