YOUR LEARNING PATH
CKAD: Application Developer Foundations
Build the core skills the Certified Kubernetes Application Developer exam tests, in order: workloads, Pod composition, configuration, resources, health, batch and networking — on a real cluster.
Your practice sequence
One exercise at a timePods and Deployments
NextCreate, scale and inspect workloads: the twenty-minute onramp.
BeginnerFree20 minConfigMaps and Environment
Separate config from code: store settings in a ConfigMap and inject them into a Deployment.
BeginnerFree15 minInjecting Secrets
Store sensitive configuration in a Secret and inject it into a workload as environment variables — never in plaintext.
BeginnerFree15 minResource Requests and Limits
Right-size a workload: set CPU and memory requests, then limits, and reach Guaranteed QoS.
BeginnerFree15 minHealth Probes
Tell Kubernetes when a Pod is ready for traffic and when to restart it: readiness and liveness probes.
BeginnerFree15 minExposing Workloads with Services
Front a Deployment with a Service so it has one stable address, and make the selector match its Pods.
BeginnerFree15 minRunning Work to Completion
Run a batch workload as a Job — once, and in parallel to a fixed number of completions.
BeginnerFree15 minScheduling Work with CronJobs
Schedule a recurring Job with a CronJob, then suspend it the way you'd pause a scheduled backup — without deleting it.
BeginnerPlus15 minLockedMulti-Container Pods
Run a helper alongside your app in the same Pod — the sidecar pattern — sharing the Pod's network and lifecycle.
IntermediatePlus20 minLockedInit Containers
Run setup logic to completion before your app starts, in an init container — and see why it isn't just another sidecar.
IntermediatePlus20 minLockedPod Metadata with the Downward API
Give a container its own identity — pod name, namespace, node and IP — through the Downward API instead of hardcoding it.
IntermediatePlus15 minLockedHardening Pods with securityContext
Drop a workload's privileges: run as non-root, forbid privilege escalation, make the root filesystem read-only, and drop all Linux capabilities.
IntermediatePlus20 minLockedDurable Storage with PVCs
Give a workload storage that survives a restart: claim a PersistentVolume and mount it, and understand why the claim only binds once a Pod needs it.
IntermediatePlus20 minLockedZero-Downtime Rolling Updates
Tune a Deployment's rollout strategy for zero downtime, then ship a new image version without dropping a request.
IntermediatePlus20 minLockedHTTP Routing with Ingress
Expose an internal Service to the outside world over HTTP with an Ingress rule — host, path and backend.
IntermediatePlus15 minLockedRestricting Traffic with NetworkPolicy
Lock a namespace down with a default-deny, then open one precise path with a from-and-port allow rule.
IntermediatePlus20 minLocked- Challenge
Ship a Web App
Exam-pace drill: in one sitting, wire up config, a resourced and probed Deployment, durable storage, a Service and an Ingress — each task fuses several skills, like the real thing.
AdvancedPlus30 minLocked - Challenge
Secure a Workload
Exam-pace drill: give a workload a scoped identity (ServiceAccount + RBAC), lock the container down, and isolate it with a NetworkPolicy — exact specs, costly hints, tight timer.
AdvancedPlus30 minLocked - Challenge
Rollout and Protect
Exam-pace drill: stand up a probed, rolling Deployment; ship a new version zero-downtime while scaling; then front it with a Service and protect it with a PodDisruptionBudget.
AdvancedPlus30 minLocked
Test yourself
Mock ExamTimed, scored under exam conditions. Take these once the tree feels solid.
60 min · Pro
60 min · Pro
60 min · Pro
45 min · Pro