This book is written for an engineer who already runs Kubernetes in anger. You know what a Deployment, a Service, a PersistentVolumeClaim and a RoleBinding are, and you have debugged a CrashLoopBackOff at 2 a.m. What you need for EX280 is not another Kubernetes primer. You need the OpenShift deltas: the extra APIs, the opinionated security defaults, the operators that own cluster configuration, and the oc subcommands that turn a five-minute YAML exercise into a fifteen-second one-liner. Every chapter is organised around exactly that.
Which exam version this book targets
Red Hat has published several objective lists for EX280 over the years. The 4.10 and earlier variants (EX280V410K, V45K, V46K) are retired. The current objective sets are the 4.12/4.14 list (EX280V412K, EX280V414K) and the newer 4.18-era list (published as EX280V422), which reorganises the same skills into slightly different headings and adds explicit items for declarative resource management, non-HTTP/SNI exposure and the Red Hat Certified Technologist in OpenShift tasks (the EX188/EX180 material). This book covers the union of those lists, so whichever version you sit, nothing on your sheet is missing.
Objective domain |
Where it is covered |
Manage OpenShift Container Platform |
Chapters 1, 2 |
Declarative resource management, Kustomize |
Chapter 3 |
Deploy applications (templates, Helm, jobs, services) |
Chapter 3 |
Manage storage, secrets, config maps |
Chapter 4 |
Configure applications for reliability |
Chapter 5 |
Manage application updates, image streams |
Chapter 6 |
Manage authentication and authorization |
Chapter 7 |
Configure network security, routes, TLS, policies |
Chapter 8 |
Expose non-HTTP/SNI applications, MetalLB, Multus |
Chapter 9 |
Enable developer self-service |
Chapter 10 |
Manage OpenShift operators |
Chapter 11 |
Configure application security, SCCs, API access |
Chapter 12 |
Configure pod scheduling (older objective set) |
Chapter 13 |
Update OpenShift |
Chapter 14 |
Practice exam |
Chapter 15 |
The exam in one page
EX280 is a performance-based exam. You get a live cluster (or several), a list of tasks, and roughly three hours. Nobody reads your YAML; a grading script inspects the end state of the cluster. That has three consequences which should shape how you study.
• End state is everything. A user who can log in, a route that answers with a valid certificate, a quota that exists in the right project with the right name. Spelling of names matters more than elegance of method. • Persistence after reboot. Red Hat states that configurations must survive a reboot without intervention. In OpenShift this is mostly free, because everything you create through the API lives in etcd. The traps are things done outside the API: editing a file on a node with oc debug, starting a process by hand with oc exec, or making a change an operator will revert. If an operator owns a resource, change its config CR, not the object it renders. • Speed comes from imperative commands. Generating YAML from scratch is slow and error-prone. Use oc create ... --dry-run=client -o yaml to scaffold, oc set to mutate, and oc explain to look up fields. This book shows the fast path first and the YAML second.Conventions
Commands are shown as you would type them. Long lines that wrap in print end with a backslash. Where the wrap falls inside a quoted string (long JSONPath expressions, for example), type the command as one line rather than copying the backslash. Names such as apps.ocp4.example.com stand for your cluster's wildcard domain; find yours with oc get ingresses.config cluster -o jsonpath='{.spec.domain}'. Callout boxes flag exam tips, Kubernetes-to-OpenShift translations, and common mistakes.
Building a practice lab
Reading without typing will not pass this exam. Options, roughly in order of fidelity:
• OpenShift Local (formerly CodeReady Containers). A single-node OpenShift on your laptop. Needs about 9 GB RAM free for the default config, more for operators. Supports HTPasswd, routes, quotas, SCCs and most of this book. It cannot meaningfully demonstrate MetalLB or multi-node scheduling. • Developer Sandbox. Free, browser-based, but you are not cluster-admin. Useful for project-level work only. • A real cluster. A three-node compact cluster on bare metal or a homelab hypervisor (assisted installer or agent-based installer) is the closest thing to the exam. Red Hat's trial entitlement gives you 60 days. • Red Hat Learning Subscription / DO280 labs. The official course labs mirror the exam environment closely.