CKA 40-Day Study Roadmap

A day-by-day learning plan synthesized from the Tech Tutorials with Piyush CKA Full Course. Designed for the Certified Kubernetes Administrator exam (2025 Edition).

Phase 1: Foundation & Core Concepts (Days 0–10)

DayTopicCKA Domain
0Course Introduction & Exam OverviewArchitecture
1What is Kubernetes & Why K8s?Architecture
2Kubernetes Architecture (Control Plane & Worker Nodes)Architecture
3Installing Kubernetes with kubeadmArchitecture
4kubectl Essentials & Cluster InteractionArchitecture
5Understanding Pods & Container PatternsWorkloads
6Multi-Container Pods, Init Containers & SidecarsWorkloads
7Labels, Selectors & AnnotationsWorkloads
8Deployments, ReplicaSets & Replication ControllersWorkloads
9Kubernetes Services (ClusterIP, NodePort, LoadBalancer, ExternalName)Networking
10Kubernetes Namespaces (default, kube-system, resource isolation, DNS)Architecture

Phase 2: Workloads, Networking & Storage (Days 11–25)

DayTopicCKA Domain
11Multi-Container Pods (Sidecar, Init, Adapter, Ambassador)Workloads
12DaemonSets, Jobs & CronJobsWorkloads
13Static Pods, Manual Scheduling, Labels & SelectorsWorkloads
14Taints & Tolerations in KubernetesWorkloads
15Node Affinity ExplainedWorkloads
16Kubernetes Requests and LimitsWorkloads
17Kubernetes Autoscaling — HPA vs VPAWorkloads
18Kubernetes Health Probes — Liveness vs Readiness vs StartupWorkloads
19ConfigMaps & SecretsArchitecture
20SSL/TLS FundamentalsSecurity
21Manage TLS Certificates in K8s — CSR & kubeadm PKISecurity
22Authentication & Authorization BasicsArchitecture
23RBAC: Roles, RoleBindings & Hands-On DemoArchitecture
24RBAC Continued: ClusterRoles & ClusterRoleBindingsArchitecture
25Kubernetes Service Account & RBAC for WorkloadsArchitecture
26Kubernetes Network Policies ExplainedNetworking
27Setup a Multi Node Kubernetes Cluster Using KubeadmArchitecture

Phase 3: Storage, Scheduling & Troubleshooting (Days 28–37)

DayTopicCKA Domain
28Docker Storage: Volumes, Bind Mounts & Layered ArchitectureStorage
29Kubernetes Storage: Volumes, PersistentVolumes & PVCsStorage
30What Is DNS — External DNS FundamentalsNetworking
31Understanding CoreDNS In KubernetesNetworking
32Kubernetes Networking Explained — CNI With @kubesimplifyNetworking
33Kubernetes Ingress Tutorial — Ingress Explained (with @AbhishekVeeramalla)Networking
34RestoreArchitecture
35ETCD Backup & RestoreArchitecture
36Kubernetes Logging & MonitoringTroubleshooting
37Application Failure TroubleshootingTroubleshooting
38Troubleshooting Control Plane FailureTroubleshooting
39Troubleshooting Worker Nodes FailuresTroubleshooting
40Phase 3 Review & Practice Exam

Phase 4: Mock Exams & Final Preparation (Days 38–42)

DayFocus
38Mock Exam 1: Full 2-Hour Simulation
39Mock Exam 2: Speed & Accuracy Drill
40Weak Area Revision & kubectl Cheatsheet
41Exam Strategy: Time Management & Documentation Search
42Final Review & Confidence Building

Daily Study Methodology

  1. Watch the daily video (20–40 min)
  2. Lab — Replicate every command on a local cluster (kind/minikube)
  3. Note — Summarize key commands and YAML patterns in your own words
  4. Quiz — Try to solve related tasks without looking at notes
  5. Log — Mark progress in the CKA Progress Tracker

Critical Exam Skills to Build

  • YAML Speed: Practice writing Deployments, Services, and RBAC manifests from memory
  • Service Types: Know the four types (ClusterIP, NodePort, LoadBalancer, ExternalName), their port fields, and when each applies
  • kubectl Explain: Use kubectl explain --recursive to discover field structures quickly
  • Context Switching: The exam uses multiple clusters; be fluent with kubectl config use-context
  • Docs Navigation: Learn to find answers on kubernetes.io/docs in under 30 seconds
  • Troubleshooting Chain: Master kubectl get → describe → logs → exec for rapid diagnosis

Sources

Post-CKA Specialization: DevSecOps & Helm

After completing the 40-day CKA curriculum, two structured specializations extend CKA knowledge into production operations:

DevSecOps Path

The DevOps to DevSecOps in 9 Hours course by Abhishek Veeramalla maps directly onto CKA knowledge:

CKA FoundationDevSecOps Extension
Docker Fundamentals (Day 1–3)Container Security — image scanning, non-root users, distroless images
Kubernetes Architecture & kubeadm (Day 5, 27)Terraform Security — IaC scanning, state encryption, Vault integration
RBAC & Authentication (Day 22–25)Kubernetes Security — least-privilege RBAC, NetworkPolicies, Pod Security
TLS & Certificates (Day 20–21)GitOps Security — branch protection, secret scanning, PAT hygiene
CI/CD ConceptsSAST/DAST/SCA — SonarQube, OWASP ZAP, Trivy in GitHub Actions
PR Review & Approval PatternsAtlantis — Terraform plan/apply comments and project locking

This progression turns a cluster administrator into a security-aware pipeline engineer.

Helm & Application Delivery Path

The Helm Zero to Hero course (also by Abhishek Veeramalla) covers the standard Kubernetes packaging layer:

CKA FoundationHelm Extension
Kubernetes Architecture & kubeadm (Day 5, 27)Helm v3 architecture — client-side only, no Tiller, API server direct
Deployments, Services, ConfigMaps (Day 8–10, 19)Chart authoring — templating Deployments, Services, and ConfigMaps
Ingress (Day 33)Installing Ingress Controllers via Helm repositories
Namespaces & RBAC (Day 10, 22–25)Namespace-scoped releases and Helm RBAC considerations
Application Troubleshooting (Day 37)Helm revision history, rollback, and release debugging

Mastering Helm is essential for any Kubernetes operator because the entire ecosystem (Prometheus, Grafana, Argo CD, cert-manager, NGINX Ingress) distributes via Helm charts.


Tags: cka kubernetes roadmap learning-plan 40-days devops devsecops