11 - Installing & Upgrading Clusters (kubeadm)
Why this matters
CKA tests this directly, and in the real world someone has to actually bootstrap and upgrade clusters that aren't managed (EKS/GKE handle control planes for you — self-managed clusters don't). Understanding kubeadm also demystifies what EKS is doing under the hood.
Read this first — Definitions & Explanations
kubeadm
The standard tool to bootstrap and upgrade Kubernetes clusters (control plane + join workers).
Control plane bootstrap
kubeadm creates certificates, static Pod manifests, and joins components so the API becomes available. Workers then kubeadm join with a token.
Upgrade order (rule of thumb)
Upgrade control plane first, then workers carefully (cordon/drain → upgrade → uncordon). Always read the version skew policy for your release.
Certificates
Kubernetes uses many TLS certs. Expired certs break API auth. Know where kubeadm stores them and how to renew.
cordon / drain
- cordon: mark node unschedulable
- drain: evict Pods safely before maintenance (respects PDBs)
Official docs (read for detail)
- Creating a cluster with kubeadm
- Upgrading kubeadm clusters
- Safely Drain a Node
- Certificate Management with kubeadm
Key Concepts
kubeadm init/kubeadm joinflow, join tokens, discovery- Certificate management (
kubeadm certs check-expiration, renewal) - Upgrade order: control plane first, then nodes, one minor version at a time
kubectl drain→ upgrade kubelet/kubeadm →kubectl uncordonper nodekubeadm upgrade plan/kubeadm upgrade apply- Version skew policy (kubelet can be older than API server, within limits)
YouTube search terms
- "kubeadm cluster setup from scratch"
- "Kubernetes cluster upgrade kubeadm step by step"
- "Kubernetes version skew policy explained"
Hands-on lab (on prod-sim)
Minikube abstracts kubeadm away, but you can still see it underneath and practice the drain/upgrade/uncordon workflow:
# See kubeadm's fingerprints
minikube ssh -p prod-sim
sudo kubeadm certs check-expiration
sudo kubeadm version
exit
# Practice the real-world drain -> maintain -> uncordon cycle
kubectl cordon prod-sim-m02
kubectl get nodes # SchedulingDisabled
kubectl drain prod-sim-m02 --ignore-daemonsets --delete-emptydir-data
kubectl get pods -o wide # confirm nothing (non-daemonset) is on m02 anymore
# ... this is the exact window where you'd patch/upgrade the node in the real world ...
kubectl uncordon prod-sim-m02
kubectl get nodes # Ready again
# For a REAL kubeadm upgrade experience (optional, separate throwaway VM/cluster,
# not minikube): spin up 2 Ubuntu VMs with multipass or on a cloud VM, install kubeadm
# at version N, `kubeadm init`, `kubeadm join`, then upgrade to N+1 following:
# https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-upgrade/
Notes
(fill in your own words after watching + labbing)