Lộ trình
Cloud Native Computing FoundationAssociateTuần 4: Tối ưu & vận hànhBài 28 / 30

Ngày 28: Ôn tập tuần 4

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
ckadngày 28
hoàn thành28 / 30 bài
Bối cảnh bài học

Ôn tập tuần 4 bằng 10 timed Services & Networking labs: Service types, Ingress/TLS, NetworkPolicy, quota admission, CRD discovery và command speed với request-path evidence.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Ôn tập tuần 4 bằng 10 timed Services & Networking labs: Service types, Ingress/TLS, NetworkPolicy, quota admission, CRD discovery và command speed với request-path evidence.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Luyện lại Services and Networking
  • Làm 10 câu trắc nghiệm tự kiểm tra
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Networking failure thường nằm ở nhiều hop: quota chặn Pod, selector thiếu endpoint, Ingress controller/path sai, policy chặn DNS hoặc CRD/controller không reconcile. Bài tổng hợp buộc phân loại control-plane admission, object mapping và dataplane.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • Request path cần đi từ source/DNS/Ingress → Service → EndpointSlice → Pod/readiness → app; mỗi hop có command/evidence riêng.
  • Admission/quota/CRD/schema có thể chặn object trước dataplane; phân biệt API reject, controller failure và network connection failure.
  • Service type/Ingress/TLS/NetworkPolicy có scope/implementation dependency; local cluster/controller/CNI limitation phải ghi rõ.
  • Selector/namespace labels/ports/pathType/policy direction/DNS là common hidden variables; default deny và external path cần test từ đúng source.

Services & Networking review

Đi theo source/DNS → Ingress/controller → Service → EndpointSlice → Pod Ready → app, đồng thời kiểm tra gate trước đó: quota/LimitRange/API schema/CRD/controller. Selector/port/path/namespace labels, policy direction/DNS và TLS là các biến thường gây failure.

Scorecard

Mỗi lab chấm first useful command, domain classification, minimal remediation, real traffic/status proof, safety/cleanup và variant. Phân biệt API reject, controller reconcile failure, endpoint mapping và CNI/dataplane. Ghi limitation môi trường thay vì coi chưa test là pass.

Bài tập

Chạy 10 scenario timed, tạo lỗi đa hop, debug từ source đúng, replay variant, cập nhật gap list/cheat sheet và cleanup policy/Ingress/CR/Secret/namespace.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
kubectl config current-context
kubectl get svc,endpointslice,ingress,networkpolicy -n ckad-day28 -o wide
kubectl get events -n ckad-day28 --sort-by=.lastTimestamp
kubectl get resourcequota,limitrange -n ckad-day28
kubectl api-resources
kubectl run net-debug -n ckad-day28 --rm -it --restart=Never --image=curlimages/curl -- sh
Hands-on lab

Thực hành theo scenario

  1. Tạo namespace `ckad-day28`, chuẩn bị 10 scenario: (1) ClusterIP selector, (2) NodePort path, (3) ExternalName DNS, (4) Ingress host/path, (5) TLS secret, (6) NetworkPolicy default deny/DNS, (7) quota/LimitRange admission, (8) Endpoint/readiness, (9) CRD/controller discovery, (10) fast kubectl expose/patch/verify.
  2. Mỗi scenario ghi source/destination/expected response, namespace/context, timebox và cleanup; chạy request từ debug Pod khi cần, lưu EndpointSlice/Ingress/policy/events/quota/CRD evidence.
  3. Cố ý tạo ít nhất bốn lỗi selector/port/path/label/DNS/policy/quota/controller; sửa minimal, verify HTTP/DNS/allow-deny/rollout/status và tạo variant namespace/host/port/label.
  4. Chấm 5 điểm/lab: first useful evidence, root cause, fix, traffic/runtime proof, safety/cleanup. Ghi limitation nếu không có Ingress controller/CNI enforcement/LoadBalancer.
  5. Pass 8/10 không hint, không critical shared mutation, 10 worksheet đầy đủ và replay variant; cleanup Services/Ingress/Policies/CRs/Secrets/namespace theo owner.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • Đủ 10 Services/Networking scenario.
  • Request path và admission/controller/dataplane domain đúng.
  • Traffic/allow-deny/DNS/status evidence có proof.
  • Variant/score/time/limitation có dữ liệu.
  • Cleanup không phá shared controller/CNI/CRD.
Transfer to exam / production

Bẫy thường gặp và trade-off

Tuần 4 hãy vẽ path trước khi chạy lệnh. Nếu object bị reject xem admission; nếu endpoint rỗng xem selector/readiness; nếu endpoint có mà timeout xem policy/DNS/controller/path từ đúng source.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: Service có EndpointSlice ready nhưng Ingress trả 404 ở một host/path. Kiểm tra ưu tiên nào?

Kết thúc bài

Checklist trước khi sang Ngày 2