8.8 KiB
CKS Edition — Resources & Sprint Plan
Owner: freshly-minted CKA (81%, v1.35 curriculum), prod SRE Mission: CKS while the cluster-surgery fingers are still warm Doc status: v0.1 — living document Operating mode unchanged: DRILL > read. Type first, autopsy second.
1. Ground truth
| Item | Value |
|---|---|
| Prerequisite | Valid-at-any-point CKA — ✅ you qualify twice over |
| Format | 15–20 tasks (typically ~16), 120 min, PSI remote proctored |
| Passing score | 67% (one point higher than CKA) |
| Exam version | Tracks latest k8s minor — verify at booking |
| Voucher includes | 1 free retake + 2 killer.sh CKS sessions |
| killer.sh CKS quirk | Both sessions have IDENTICAL questions (unlike CKA's A/B split) — changes the protocol, see §4 |
| Curriculum revision | Oct 2024 — courses/notes older than that are poison |
Domains (post-2024 weights)
- Cluster Setup — 10%
- Cluster Hardening — 15%
- System Hardening — 15%
- Minimize Microservice Vulnerabilities — 20%
- Supply Chain Security — 20%
- Monitoring, Logging & Runtime Security — 20%
Allowed docs (broader than CKA — this is a gift)
- kubernetes.io/docs + kubernetes.io/blog
- Third-party tool docs for exam-covered tools: Falco, Trivy, AppArmor (etc. — verify exact list on the LF exam-resources page at booking)
- One extra browser tab, same PSI environment as CKA — you know the desk already
2. Resource stack — ranked for YOUR situation
Tier 1 — the spine (use all three)
1. KodeKloud CKS course (Mumshad) — primary, already in your sub, fully updated for the Oct-2024 revision. Usage: unlike your CKA re-sit, this is NEW material — watch + lab for everything except RBAC/NetworkPolicy/ServiceAccount sections (skim-lab those; you just aced them). The community verdict is consistent: KodeKloud CKS alone covers what the exam requires.
2. Kim Wüstkamp's free CKS course (YouTube) + Killercoda CKS scenarios (free) — the resource CKA prep didn't have an equivalent of. Made by the killer.sh author, so it's tuned to exactly how the simulator (and therefore the exam) phrases things. Usage: Killercoda scenarios as your DAILY drill snack — browser-based, zero setup, one scenario per coffee. The video course as second-angle explanation when a KodeKloud topic doesn't click (Falco rules and AppArmor profiles are the usual candidates).
3. killer.sh CKS sessions (with voucher) — same diagnostic role as before, one protocol change (§4).
Tier 2 — in your sub, use selectively
KodeKloud "CKS Challenges" — scenario-based hardening gauntlets (attack-then-defend style). Excellent as the bridge between course labs and mocks; run these AFTER the course, BEFORE killer. KodeKloud Ultimate CKS Mock Exam Series — auto-scored mocks mapped to curriculum proportions. Same role as the CKA Ultimate mocks: volume + speed gate before killer. Same caveats as before: question-bank recycling on repeats, occasional wrong answers — grade skeptically.
Tier 3 — reference, not courses
- Official curriculum repo (github.com/cncf/curriculum) — read the CKS PDF once; it's the contract.
- kube-bench / CIS benchmark output — you don't study CIS docs; you run kube-bench and learn to read its remediation text (that's the exam skill).
- Community question repos (e.g. the killer.sh-style GitHub collections) — mine for extra drill ideas ONLY after killer; don't let 2020-era questions teach you PSP or other dead APIs.
Skip
- LFS260 (official LF course) — fine content, but redundant with KodeKloud at extra cost.
- Any material predating Oct 2024 revision without an update note. PSP, old dashboards — dead ends.
- Paid mock bundles beyond what's above. Volume is already covered.
3. The delta (what CKA didn't teach you)
Tiered by exam weight × your unfamiliarity:
Tier 1 — new tools, guaranteed presence, drill until boring
- Falco (Runtime, 20% domain) — read/write rules, find the offending pod from log output, output_fields formatting,
falco.yamlconfig, service restart flow. Killer's classic: "collect logs in EXACTLY this format." - Trivy (Supply chain, 20%) — image scanning, filtering by CVE ID/severity, scanning many images fast (
k get pods -o jsonpath→ loop trivy) - AppArmor + seccomp (System hardening) — load a profile on the node (
apparmor_parser), reference viasecurityContext.appArmorProfile(post-1.30 field, NOT the old annotation — revision trap), seccompRuntimeDefault+ custom Localhost profiles - Audit logging — write an audit policy (levels, rules, omitStages), wire
--audit-*flags + volumes into the apiserver static pod, grep/jq the log - Admission for images — ImagePolicyWebhook flag/config plumbing; plus awareness of OPA Gatekeeper/Kyverno constraint shapes
Tier 2 — extensions of what you know
- Pod Security Admission — namespace labels, enforce/audit/warn, baseline vs restricted (you know the concept; drill the label syntax cold)
- SecurityContext deep cuts — runAsNonRoot, readOnlyRootFilesystem, capabilities drop/add, privileged escalation chain
- NetworkPolicy expert tier — default-deny both directions + selective holes; you're already strong, push to speed
- RBAC hardening — minimize/audit existing permissions (reverse of creating them), SA token automounting off, bound tokens
- Secrets encryption at rest — EncryptionConfiguration, apiserver flag, re-encrypt existing secrets
- TLS/cert hygiene — apiserver TLS versions/ciphers flags, kubelet authn/authz flags (the x509 muscle from CKA transfers directly)
- RuntimeClass / gVisor — define RuntimeClass, run pod under runsc, verify via
dmesg/uname trick - kube-bench — run, read, remediate selected findings on CP node
- mTLS / ServiceMesh awareness — curriculum mentions it at concept level; don't over-invest
Tier 3 — CKA muscle that transfers as-is
Static pod surgery, kubeadm layout, etcd, kubeconfig triage, netpol, RBAC creation, jsonpath — all directly reusable. Your v2 mock pack was secretly half CKS prep.
4. killer.sh protocol — CHANGED for CKS
Both CKS sessions are identical (same 17 questions), unlike CKA's different A/B sets. So:
- Session 1 (T-14 to T-10): full 120-min diagnostic, exam conditions. Then the 34h autopsy: every solution, re-solve misses.
- Session 2 (T-3): it's a RETAKE of the same paper — the goal is not discovery but fluency: target 90%+ and finishing with 20+ min spare. It measures whether the patch work landed, not whether you'd pass cold.
- Between them: Killercoda scenarios + KodeKloud mocks fill the novelty gap that CKA's different-question session 2 used to provide.
5. Sprint plan — 3 weeks (CKA-holder pace)
Week 1 — Tooling assault
- D1–2: Falco (KodeKloud section + labs + 2 Killercoda scenarios)
- D3: Trivy + supply chain (image digests, allowed registries via policy)
- D4: AppArmor + seccomp end-to-end (node profile → pod reference → verify)
- D5: Audit logging (policy authoring + apiserver wiring — this is static-pod surgery you already own)
- Weekend: PSA + SecurityContext + secrets encryption; first KodeKloud CKS mock, untimed, to map the terrain
Week 2 — Integration
- D1: kube-bench + apiserver/kubelet hardening flags
- D2: ImagePolicyWebhook + admission landscape
- D3: RuntimeClass/gVisor + RBAC minimization drills
- D4–5: KodeKloud CKS Challenges (the attack/defend gauntlets)
- Weekend: killer.sh CKS session 1 under full exam law → miss list → Claude drill pack CKS-edition gets built from it
Week 3 — Sharpen + sit
- D1–3: drills on session-1 misses; Ultimate CKS mocks timed until <100 min clean
- D4: killer.sh session 2 (the fluency retake — 90%+ or investigate)
- D5–6: docs-navigation reps on Falco/Trivy/AppArmor sites (new allowed domains = new muscle), light review
- D7: EXAM
Range note: the kind+Cilium drills cluster handles ~70% of CKS drilling (netpol, PSA, securityContext, RBAC, audit-policy authoring, RuntimeClass definitions, trivy/kube-bench runs). AppArmor/Falco/gVisor need real node access — kind containers can host trivy and kube-bench fine, AppArmor partially (host kernel dependent); use KodeKloud labs/Killercoda for the kernel-adjacent stuff rather than fighting the range.
6. Booking checklist
- CKS purchased (includes retake + 2 killer sessions)
- Exam date booked: ______ (target: ~3.5 weeks out, per sprint)
- killer.sh CKS sessions visible in portal
- LF allowed-resources page re-checked at booking (tool-docs list)
- Dog scheduled for grandma's house on exam day — non-negotiable line item
7. Changelog
- v0.1 — initial: ground truth, ranked resource stack, delta inventory, killer protocol correction, 3-week sprint.