Exam CKA Topic 4 Question 75 Discussion
Actual exam question for Linux Foundation's CKA exam
Question #: 75
Topic #: 4
Question #: 75
Topic #: 4
You have a Kubernetes cluster with a service account named "my-sa" in the "my-namespace" namespace. You need to grant the service account the ability to read and write secrets in the "my-namespace" namespace and the ability to create pods in that namespace.
Create a Role and RoleBinding to achieve this using kubectl commands.
Create a Role and RoleBinding to achieve this using kubectl commands.
Suggested Answer:
See the solution below with Step by Step Explanation.
Explanation:
Solution (Step by Step) :
1 . Create the Role: Use the following command to create a role called 'sa-secret-pod-writer' in the 'my- namespace' namespace:
kubectl create role sa-secret-pod-writer--namespace=my-namespace --verb=get--verb=list --verb=watch verb=create --verb=update --verb=delete --verb=patch --resource=secrets --resource=pods --api-groups=""
2. Create the RoleBinding: Bind the role to the service account using the following command:
kubectl create rolebinding sa-secret-pod-writer-binding --namespace=my-namespace --role=sa-secret-pod- writer --serviceaccount=my-namespace:my-sa
3. Verify Access: Try running a pod using the service account "my-sa" in the "my-namespace" namespace. You should be able to successfully create the pod and access secrets within the namespace. You can test this by creating a pod definition with the 'serviceAccountName: my-sa' and include a volume mount to a secret within the "my-namespace" namespace.,
Explanation:
Solution (Step by Step) :
1 . Create the Role: Use the following command to create a role called 'sa-secret-pod-writer' in the 'my- namespace' namespace:
kubectl create role sa-secret-pod-writer--namespace=my-namespace --verb=get--verb=list --verb=watch verb=create --verb=update --verb=delete --verb=patch --resource=secrets --resource=pods --api-groups=""
2. Create the RoleBinding: Bind the role to the service account using the following command:
kubectl create rolebinding sa-secret-pod-writer-binding --namespace=my-namespace --role=sa-secret-pod- writer --serviceaccount=my-namespace:my-sa
3. Verify Access: Try running a pod using the service account "my-sa" in the "my-namespace" namespace. You should be able to successfully create the pod and access secrets within the namespace. You can test this by creating a pod definition with the 'serviceAccountName: my-sa' and include a volume mount to a secret within the "my-namespace" namespace.,
by Mick at Apr 13, 2025, 11:45 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).