← KCNA: Kubernetes and cloud native foundations
08 / 8 · 60 MIN

Workshop: diagnosis, delivery and indicators

Connect access, data, release and telemetry to concrete acceptance criteria.

From name to business outcome

DNS answers, TCP connectivity and correct transactions are different evidence. In fictional custody-api, the process listens on 8080 while targetPort points to 9090. The name can resolve and labels can match without useful communication. Correct the mapping to the intended listener and inspect readiness before checking the transaction. If egress policy blocks the resolver, allowing only the database IP does not restore DNS. Draw the path with source, resolution, destination and dependencies, stating that the CNI enforces policies. Then check allowed flows and those that must remain excluded.

Persistence and permissions have boundaries

A 10Gi PVC does not match a 5Gi PV merely because the class matches. Without dynamic provisioning, provide a suitable volume or justify revising the requirement. After binding, ReadWriteOnce refers to one node and can permit multiple Pods there; it is not a writer mutex. Likewise, readOnlyRootFilesystem does not forbid all writable mounts. For /tmp, provide a suitable volume and check observed UID, groups and permissions. These examples require connecting each declaration to its exact scope rather than treating a field as a guarantee of consistency or complete authorization.

Read the reason for rejection

Status 403 alone is insufficient to choose a correction. Compare log retrieval denied for missing pods/log permission with Pod creation denied by exceeded quota: requests.memory. The first calls for scoped authorization review; the second for quota, accounted usage and request values. Granting cluster-admin because both say Forbidden confuses causes and expands access without fixing the design. At RUN handover, retain error examples without tokens or customer data and assign each to its appropriate owner. Also confirm whether the object was created, since that changes which evidence is available.

From integration to release adoption

A green pipeline demonstrates only what its steps checked. If image A passed tests but production references B, adoption is still missing. With GitOps, inspect the selected revision, branch and path, then compare actual state. A fix applied only to test does not change environments/prod. Readiness may also be insufficient for functional acceptance: if incorrect results increase, pause promotion and assess recovery with data and dependency owners. The release record should link artifact, declaration, execution and transaction, with stopping criteria agreed before increasing exposure.

Calculate indicators without losing the denominator

To combine request groups with the same criteria and window, add successes and totals before division. A group with 990 successes out of 1000 and another with 9000 out of 9000 gives 9990/10000, or 99.9%. Averaging percentages gives 99.5% and changes request weighting. Retain group-level views too: an acceptable aggregate can hide unequal experience. Define eligible events and measurement location. A backend-only metric may miss requests that never arrived there. Expose this gap when deciding objectives and alerts rather than inventing uncollected outcomes.

Signals the team can operate

A label containing a new identifier for each customer creates a growing set of series. For an aggregate dashboard, prefer controlled dimensions such as operation and response class, with an access policy for individual investigation. Do not treat base 64 as anonymization. To connect API and worker, equal span names are insufficient: context must cross the transport through suitable instrumentation. These workshop examples neither export telemetry nor run a cluster. Give APS the indicator definition, cardinality boundaries, context path and authorized validation plan. Handover then addresses how signals work, as well as whether they exist.

# Synthetic request groups, same window and eligibility
A: total=1000 good=990
B: total=9000 good=9000
aggregate: good=9990 total=10000 ratio=0.999
IN PRACTICE

990/1000 and 9000/9000 give 9990/10000=99.9%; retain group-level analysis too.

Common pitfalls

Treating 403 as one cause, Ready as acceptance, RWO as a mutex or mean rates as an aggregate rate.

Related topics: Workshop: capacity, eligibility and startup

Take this idea with you

Connect declaration to execution and measured outcome.

Create account

Reference: Implementing SLOs · KCNA current four-domain curriculum; edition date unconfirmed

Kubernetes® and KCNA are trademarks or registered trademarks of The Linux Foundation. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by The Linux Foundation. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.