Latest Posts
CNCF CKA: Scheduling Problems
A Pending Pod is not evidence that the Kubernetes scheduler is confused. It usually means the scheduler is doing exactly what the Pod specification and cluster state require, but no node satisfies all of the constraints at the same time. The fastest way to troubleshoot scheduling is therefore to reconstruct the filter that the scheduler is applying. Resource requests are one part of that filter. Taints can repel Pods. Tolerations can make a taint acceptable. Node selectors and node affinity can restrict eligible nodes. Pod affinity and anti-affinity can…
CNCF CKA: etcd Is Small, Critical, and Worth Understanding
etcd is easy to ignore because most Kubernetes administrators interact with the API server rather than with the backing store directly. Yet the control plane depends on etcd for authoritative cluster state. Deployments, Secrets, ConfigMaps, Nodes, custom resources, leases, and the rest of the API model ultimately depend on a storage system that must remain consistent and available. That does not mean every administrator should treat etcd as a database to tune casually. The opposite is safer. etcd deserves respect because unnecessary intervention can turn a recoverable control-plane issue…
CNCF CKA: Cluster Upgrades Are an Operations Exercise, Not a Version Bump
A Kubernetes upgrade changes more than a version string. It changes a distributed control plane while workloads are running, nodes are serving traffic, add-ons depend on Kubernetes APIs, and automation assumes particular behaviors. The safest upgrade plan therefore looks more like a controlled operations exercise than a software installer. The high-level order is simple: understand the current cluster, prepare recovery, upgrade the control plane, move through worker nodes, and verify the system at each stage. The complexity comes from the dependencies around that order. API removals can break manifests….
CNCF CKA: Network Policies: Security Depends on the CNI You Actually Run
Kubernetes NetworkPolicy is a powerful example of declarative intent that depends on an implementation. You can create a perfectly valid NetworkPolicy object and see it stored by the API server even when the cluster network does not enforce that policy. The security outcome therefore depends not only on the YAML but on the CNI or network implementation that turns the policy into packet filtering. This matters because Kubernetes networking is generally open between Pods unless something deliberately restricts it. A NetworkPolicy selects Pods and defines allowed ingress, egress, or…
CNCF CKA: Resource Requests and Limits Shape Cluster Stability
Kubernetes resource settings are not merely performance tuning. Requests influence where Pods can be scheduled, limits influence how the node enforces consumption, and the combination affects quality-of-service classification, eviction behavior, capacity planning, and the amount of useful work a cluster can safely host. Poor values can make a cluster look full when it is idle or make it look efficient until memory pressure causes a cascade of failures. The important distinction is that a request and a limit answer different questions. A request tells the scheduler how much of…
CNCF CKA: Reading Kubernetes Events Before Reaching for the Logs
Kubernetes events are often the shortest path from a vague symptom to the component that first noticed it. A Pod is Pending, a volume will not mount, an image cannot be pulled, or a node turns NotReady; in each case, the control plane and node agents may already have emitted a concise explanation before an administrator opens any application log. That does not make events a replacement for logs. Events are best-effort, have limited retention, and summarize state changes rather than preserving every detail. Their value is triage. They…
CNCF CKA: Building a CKA Practice Cluster
A CKA practice cluster should be a place where systems fail in understandable ways. If every lab starts from a perfect manifest and ends with a successful kubectl command, the candidate can become fast at syntax without learning how Kubernetes behaves when state diverges from intent. Real administration—and a performance-based exam—requires diagnosis as much as construction. The current CKA is a two-hour, performance-based exam built around hands-on command-line tasks. Its blueprint emphasizes Troubleshooting, cluster architecture and configuration, networking, scheduling, and storage. A practice environment should therefore let those domains…
Huawei H12-811 V2.0: VLANs, Trunks, and Clean Campus Design
VLAN configuration feels arbitrary when it is learned as a sequence of commands. It becomes much more logical when the starting point is the traffic itself. A campus switch is trying to answer a simple question for every Ethernet frame: which Layer 2 broadcast domain does this frame belong to, and where is that broadcast domain allowed to extend? VLAN tags, access interfaces, trunks, and Layer 3 gateways are mechanisms for preserving that answer as traffic crosses the network. A clean campus design therefore begins with boundaries, not VLAN…
Huawei H12-811 V2.0: OSPF Fundamentals by Following the Route
OSPF becomes unnecessarily difficult when learners start with packet names, LSA types, and configuration syntax. A better starting point is a route. Imagine a router needs to forward a packet to a subnet several hops away. OSPF’s job is to give that router a consistent view of the network topology and enough information to choose a shortest path to the destination. That simple goal explains most of the protocol. Routers must discover neighbors, form the right adjacencies, describe their links, synchronize topology information, calculate paths, and install usable routes….
Huawei H12-811 V2.0: STP Is Still the Safety Net Your Layer 2 Network Needs
Redundant Ethernet links are desirable until they create a loop. Unlike a routed packet, a Layer 2 frame does not carry a hop limit that reliably makes a switching loop burn itself out. Broadcast, multicast, and unknown unicast traffic can circulate repeatedly, while switches continuously relearn the same source MAC addresses on different ports. The result can be a broadcast storm, MAC-table instability, and a network that fails very quickly. Spanning Tree Protocol exists to let a topology contain redundant links without allowing every link to forward Layer 2…
Huawei H12-811 V2.0: IPv6 Addressing Without the Confusion
IPv6 looks difficult mainly because the addresses are longer and the operational habits are different from IPv4. The underlying job has not changed: interfaces need addresses, routers need prefixes, hosts need a default path, and operators need a design that makes failures understandable. Once the address is treated as a 128-bit value divided into a network prefix and interface portion, the notation becomes much less intimidating. The bigger change is that IPv6 was designed with mechanisms such as Neighbor Discovery and Router Advertisements as core parts of normal operation….
Huawei H12-811 V2.0: VRRP and the Design of a Reliable Default Gateway
Redundant switches do not automatically create a redundant default gateway. An endpoint normally sends off-subnet traffic to one gateway IP address. If that address belongs to a single physical router and the router fails, the LAN can remain perfectly healthy while every remote destination becomes unreachable. First-hop redundancy protocols solve that specific dependency. Virtual Router Redundancy Protocol creates a virtual gateway identity shared by multiple routing devices. Hosts keep one default gateway address while the routers coordinate which device currently owns the forwarding role. The result is a cleaner…
Huawei H12-811 V2.0: WLAN Planning for Coverage and User Experience
Wireless design fails when the plan stops at “there is signal everywhere.” A client can see a strong SSID and still have a terrible experience because the channel is congested, neighboring access points overlap badly, the noise floor is high, or too many users are competing for the same airtime. Coverage is necessary, but it is only one dimension of a working WLAN. A useful WLAN plan starts with user behavior. Where will people actually work? Which applications are sensitive to delay and loss? How many devices are expected…
Huawei H12-811 V2.0: ACLs and Traffic Policy on Huawei Datacom Networks
An access control list is not security merely because it contains deny statements. An ACL is a way to classify traffic by fields such as source address, destination address, protocol, or port. What happens to the matching traffic depends on where and how that classification is applied. The same ACL concept can support packet filtering, quality-of-service classification, traffic statistics, redirection, or other policy actions. That distinction is important on Huawei datacom devices because traffic-filter and traffic-policy mechanisms can both reference ACL logic but solve different operational problems. A good…
Huawei H12-811 V2.0: eSight, Telemetry, and Network Operations
Traditional network management often begins with devices: log in to a switch, inspect an interface, change a configuration, and move to the next device. That approach works on a very small network but scales poorly because the operator has to reconstruct service behavior from individual boxes. Modern network operations tries to reverse the perspective: understand the health of the network and the services first, then use device data to explain what is happening. Huawei eSight represents the centralized-management side of that shift. It can discover and visualize network devices,…