Kubernetes
Deploy, scale, break and repair a real single-node cluster.
31 labs and exams
Practice exams timed and weighted like the paper you are booking, on a live Kubernetes cluster in a browser tab. Every task is graded against actual cluster state, so a pass means you did the work.
No card. Every lab is free.
Incident · P1
web-frontend is down
Monitoring paged at 09:12. The web Service stopped answering and it was healthy at 09:00 — something changed the cluster. No steps. Find it.
SLO99.5% availability — burning
learner@lab:~$ curl -s http://10.43.20.14/ curl: (7) Failed to connect to 10.43.20.14 port 80: Connection refused learner@lab:~$ kubectl get pods -l app=web NAME READY STATUS RESTARTS AGE web-6f8d9c4b7-4mzql 1/1 Running 0 14m web-6f8d9c4b7-t8kxr 1/1 Running 0 14m learner@lab:~$ kubectl get endpoints web NAME ENDPOINTS AGE web <none> 14m learner@lab:~$
Catalogue
Every one of these has labs in the catalogue today.
Deploy, scale, break and repair a real single-node cluster.
31 labs and exams
Files, permissions, services and the shell they all live in.
1 labs and exams
A real daemon: build an image, run it, compose a stack.
1 labs and exams
A live mesh: traffic shifting, mTLS and what breaks under both.
1 labs and exams
Workflows, CD, Rollouts and Events on a running cluster.
2 labs and exams
Network policy and eBPF, on a cluster you can watch drop packets.
1 labs and exams
Run it, scrape a target, and answer a question in PromQL.
1 labs and exams
How it works
A container boots on our infrastructure with a real kernel, a real package manager and, where the lab needs one, a real single-node Kubernetes cluster. Nothing installs on your machine.
A full shell in the browser tab. The same commands you would run on a server — kubectl, docker, systemctl, ip, journalctl — against a system that behaves like a server, because it is one.
Validation runs a script inside the machine and inspects what is actually there: the running pods, the file's permissions, the listening port. There is no answer to recognise and nothing to tick.
Four modes
The same sandboxes and the same validation underneath all of them, so a pass means the same thing everywhere.
The system boots broken. You get an incident report, a clock, and no instructions.
The fault is different for each person, so a solution posted online will not run on your cluster.
The only way through is to actually diagnose it — read the logs, form a hypothesis, test it, and fix the thing that is really wrong.
Instructions beside a live terminal. You run real commands on a real machine, and each step is verified against system state before you move on.
Timed and weighted like the certification they mirror, then scored per domain — a pass tells you you are ready, and a fail tells you which subject to go back to.
Two people, identical broken environments, first correct fix wins. The same validation as everything else, so speed never beats a fix that does not hold.
After an exam
Not a number. A breakdown by domain, weighted the way the real exam weights it, so you know which subject cost you the pass.
Not ready yet — Storage and troubleshooting are below the line. Those are the two to work on before you book the real exam.
Catalogue
Practice exams for the CNCF certifications, and the free labs that get you ready for them. Every lab is free to run; exams are sold separately.
Pricing
$0
Every lab in the catalogue. One session at a time. One free readiness check per hands-on exam, which grades a sample of real tasks and reports where you are weak.
$0
60 questions, 90 minutes, every answer explained in the review.
$10$30
17 timed tasks on a live cluster, scored per domain.
Written papers are free, with no card and no expiry. A hands-on exam lasts 365 days from purchase, with unlimited retakes — the sandbox is rebuilt from scratch each attempt.
Charged in US dollars by international card — Visa or Mastercard — through Stripe. Access opens the moment the payment clears; your bank sets the exchange rate it applies.
FAQ
Real. Each session is a Linux container on our infrastructure with its own filesystem, processes and network. Labs that need Kubernetes run a real single-node k3s cluster inside it, and the Docker labs run a real Docker daemon. You can break it, and you often are meant to.
No. The terminal is a browser tab. Nothing is installed on your machine and nothing is left behind when the session ends.
Killer.sh gives you two sessions. Here, an exam entitlement lasts a year and you can retake as often as you like — the sandbox is rebuilt from scratch each time, so it is a real attempt rather than a replay.
You also get two things it does not have: break/fix incidents where the fault differs per person, so a posted walkthrough will not work on your environment, and a per-domain readiness report rather than a single number — it names the subject you are weak in instead of leaving you to guess.
If you already have Killer.sh, use it. It is good and it is already paid for. Come here for the retries and for knowing why you failed.
A current browser and a working connection. The terminal is text over a websocket, so it stays usable on a slow line — there is no video and no remote desktop. A physical keyboard makes the exams far easier than a phone.
An international card — Visa or Mastercard — charged in US dollars through Stripe. One payment per certification, not a subscription: it opens that certification's hands-on exams for 365 days with unlimited retakes. Written papers, incident labs and races are free and need no card at all.
Every hands-on exam has one free readiness check: a sample of its real tasks, graded on cluster state and reported per domain. No card, and it names the subject you are short on rather than a number.