⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 2 — Cluster Administration Module 11 of 24 Free & Open Access

Installing & Upgrading Clusters (kubeadm)

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

11 - Installing & Upgrading Clusters (kubeadm)

Why this matters

CKA tests this directly, and in the real world someone has to actually bootstrap and upgrade clusters that aren't managed (EKS/GKE handle control planes for you — self-managed clusters don't). Understanding kubeadm also demystifies what EKS is doing under the hood.

Read this first — Definitions & Explanations

kubeadm

The standard tool to bootstrap and upgrade Kubernetes clusters (control plane + join workers).

Control plane bootstrap

kubeadm creates certificates, static Pod manifests, and joins components so the API becomes available. Workers then kubeadm join with a token.

Upgrade order (rule of thumb)

Upgrade control plane first, then workers carefully (cordon/drain → upgrade → uncordon). Always read the version skew policy for your release.

Certificates

Kubernetes uses many TLS certs. Expired certs break API auth. Know where kubeadm stores them and how to renew.

cordon / drain

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

Minikube abstracts kubeadm away, but you can still see it underneath and practice the drain/upgrade/uncordon workflow:

# See kubeadm's fingerprints
minikube ssh -p prod-sim
  sudo kubeadm certs check-expiration
  sudo kubeadm version
  exit

# Practice the real-world drain -> maintain -> uncordon cycle
kubectl cordon prod-sim-m02
kubectl get nodes   # SchedulingDisabled
kubectl drain prod-sim-m02 --ignore-daemonsets --delete-emptydir-data
kubectl get pods -o wide   # confirm nothing (non-daemonset) is on m02 anymore
# ... this is the exact window where you'd patch/upgrade the node in the real world ...
kubectl uncordon prod-sim-m02
kubectl get nodes   # Ready again

# For a REAL kubeadm upgrade experience (optional, separate throwaway VM/cluster,
# not minikube): spin up 2 Ubuntu VMs with multipass or on a cloud VM, install kubeadm
# at version N, `kubeadm init`, `kubeadm join`, then upgrade to N+1 following:
# https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-upgrade/

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 11 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: kubeadm is primarily used to:
  • A. Bootstrap/upgrade Kubernetes clusters
  • B. Replace Helm
  • C. Run only serverless functions
  • D. Manage DNS exclusively
✓ Correct Answer: A (Bootstrap/upgrade Kubernetes clusters)
Option A ('Bootstrap/upgrade Kubernetes clusters') is the standard production architectural best practice.
Question 2: A common upgrade order caution is:
  • A. Control plane first, then workers (carefully)
  • B. Delete etcd first
  • C. Workers before control plane always with no plan
  • D. Upgrade by removing all CNI
✓ Correct Answer: A (Control plane first, then workers (carefully))
Option A ('Control plane first, then workers (carefully)') is the standard production architectural best practice.
Question 3: kubeadm join is used to:
  • A. Add a node to an existing cluster
  • B. Create a PVC
  • C. Install Helm
  • D. Issue Ingress certs
✓ Correct Answer: A (Add a node to an existing cluster)
Option A ('Add a node to an existing cluster') is the standard production architectural best practice.
Question 4: Certificate rotation matters because:
  • A. Control-plane certs expire and break auth
  • B. Pods cannot use DNS otherwise
  • C. CNI cannot allocate IPs
  • D. Helm charts refuse to install
✓ Correct Answer: A (Control-plane certs expire and break auth)
Option A ('Control-plane certs expire and break auth') is the standard production architectural best practice.
Question 5: drain/cordon before upgrading a node helps:
  • A. Evict workloads safely and stop new Pods
  • B. Delete etcd data
  • C. Disable RBAC
  • D. Force delete Namespaces
✓ Correct Answer: A (Evict workloads safely and stop new Pods)
Option A ('Evict workloads safely and stop new Pods') is the standard production architectural best practice.
← Previous Module (10) Control Plane Deep Dive Next Module (12) → Networking Deep Dive (CNI, NetworkPolicy)