Skip to main content

The Linux Foundation / CNCF exam preparation

Certified Kubernetes Administrator (CKA)

Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises in a real terminal and practice exams.

The operator exam. You are given a live cluster and a command line, and asked to fix, configure and recover it under time pressure.

Lessons, quizzes and hands-on practice across every CKA objective, added to your roadmap. Free account.
Not ready to start? Tell us you want it and nothing else changes.

What you'll learn

Every objective CKA publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.

  • Troubleshooting (30% of the exam)Manage and evaluate container output streams. Monitor cluster and application resource usage. Troubleshoot services and networking. Troubleshoot cluster components. Troubleshoot clusters and nodes.
  • Cluster Architecture, Installation and Configuration (25% of the exam)Manage role based access control (RBAC). Prepare underlying infrastructure for installing a Kubernetes cluster. Create and manage Kubernetes clusters using kubeadm. Implement and configure a highly-available control plane. Manage the lifecycle of Kubernetes clusters. Understand extension interfaces (CNI, CSI, CRI, etc.). And 2 more, each a topic in the course below.
  • Services and Networking (20% of the exam)Understand connectivity between Pods. Use ClusterIP, NodePort, LoadBalancer service types and endpoints. Understand and use CoreDNS. Know how to use Ingress controllers and Ingress resources. Use the Gateway API to manage Ingress traffic. Define and enforce Network Policies.
  • Workloads and Scheduling (15% of the exam)Understand the primitives used to create robust, self-healing, application deployments. Understand application deployments and how to perform rolling update and rollbacks. Use ConfigMaps and Secrets to configure applications. Configure Pod admission and scheduling (limits, node affinity, etc.). Configure workload autoscaling.
  • Storage (10% of the exam)Configure volume types, access modes and reclaim policies. Manage persistent volumes and persistent volume claims. Implement storage classes and dynamic volume provisioning.

Explore related topics

The exam at a glance

Length
2 hours
Cost
$445
Validity
2 years
Style
Hands-on

Online proctored, performance-based, solved entirely at a command line. Based on Kubernetes v1.35.

What to expect on the day

Confirmed 1 October 2026

Current detail on the CKA exam, beyond what its published format covers.

  • kubectl is already there as `k`, with Bash autocompletion configured, on every host a task sends you to. You do not set either up and you do not lose tab completion.
  • Nested ssh does not work: `exit` back to the base system, whose hostname is `base`, before you start the next task. `sudo -i` gets you root on any host.
  • Do not reboot the base node, whose hostname is `base`. Rebooting it does not restart the exam environment.
  • Copy and paste inside the terminal is Ctrl+Shift+C and Ctrl+Shift+V. Everywhere else on the desktop it is Ctrl+C and Ctrl+V.
  • Ctrl+W closes the browser tab instead of deleting a word, so the exam remaps it to Ctrl+Alt+W. The INSERT key is blocked outright: press `i` to get into vim's insert mode.
  • The environment runs Kubernetes v1.35, and is realigned to each new minor version within roughly 4 to 8 weeks of its release. Practise against the version you will actually sit.

Sitting the exam

The part nobody publishes in a syllabus. For CKA the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.

Where you sit it

  • Online proctored through PSI's Bridge platform. You sit it in a secure browser on your own machine and work inside a Linux remote desktop, so the cluster is never local.
  • The base node has no tooling on it. The work happens over SSH to the hosts each task names, where kubectl (aliased to k), yq, curl, wget and man pages are already installed.
  • One monitor. Dual monitors are not supported, virtual machines are not permitted, and no other application or browser window may be running.
  • A private walled room with the door closed, a clear desk with nothing on or under it, and nobody else present. Audio, video and your screen are streamed to a proctor for the full two hours, and you have to stay in the camera frame throughout.

What you are asked

  • 15 to 20 performance-based tasks in 2 hours. Nothing to recognise and nothing to select: you either make the cluster do the thing or you do not.
  • That is roughly 6 to 8 minutes a task on average, which is the number worth practising against. Reading a task, deciding it is expensive, and coming back to it is a skill in itself.

What you can look at

  • The Kubernetes documentation (kubernetes.io/docs), the Kubernetes blog (kubernetes.io/blog), the Helm documentation (helm.sh/docs) and the Gateway API documentation (gateway-api.sigs.k8s.io).
  • Searching within kubernetes.io/docs is allowed, but you must not open a search result that leads off it.
  • Documentation shipped on the exam machine under /usr/share, the distribution's own packages, and the task instructions in the terminal.
  • Because those pages are the only reference you get, practise with them open rather than from memory. Knowing where the manifest you need lives is part of the exam.

How it is marked

  • 66% or above is a pass.
  • A score report reaches you by email within 24 hours of finishing.

Identification and proctoring

  • One valid, unexpired, original government-issued photo ID, physically in your hand. Photocopies, photos of a document and electronic copies are all refused.
  • Accepted: an international travel passport, a government-issued driving licence or permit, a national identity card, a state or province identity card, an alien registration or permanent resident card, and in Japan the Basic Resident Register card or My Number card.
  • It has to carry your name, photo and signature. A government-issued biometric ID with no signature is accepted.
  • The first and last name on your Linux Foundation account must match the ID exactly. If the ID is in a non-Latin script, enter your name in that script rather than a transliteration.
  • Check-in includes uploading a picture of the ID. Being assigned a check-in specialist should take no more than 15 minutes, so start early.

If you do not pass

  • One retake is included in the exam price, granted when the first attempt is graded as not passed. It is not a second exam you buy.
  • The retake has to be taken within 12 months of the original purchase, or before a corporate subscription expires, whichever comes first.
  • Registrations sold as SINGLE or SINGLE-ATTEMPT get one attempt and no simulator. Check which one you are buying.
  • Bought through an authorised training partner? Retake eligibility is the partner's to confirm, not the Linux Foundation's.

Booking it

  • 12 months from purchase to schedule and sit it. The clock starts when you pay, not when you book.
  • $445 for the exam alone. The Linux Foundation also lists it bundled with a subscription at $625 and with a course at $645.
  • You accept the Linux Foundation Global Certification and Confidentiality Agreement at registration and again before testing. Declining it ends the exam and the fee is not refunded.

What comes with it

  • Two exam simulator attempts from Killer.sh, each giving 36 hours of access from the moment you activate it. Candidates routinely never claim these.
  • The simulator's questions are the same for every attempt and every candidate, unlike the real exam. Treat it as a rehearsal of the environment and the clock, not a preview of the tasks.

Read off the official exam page on 25 August 2026. Rules change without notice, so confirm anything you are about to spend money on.

What the exam covers

Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.

Troubleshooting30%
Cluster Architecture, Installation and Configuration25%
Services and Networking20%
Workloads and Scheduling15%
Storage10%

Course content

27 topics

The control plane and worker node components that every later topic refers to: the API server, etcd, the scheduler, the controller manager, the kubelet and the container runtime.

The objects you work with all day and the tool you work with them through: pods, YAML manifests, namespaces and labels, applied and inspected with kubectl.

  • Understand the primitives used to create robust, self-healing, application deployments
  • Understand application deployments and how to perform rolling update and rollbacks
  • Use ConfigMaps and Secrets to configure applications
  • Configure Pod admission and scheduling (limits, node affinity, etc.)
  • Configure workload autoscaling
  • Manage and evaluate container output streams
  • Monitor cluster and application resource usage
  • Understand connectivity between Pods
  • Use ClusterIP, NodePort, LoadBalancer service types and endpoints
  • Understand and use CoreDNS
  • Know how to use Ingress controllers and Ingress resources
  • Use the Gateway API to manage Ingress traffic
  • Define and enforce Network Policies
  • Troubleshoot services and networking
  • Configure volume types, access modes and reclaim policies
  • Manage persistent volumes and persistent volume claims
  • Implement storage classes and dynamic volume provisioning
  • Manage role based access control (RBAC)
  • Prepare underlying infrastructure for installing a Kubernetes cluster
  • Create and manage Kubernetes clusters using kubeadm
  • Implement and configure a highly-available control plane
  • Manage the lifecycle of Kubernetes clusters
  • Understand extension interfaces (CNI, CSI, CRI, etc.)
  • Understand CRDs, install and configure operators
  • Use Helm and Kustomize to install cluster components
  • Troubleshoot cluster components
  • Troubleshoot clusters and nodes

What to know before you start

  • Comfortable in a Linux shell without looking up basic commands
  • Containers and images as everyday tools, not new concepts
  • Reading and editing YAML quickly
  • Basic networking: DNS, routing, ports

Further reading

Other The Linux Foundation / CNCF certifications

All The Linux Foundation / CNCF certifications

Frequently asked questions

How much does the CKA exam cost?

$445. Confirm it on The Linux Foundation / CNCF's page before you book: exam fees change.

How long is the CKA exam?

2 hours. Online proctored, performance-based, solved entirely at a command line.

How many questions are on the CKA exam?

15 to 20 performance-based tasks in 2 hours. Nothing to recognise and nothing to select: you either make the cluster do the thing or you do not. Check the current count with The Linux Foundation / CNCF before you book.

How long is CKA valid?

2 years. Check The Linux Foundation / CNCF's recertification route before it lapses.

Is the CKA exam hands-on?

Yes. It is performance-based: you are given a live environment and a command line, and marked on what you actually do rather than what you can recognise. Reading alone does not prepare you for it.

What is on the CKA exam?

5 domains. The heaviest is Troubleshooting at 30% of the exam, so it is the one worth over-preparing.

What should I know before starting CKA?

Comfortable in a Linux shell without looking up basic commands. Containers and images as everyday tools, not new concepts. Reading and editing YAML quickly. Basic networking: DNS, routing, ports.

CKA vs CKAD: what is the difference?

CKA: 2 hours, $445, hands-on. CKAD: 2 hours, $445, hands-on. Both are The Linux Foundation / CNCF exams with their own guide on this site.

Exam details from The Linux Foundation / CNCF, checked August 2026. Always confirm on their page before booking.

What learners say about Acelro

About Acelro rather than the CKA exam: what learners made of the gap analysis, the roadmap and the projects.

“The roadmap makes me focus on a learning curve, no matter the length.”
Daniel O., Career path navigation
“Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.”
Stephanie E., Learner
“The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.”
Cebuka B., Career changer

Not sure you are ready for CKA yet? Check where your skills stand in under a minute, no sign-up required.