- Course
Certified Kubernetes Administrator (CKA): Troubleshooting Workloads, Services, and Resource Usage
CKA troubleshooting tasks test logs, service debugging, and the new ephemeral containers. This course completes the Troubleshooting domain with workload and networking diagnosis
- Course
Certified Kubernetes Administrator (CKA): Troubleshooting Workloads, Services, and Resource Usage
CKA troubleshooting tasks test logs, service debugging, and the new ephemeral containers. This course completes the Troubleshooting domain with workload and networking diagnosis
Get started today
Access this course and other top-rated tech content with one of our business plans.
Try this course for free
Access this course and other top-rated tech content with one of our individual plans.
This course is included in the libraries shown below:
- Core Tech
What you'll learn
Troubleshooting workloads and networking is the final layer of CKA troubleshooting mastery. In this course, Certified Kubernetes Administrator (CKA): Troubleshooting Workloads, Services, and Resource Usage, you'll gain the ability to systematically diagnose and repair pod failures, service connectivity issues, network policies that block traffic, and DNS resolution failures. You'll also learn the new ephemeral containers and native sidecar debugging patterns introduced in Feb 2025. First, you'll master container output analysis. You'll read kubectl logs for single-container and multi-container pods, understand container states (Waiting, Running, Terminated) and their failure reasons (CrashLoopBackOff, ImagePullBackOff, OOMKilled, CreateContainerConfigError). You'll diagnose init container failures and use kubectl describe pod to correlate events with failures. [Exam: Manage and evaluate container output streams] Next, you'll troubleshoot services and networking systematically. You'll diagnose service selector mismatches that leave endpoints empty, trace targetPort misconfiguration, understand how NetworkPolicy blocks traffic, detect DNS resolution failures in CoreDNS, and fix Ingress backend misconfigurations. You'll follow the complete connectivity debugging pattern: does the pod exist; does the service have endpoints; can the pod reach the service IP; is NetworkPolicy blocking it; does DNS work. [Exam: Troubleshoot services and networking] Finally, you'll explore the new ephemeral containers and native sidecar container debugging features. kubectl debug lets you attach an ephemeral container to a running pod without redeploying it; this is essential for debugging distroless containers where there's no shell. kubectl debug --copy-to creates a copy of a pod with a debug container attached. Native sidecar containers, introduced in Feb 2025, let you add persistent debug sidecars that restart with the pod. You'll build the pattern: distroless pod breaks; attach an ephemeral container; investigate from inside; fix the issue. [Exam: Apply ephemeral containers and native sidecar patterns to debug running workloads without redeployment] When you're finished with this course, you'll have the complete troubleshooting skillset needed to diagnose and repair workload and networking failures on production Kubernetes clusters, handle all 5 competencies in the 30% Troubleshooting domain on the CKA exam, and debug modern containerized applications including distroless containers that would have been impossible to troubleshoot just a few years ago.