Exam CKA Topic 4 Question 75 Discussion

Actual exam question for Linux Foundation's CKA exam
Question #: 75
Topic #: 4
You have a Kubernetes cluster with a service account named "my-sa" in the "my-namespace" namespace. You need to grant the service account the ability to read and write secrets in the "my-namespace" namespace and the ability to create pods in that namespace.
Create a Role and RoleBinding to achieve this using kubectl commands.

Suggested Answer:

See the solution below with Step by Step Explanation.
Explanation:
Solution (Step by Step) :
1 . Create the Role: Use the following command to create a role called 'sa-secret-pod-writer' in the 'my- namespace' namespace:
kubectl create role sa-secret-pod-writer--namespace=my-namespace --verb=get--verb=list --verb=watch verb=create --verb=update --verb=delete --verb=patch --resource=secrets --resource=pods --api-groups=""
2. Create the RoleBinding: Bind the role to the service account using the following command:
kubectl create rolebinding sa-secret-pod-writer-binding --namespace=my-namespace --role=sa-secret-pod- writer --serviceaccount=my-namespace:my-sa
3. Verify Access: Try running a pod using the service account "my-sa" in the "my-namespace" namespace. You should be able to successfully create the pod and access secrets within the namespace. You can test this by creating a pod definition with the 'serviceAccountName: my-sa' and include a volume mount to a secret within the "my-namespace" namespace.,

by Mick at Apr 13, 2025, 11:45 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10