Exam day

CKAD exam requirements

Two hours of kubectl while a stranger watches your webcam. Machine, room, ID, PSI — not the syllabus. Confirm against the Linux Foundation handbook; they move this.

KubeLab is not the Linux Foundation or PSI. This is a reading of their public docs (August 2026). Your confirmation email wins if it disagrees.

The sitting

Duration
2 hours
Tasks
15–20 CLI problems
Pass
66%
Price
$445, one retake
Cluster
Kubernetes 1.35
Valid
2 years
To schedule
12 months
Languages
EN, JA, ZH
Proctor
PSI Bridge + Secure Browser
Results
Email within 24 hours

A computer that will actually launch

CKAD uses PSI Bridge and the PSI Secure Browser — a downloaded app, not a Chrome tab. You need to install it and kill other processes. Work laptops usually cannot.

Bring this

  • A personal Windows, Mac, or Ubuntu machine you administer.
  • One active monitor. 15" and 1080p recommended (1024×768 is the floor).
  • 16 GB RAM recommended, 8 GB minimum. Reboot so about half the RAM is free.
  • 500 MB free disk for the Secure Browser.
  • A webcam you can point around the room. Desktop: an external cam you can pick up.
  • Built-in mic and speakers. No headset, no earbuds, no AirPods.
  • Wired broadband if you can. 3 Mbps up and down. 750 kbps is the floor.
  • HTTPS to AWS S3 and WebRTC allowed. No VPN, no corporate firewall, no HTTP proxy.
  • Latest Chrome to schedule. The Secure Browser is Chrome-based; other browsers are a worse rehearsal.

Leave this

  • A work or school laptop. MDM, no admin, corporate firewall — it will not install.
  • A second monitor. Disable extras so the OS reports one display.
  • Any VM, even if the compatibility check is green.
  • A Chromebook. CKAD needs the Secure Browser, not the Chrome extension.
  • A phone or tablet. Surface Pro with a front camera is the only tablet PSI lists.
  • VPN, corporate firewall, HTTP proxy, headphones, extra cameras left plugged in.

Operating systems PSI lists

Supported

  • Windows 10 or 11, 64-bit
  • macOS Sonoma 14, Sequoia 15, Tahoe 26
  • Ubuntu 22.04, 24.04, 26.04 LTS

Not supported

  • Windows Education, Windows Enterprise, S-Mode, Snapdragon
  • macOS Ventura 13 and older
  • Ubuntu 20.04, non-LTS (odd-year) Ubuntu
  • ChromeOS / Chromebook (no Secure Browser)

Windows Education and Windows Enterprise are on the refuse list. That is the edition a work laptop actually runs. A $445 professional exam that rejects the professional OS. Bring a personal machine.

Ubuntu: launch the Secure Browser from the desktop icon. Not from a terminal. You are about to sit a Linux exam. They still want a double-click.

Prove it before exam day

The room

ID

Day-of sequence

  1. 01

    Clear the machine

    Reboot. Plug the laptop in. Close everything. Pause antivirus if you can. Mac: Bluetooth off. Extra cameras and mics unplugged.

  2. 02

    Launch on time

    Take Exam is live 30 minutes before the slot. Start within 30 minutes of the scheduled time or you are a no-show: no refund, no reschedule.

  3. 03

    Install, then check-in

    First time: download and install the Secure Browser. Accept the agreements. Photo of the ID, then a selfie.

  4. 04

    Scan the room

    360° of the walls, floor to ceiling, wrists and ears (and glasses), the desk including under the laptop. Show the phone, then put it behind you out of reach.

  5. 05

    Wait, then sit

    A check-in specialist should take you in under 15 minutes. Use live chat, not the US phone numbers, if you are not in the US. The proctor releases the exam after you accept the rules again.

  6. 06

    End cleanly

    End Exam, then End Session. Close the Secure Browser before you stand up. Walking off camera after you finished can still void the result.

If you disconnect, the two-hour clock keeps running. $445, and a Wi-Fi blip eats the remaining time. Wired if you can. Re-launch, check in again, no extra minutes.

Rules that fail you

Muttering while you debug is how humans work. It is also how they pause you. Looking at the ceiling to think is a violation. Two hours of kubectl under a behavior policy written for multiple-choice.

What you may open

Only from Firefox inside the exam VM. Not from your own machine. Search on kubernetes.io/docs is allowed; do not open hits that leave that site.

Bring this

  • kubernetes.io/docs — and translations, though English is the one they keep current.
  • kubernetes.io/blog
  • helm.sh/docs
  • Links in the task’s Quick Reference box
  • man pages and /usr/share on the exam host
  • Distro packages you install yourself

Leave this

  • Gateway API docs — that is CKA, not CKAD
  • Google, Stack Overflow, ChatGPT, personal notes, a second browser on your laptop

On each SSH host: kubectl (alias k) with bash completion, yq, curl, wget, man. sudo -i works. Nested SSH does not. Do not reboot the base node.

The remote desktop will fight you

After

Practice without the hazing

KubeLab is not PSI. No webcam, no Secure Browser, a live cluster in the browser. One mock is free. The skill is kubectl. Their desktop is a one-day tax.

Start the free mock

FAQ

Can I use my work laptop?

Assume no. You need to install the Secure Browser and kill processes. Windows Enterprise and Education are unsupported. Use a personal machine.

Can I use two monitors?

No. One active monitor. Disable the rest. A laptop with the lid closed plus one external display is fine if the OS shows a single screen.

Will a Chromebook work?

Not for CKAD. PSI’s Chrome extension can run on ChromeOS; the CKAD sitting uses the Secure Browser, which Chromebooks do not get.

Do I need a second camera on my phone?

Linux Foundation CKAD docs describe one webcam and a room scan, not a phone filming you for two hours. PSI publishes a second-camera product for some exams. Follow the confirmation email if it asks for one.

Can I take a bathroom break?

Only with the proctor’s permission, and the clock does not stop. Plan to sit still for two hours.

Is there a prerequisite?

No. CKAD has no required prior cert. CKS is the one that needs CKA first.

What score do I need?

66% or above. About 15–20 weighted CLI tasks, two hours, Kubernetes 1.35. Results by email within 24 hours.

Sources