KubeRusted
Spinning up your cluster…

CBA exam prep — Certified Backstage Associate

Free CBA (Certified Backstage Associate) practice: the 4 official domains, exam-style questions, a timed practice exam and more.

Play the CBA map → · Official CBA exam page

Backstage Development Workflow (24%)

Run locally, local dev workflows, TypeScript builds, Yarn dependencies, Docker images

Backstage Infrastructure (22%)

The framework, configuration, production deployment, client-server architecture

Backstage Catalog (22%)

Why a catalog, populating it, annotations, locations, ingestion and troubleshooting

Customizing Backstage (32%)

Frontend vs backend plugins, customizing plugins, React code, Material UI

Practice questions

Which package manager does a scaffolded Backstage app use by default?

Answer: Yarn. The monorepo uses Yarn workspaces.

Where is the frontend app code in a scaffolded Backstage repo?

Answer: packages/app. The backend lives in packages/backend; your own plugins under plugins/.

Where do new plugins created with `yarn new` go by default?

Answer: plugins/. Each plugin is its own workspace package.

Which file holds local overrides that should not be committed?

Answer: app-config.local.yaml. It is git-ignored by default and loaded after app-config.yaml in development.

Which Node.js versions does Backstage support?

Answer: The active and maintenance LTS releases. Check the release notes for the exact supported versions.

Which command runs the tests of a package?

Answer: yarn test (backstage-cli package test). Repo-wide: yarn test:all.

Which command lints the whole repo?

Answer: yarn lint:all. Packages can be linted individually with yarn lint.

What does `yarn build:backend` produce for deployment?

Answer: A bundle (dist/bundle.tar.gz) of the backend plus the built frontend. The Dockerfile copies this bundle into the image.

Why run `yarn tsc` before building a Docker image on the host?

Answer: The backend build expects type declarations to be generated and type errors caught first. The documented host build runs yarn install, yarn tsc, then yarn build:backend.

What is the advantage of a multi-stage Docker build for Backstage?

Answer: It builds everything inside Docker, so the host needs no Node toolchain. The final stage contains only what is needed to run.

Which port does the Backstage backend listen on by default in development?

Answer: 7007. The frontend dev server runs on 3000.

How do you bump all Backstage packages to the latest release?

Answer: yarn backstage-cli versions:bump. Read the release notes and changelog for required changes.

What is the Backstage upgrade helper used for?

Answer: Showing the template changes between two create-app versions to apply to your app. Scaffolded files are yours, so template changes must be applied manually.

Which file defines which config files a Backstage process loads in production?

Answer: The --config flags passed to the backend command. e.g. node packages/backend --config app-config.yaml --config app-config.production.yaml.

Why are Backstage apps called "frameworks, not products"?

Answer: You own and compose the app code; upstream provides packages you upgrade. This is why create-app generates a full repository.

How does the frontend reach backend plugins during local development?

Answer: Through the backend base URL configured in app-config (backend.baseUrl). app.baseUrl and backend.baseUrl must be set correctly for each environment.

Which TypeScript setting area should you keep consistent across packages?

Answer: The shared root tsconfig.json used by yarn tsc. Type-checking runs across the whole monorepo.

Where are dependencies for a single plugin declared?

Answer: In that plugin’s own package.json. Add them with yarn --cwd plugins/<name> add <dep>.

What does `yarn dev` (or yarn start) need for the catalog to show example entities?

Answer: The example catalog locations configured in app-config.yaml. The scaffolded config includes examples so a fresh app is not empty.

Which three main parts make up the Backstage architecture?

Answer: The frontend app; Backend plugins; Databases/storage used by plugins. Plugins integrate external systems on both frontend and backend.

What does the proxy backend plugin do?

Answer: Forwards frontend requests to third-party APIs, adding headers such as auth server-side. Configured under proxy.endpoints in app-config.yaml.

How does config reach the frontend in Backstage?

Answer: Config values marked visible in a config schema are bundled/served to the frontend. Never mark secrets as frontend-visible.

How do you substitute an environment variable in app-config.yaml?

Answer: ${MY_VAR}. $file and $include are other supported directives.

Which config key sets the database client to PostgreSQL?

Answer: backend.database.client: pg. Connection details go under backend.database.connection.

What is the recommended way to run Backstage in production on Kubernetes?

Answer: A Deployment of your Backstage image with PostgreSQL, config and secrets. You build your own image because the app is your code.

Which auth concept maps a GitHub login to a catalog User entity?

Answer: A sign-in resolver. Without a resolver, users cannot sign in to a production app.

What does the permission framework let you control?

Answer: Which users may perform which actions on which resources (e.g. deleting catalog entities). Policies are written in TypeScript as a backend module.

Which backend service gives plugins a scheduler for periodic tasks?

Answer: The scheduler core service. Tasks can be coordinated across backend replicas.

How are backend plugins isolated in the database?

Answer: Each plugin gets its own logical database (or schema) via the database service. pluginDivisionMode can choose databases or schemas.

Which component serves the built frontend in a typical production setup?

Answer: The backend, via the app backend plugin. Serving the frontend separately is also possible.

How should the Backstage backend scale for availability?

Answer: Run multiple replicas behind a load balancer with a shared PostgreSQL database. In-memory SQLite cannot be shared between replicas.

Which auth provider configuration key area holds provider settings like GitHub client IDs?

Answer: auth.providers. integrations holds tokens for reading from GitHub/GitLab etc.

What is the difference between integrations and auth providers?

Answer: Integrations let Backstage read from systems (e.g. GitHub API); auth providers let users sign in. Both may use GitHub, but with different credentials and purposes.

How does the new backend system wire plugins together?

Answer: A backend instance (createBackend) with backend.add(...) for plugins and modules. Services are injected through dependency injection.

What is a backend "module"?

Answer: An extension that adds features to an existing backend plugin, e.g. a catalog entity provider. Modules extend plugins via extension points.

Why put a load balancer or Ingress with TLS in front of Backstage?

Answer: To serve it over HTTPS on a stable hostname matching app.baseUrl. Auth callbacks also need the correct public URLs.

Which entity kind represents a piece of software such as a service or website?

Answer: Component. Resources are infrastructure such as databases; Systems group components.

Which entity kind represents infrastructure a component depends on, such as a database?

Answer: Resource. Components declare dependsOn relations to Resources.

Which entity kind represents an interface such as an OpenAPI spec?

Answer: API. Components declare providesApis and consumesApis.

Which spec field is required for a Component?

Answer: type; lifecycle; owner. e.g. type: service, lifecycle: production, owner: team-a.

What does spec.owner on a Component usually point to?

Answer: A Group (team) or User entity. Ownership is one of the catalog’s core values.

Which annotation links an entity to its GitHub repository for plugins?

Answer: github.com/project-slug: org/repo. Many plugins read this well-known annotation.

Which annotation links an entity to its TechDocs?

Answer: backstage.io/techdocs-ref: dir:.. dir:. means the docs live next to catalog-info.yaml.

Which annotation lets the Kubernetes plugin find an entity’s workloads?

Answer: backstage.io/kubernetes-id (or a label selector annotation). Resources labelled backstage.io/kubernetes-id=<id> are shown.

How do you register an existing catalog-info.yaml in the UI?

Answer: The "Register existing component" page with the file’s URL. This creates a Location entity pointing at the file.

Which config key lists locations to load at startup?

Answer: catalog.locations. Each entry has a type (url or file) and target.

Which config restricts which entity kinds may be ingested from locations?

Answer: catalog.rules (allow: [...]). Rules can be set globally or per location.

How long until a changed catalog-info.yaml shows in Backstage?

Answer: After the next processing/refresh cycle (or a manual refresh). Entity providers and processors run on schedules.

What should you check when an entity is missing after registration?

Answer: Processing errors on the location/entity; Integration tokens and the URL being reachable. Invalid YAML, schema errors and auth problems are the usual causes.

What is an orphaned entity?

Answer: An entity whose originating location no longer provides it. Orphans can be cleaned up manually or automatically.

Which entity kind describes a template for the Scaffolder?

Answer: Template. Templates are ingested into the catalog like other entities.

What does a Location entity do?

Answer: Points the catalog at other descriptor files to ingest. A Location can list several targets.

How do teams usually get Users and Groups into the catalog?

Answer: An org entity provider such as LDAP, GitHub org or Microsoft Entra ID. Ingested org data enables ownership and sign-in resolution.

Which command scaffolds a new plugin or package interactively?

Answer: yarn new. It offers frontend plugin, backend plugin, module and other templates.

How is a frontend plugin page added to the app (legacy frontend system)?

Answer: Import its page component and add a <Route> in packages/app/src/App.tsx. Add a sidebar link in the Root component for navigation.

In the new frontend system, how are plugin features added to the app?

Answer: As extensions discovered from installed packages, configurable via app-config. Extensions can be enabled, disabled and configured under app.extensions.

Which component switches entity page content by entity kind or type?

Answer: EntitySwitch. EntitySwitch.Case with if={isKind("component")} picks the layout.

Which package provides InfoCard, Table and Page components?

Answer: @backstage/core-components. Using them keeps plugins consistent with the rest of the UI.

How do you change Backstage’s colours and fonts?

Answer: Provide a custom theme (createUnifiedTheme) to the app. Themes build on Material UI’s theming.

How do frontend plugins call their backend plugin?

Answer: Through a client API using discoveryApi (to find the backend URL) and fetchApi. fetchApi adds the user’s identity token automatically.

What is a Utility API in the frontend?

Answer: A shared service (like errorApi or configApi) obtained with useApi. Plugins can define their own API refs and implementations.

Which hook gives a component the current entity on an entity page?

Answer: useEntity. From @backstage/plugin-catalog-react.

How do you add a custom Scaffolder action?

Answer: Create the action with createTemplateAction and register it via a scaffolder backend module. Templates then reference it by id in their steps.

Which built-in Scaffolder action renders a template directory with parameters?

Answer: fetch:template. fetch:plain copies files without templating.

Which Scaffolder action registers the newly created repo in the catalog?

Answer: catalog:register. It points at the new repo’s catalog-info.yaml.

How are Scaffolder template parameters defined?

Answer: As JSON Schema under spec.parameters, rendered as a form. ui:widget and ui:field customize the form.

Which TechDocs generator does Backstage use?

Answer: MkDocs with the techdocs-core plugin. Docs are written in Markdown with an mkdocs.yml.

What is the recommended TechDocs setup for production?

Answer: Generate docs in CI and publish them to cloud storage; Backstage only serves them. Local builder mode is convenient for development only.

How does the Search plugin index catalog and TechDocs content?

Answer: Collators provide documents that an indexer stores in a search engine. The default engine is Lunr; Postgres or Elasticsearch/OpenSearch scale better.

How do you customize a plugin’s behaviour without forking it?

Answer: Use its exported extension points, config options or API overrides. Forking makes upgrades painful.

Where do you add a new tab to every service entity page?

Answer: In the service entity page layout in EntityPage.tsx with EntityLayout.Route. Each EntityLayout.Route is a tab.

How can a frontend plugin be loaded only for entities that have a certain annotation?

Answer: Use a conditional in EntitySwitch (e.g. isGithubAvailable or a custom if function). Plugins export helpers like isXAvailable for this.

Which library do Backstage UI components build on?

Answer: Material UI (MUI). Backstage UI components are designed to work with its theme.

How do you add an icon to the sidebar for a new page?

Answer: Add a SidebarItem with an icon and route in the Root component. In the new frontend system, nav items come from extensions.

How should plugin-specific config be validated?

Answer: Declare a config schema (config.d.ts) in the plugin package. The schema also controls frontend visibility of each key.

What is a "backend module" commonly used for in the catalog?

Answer: Adding an entity provider or processor to the catalog backend. e.g. the GitHub org provider is installed as a catalog module.

How do you render data from your own backend endpoint in a card?

Answer: Write a frontend component that calls the API through a Utility API and shows it in an InfoCard. Use hooks like useAsync for loading and error states.

Where are frontend routes between plugins bound (legacy system)?

Answer: bindRoutes in createApp. External route refs let plugins link to each other without hard dependencies.

What makes a frontend plugin "routable"?

Answer: It exports a routable extension (a page) mounted at a route. Component extensions are rendered inside other pages instead.

Which command creates a brand-new Backstage app?

Answer: npx @backstage/create-app@latest. create-app scaffolds the monorepo; `yarn new` adds plugins to an existing app.

Running `yarn start` locally starts what?

Answer: The frontend dev server and the backend, with hot reload. In development the frontend (3000) and backend (7007) run side by side.

How do you upgrade all @backstage packages to a new release consistently?

Answer: yarn backstage-cli versions:bump. versions:bump updates every Backstage dependency together, matching a release.

How do you keep a GitHub token out of app-config.yaml?

Answer: Reference it as ${GITHUB_TOKEN} and provide the environment variable at runtime. Config supports environment substitution, so secrets come from the environment or a secret store.

Which database should a production Backstage use?

Answer: PostgreSQL. In-memory SQLite loses everything on restart; production setups use PostgreSQL.

In the Backstage architecture, where does a call to a third-party API with a secret token belong?

Answer: In a backend plugin (or the proxy), never in the browser bundle. Anything in the frontend ships to every user’s browser; secrets stay server-side.

Which file registers a service in the Software Catalog?

Answer: catalog-info.yaml. The entity descriptor lives with the code; locations or providers point the catalog at it.

Thousands of repos must appear in the catalog without manual registration. What do you use?

Answer: An entity provider (e.g. GitHub discovery) running on a schedule. Automated ingestion scans the organization and keeps the catalog in sync.

Which entity kinds model ownership and architecture?

Answer: Group; System. Group/User model teams; System/Domain group components. Pods and Namespaces are Kubernetes objects.

You want a new card on every service’s overview tab. Which file do you edit?

Answer: packages/app/src/components/catalog/EntityPage.tsx. The entity page layout is React code in the app package.

How do you add a backend plugin with the new backend system?

Answer: backend.add(import('@backstage/plugin-xyz-backend')) in packages/backend/src/index.ts. The new backend system composes plugins and modules with backend.add().

Teams want a form that creates a new repo from a golden-path template. Which feature?

Answer: Software Templates (the scaffolder). Templates define parameters and steps like fetch:template, publish:github and catalog:register.