Lộ trình
Cloud Native Computing FoundationAssociateTuần 4: Tối ưu & vận hànhBài 27 / 30

Ngày 27: Ôn thao tác nhanh

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
ckadngày 27
hoàn thành27 / 30 bài
Bối cảnh bài học

Luyện thao tác kubectl tốc độ cao bằng 12 micro-drills: create/run/expose, dry-run YAML, patch/label/scale, context safety và final-state verification; xây cheat sheet có điều kiện dùng.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Luyện thao tác kubectl tốc độ cao bằng 12 micro-drills: create/run/expose, dry-run YAML, patch/label/scale, context safety và final-state verification; xây cheat sheet có điều kiện dùng.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Luyện lại các lệnh kubectl create, expose, run tốc độ cao
  • Tạo cheat sheet cá nhân cho kỳ thi
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Tốc độ thi không đến từ gõ lệnh mù: alias sai namespace, imperative defaults sai port/restart/image hoặc bỏ qua verify tạo lỗi tốn thời gian. Bài này rèn command selection, chuyển imperative output thành manifest và checkpoint an toàn.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • `run/create/expose` là generators nhanh; flags như restart, port/targetPort, replicas, labels, namespace và dry-run phải được explicit.
  • Cheat sheet nên map task wording → command skeleton → fields cần sửa → verification command → cleanup, không lưu output/secret phụ thuộc môi trường.
  • Context/namespace prompt, shell alias/function và file per task giúp tốc độ nhưng phải có guard; không dùng alias che target hoặc wildcard delete.
  • Dry-run client/server, diff, rollout/status/get/describe/events là checkpoint; command exit 0 không phải final-state evidence.

Speed protocol

parse target/context → choose generator → dry-run/edit → apply → verify → record. run/create/expose chỉ là skeleton; luôn kiểm tra restart policy, image, labels, ports, namespace, replicas và ownership.

Cheat sheet có chất lượng

Mỗi entry gồm task wording, command template, flags bắt buộc, default nguy hiểm, expected state, verify command và cleanup. Alias phải hiển thị target; không lưu secret/production context. Khi quá timebox, preserve evidence và chuyển task, không phá cluster để chạy lại.

Bài tập

Làm 12 micro-drill timed, replay variant và cập nhật cheat sheet. Chấm correctness/time/hint/safety/final evidence; cleanup namespace lab và review một entry để đảm bảo người khác dùng được.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
kubectl config current-context
kubectl create namespace ckad-day27
kubectl run web --image=nginx:stable --restart=Never --dry-run=client -o yaml
kubectl create deployment web --image=nginx:stable --replicas=2 --dry-run=client -o yaml
kubectl expose deployment web --port=80 --target-port=8080 --dry-run=client -o yaml
kubectl apply --dry-run=server -f manifest.yaml
kubectl get all -n ckad-day27 -o wide
Hands-on lab

Thực hành theo scenario

  1. Tạo namespace `ckad-day27`, chuẩn bị 12 micro-drill: run Pod, create Deployment, expose ClusterIP, generate YAML, label/annotate, scale, set image, patch resources/probe, ConfigMap/Secret, ServiceAccount, inspect events và cleanup.
  2. Trước mỗi drill ghi câu hỏi/target/context/expected state; chạy command tối thiểu, lưu YAML/output trong file task, dùng server dry-run khi mutation có rủi ro.
  3. Đặt timebox 2–4 phút/drill, checkpoint sau 4/8/12; nếu fail ghi evidence rồi chuyển tiếp. Verify bằng get/describe/rollout/endpoints/conditions/auth can-i tùy task.
  4. Tạo variant đổi namespace/label/port/container name/image/replicas để phát hiện shortcut không tổng quát; cập nhật cheat sheet thành syntax + caveat + verify.
  5. Cleanup chỉ namespace lab/resources có owner, kiểm tra không còn orphan/secret/token; không đưa credential, production context hoặc dangerous alias vào cheat sheet.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • Đủ 12 drill và timebox có ghi.
  • Imperative flags/defaults được hiểu, YAML output valid.
  • Context/namespace/verification checkpoint đầy đủ.
  • Cheat sheet có caveat/variant, không chỉ command dump.
  • Safety/cleanup không có wildcard/shared mutation.
Transfer to exam / production

Bẫy thường gặp và trade-off

CKAD speed: đọc target/namespace trước, dùng dry-run skeleton, sửa đúng field, verify ngay. Cheat sheet tốt luôn có “sau lệnh này kiểm tra gì?” và cảnh báo default/namespace.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: Một lệnh `kubectl expose` chạy thành công nhưng Service không route. Cách tránh lỗi tốc độ kiểu này là gì?

Kết thúc bài

Checklist trước khi sang Ngày 2