Hands-on Lab·Kubernetes and Cloud Native Security Associate
Control Plane Static Pod Manifests
Domain 2 is about the security of each cluster component, and the first thing to understand is where they come from. On a kubeadm cluster the entire control plane is four YAML files in one directory, and the trust that follows from that is the whole shape of the domain.
Cluster Component Security Guide 9 of 42 Beginner
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 14 min
- Reviewed25 August 2026
Written against the versions above. kubeadm v1.36.3 built this cluster, so the manifest paths and flags are kubeadm's defaults. A managed cluster hides all of this - you cannot read the apiserver's flags on EKS or GKE - which is itself worth knowing.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 3 - the cluster this inspects.
-
Four files, mode 600, owned by root
-
Owned by a Node, not a controller