learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Learn Kubernetes

From your first pod to a hardened production cluster. Covers every CKAD, CKA and CKS exam competency.

Basic

Start here. The ideas everything else is built on, from the first command.

  • Pods: The smallest thing Kubernetes runs: what a pod is, how it starts, what restarts it, and what does not bring it back. (about 30 minutes)
  • Container Images: From Dockerfile to running container: layers, tags, registries, pull policy and the pull failures you will meet. (about 30 minutes)
  • Multi-container Pods: Init containers, sidecars and the volumes they share: what containers in one pod have in common, and what they do not. (about 30 minutes)
  • Choosing a Workload: Deployment, StatefulSet, DaemonSet, Job or CronJob: what each one promises about your pods, and how to pick. (about 35 minutes)
  • Deployments & Rollouts: Ship a new version with no downtime, and get back to the old one when it goes wrong. (about 32 minutes)
  • Probes & Health Checks: Three questions the kubelet asks your container, and what it does with each answer. (about 30 minutes)
  • Logs & Debugging: Five broken pods, one routine: get, describe, logs, events, exec. Learn which one answers which question. (about 30 minutes)
  • ConfigMaps & Secrets: Keep settings out of the image: hand them to pods as variables or files, and know what base64 does not protect. (about 30 minutes)
  • Services & DNS: Pods die and change IP. A Service gives them one name that never moves. (about 30 minutes)

Intermediate

What you need to run it for real: the moving parts and the ways they fail.

  • Blue/Green & Canary: Two Deployments, one Service, and a label selector that decides who gets the customers. (about 30 minutes)
  • Helm & Kustomize: Install, upgrade and roll back packaged apps with Helm; adapt plain YAML per environment with Kustomize. (about 35 minutes)
  • Requests, Limits & Quotas: Requests reserve room on a node. Limits are enforced by the kernel. Quotas cap what a whole namespace may ask for. (about 30 minutes)
  • SecurityContext & ServiceAccounts: A pod has two identities: a Linux user on the node and a ServiceAccount to the API server. Shrink both. (about 35 minutes)
  • CRDs, Operators & API Versions: Teach the API a new noun, let an operator act on it, and keep your manifests alive when old API versions are removed. (about 30 minutes)
  • Ingress: One public entry point for many Services: host and path rules, TLS, and the controller that makes the rules real. (about 30 minutes)
  • NetworkPolicies: Every pod can reach every pod until you say otherwise. Select pods, isolate them, and allow back only the paths the shop needs. (about 32 minutes)
  • Cluster Architecture: Follow one kubectl apply through every component until a container is running. (about 32 minutes)
  • RBAC: Roles, bindings and subjects: who may do what, and how to prove it. (about 32 minutes)
  • Scheduling: How the scheduler picks a node, and every way you can steer it. (about 35 minutes)
  • Autoscaling & Self-healing: Let the cluster add replicas under load and replace what breaks. (about 32 minutes)
  • Gateway API: The successor to Ingress: a GatewayClass, a Gateway and HTTPRoutes, owned by different people, with traffic splitting built in. (about 32 minutes)
  • Storage: Volumes that outlive pods: PVs, PVCs, StorageClasses and reclaim policies. (about 35 minutes)
  • Troubleshooting Workloads: Eight broken workloads, one habit: read the STATUS column as a diagnosis, then run the one command that holds the reason. (about 32 minutes)

Advanced

Production depth: hardening, recovery and the trade-offs behind the design.

  • kubeadm: Install & Upgrade: Bootstrap a cluster, join nodes, and upgrade it one minor version at a time. (about 35 minutes)
  • HA Control Plane & etcd: Quorum, leader election, and backing up the one database that holds everything. (about 30 minutes)
  • Pod Networking & CoreDNS: How a packet gets from one pod to another: CNI, kube-proxy and cluster DNS. (about 35 minutes)
  • Troubleshooting the Cluster: Nodes go NotReady and control-plane components die. Check the API, the nodes, the system pods and the workload, in that order. (about 34 minutes)
  • Troubleshooting Networking: A request fails somewhere between the name and the pod. Read the error, test one hop at a time, and find the hop. (about 32 minutes)
  • CIS Benchmarks & API Hardening: Audit an inherited control plane with kube-bench, close what it finds, and check what you run before you run it. (about 34 minutes)
  • Network Lockdown: Default-deny everywhere, a guarded metadata endpoint, and TLS at the edge. (about 32 minutes)
  • Least Privilege: Shrink every identity to exactly what it needs, starting with ServiceAccounts. (about 30 minutes)
  • Kernel & Host Hardening: seccomp, AppArmor and capabilities: what stands between a container and the kernel. (about 32 minutes)
  • Pod Security Standards: Privileged, baseline, restricted: enforce a floor for every pod in a namespace. (about 30 minutes)
  • Secrets, Sandboxes & mTLS: Encrypt Secrets at rest, sandbox untrusted pods, encrypt traffic between them. (about 35 minutes)
  • Image Footprint & Scanning: Smaller images, scanned images, and manifests checked before they ship. (about 35 minutes)
  • Signed Images & Trusted Registries: Only run what you built: allowed registries and signatures verified at admission. (about 30 minutes)
  • Runtime Security with Falco: Watch syscalls for behaviour that should never happen, and make containers immutable. (about 35 minutes)
  • Audit Logs & Investigation: Record who did what, then reconstruct an attack from the evidence. (about 35 minutes)

Learn Kubernetes on a cluster you can break

Kubernetes is easy to start and hard to understand. kubectl apply works until it does not, and then you are reading events, describing pods and guessing. These lessons run a real-feeling Kubernetes cluster in your browser: the API server, scheduler, controllers, kubelets and the network, all drawn live, so you can see why a pod is Pending, why a rollout stalled or why a Service has no endpoints.

The course covers every competency on the official CKAD, CKA and CKS exam blueprints for Kubernetes v1.35: pods and workloads, configuration and secrets, Services, Ingress and the Gateway API, storage, scheduling, RBAC, networking and NetworkPolicy, cluster installation with kubeadm, upgrades, etcd backup, troubleshooting, and cluster hardening with Pod Security, seccomp, image signing and runtime security. Each lesson ends with typed drills and a playground, and the exam blueprint page maps every exam competency to the lesson that teaches it.

You learn the exam habit that also works in production: describe, logs, events, exec, then fix. Timed drills let you practise kubectl under exam conditions.

After these lessons you can

  • Deploy, scale, update and roll back applications with kubectl and YAML
  • Expose workloads with Services, Ingress and the Gateway API, and debug them when traffic fails
  • Configure storage, ConfigMaps, Secrets, probes, resources and scheduling rules
  • Install, upgrade and back up a cluster with kubeadm and etcd
  • Lock a cluster down with RBAC, NetworkPolicy, Pod Security and supply-chain checks
  • Troubleshoot a failing pod, node or cluster quickly, the way the CKA exam expects

Who it is for

Developers deploying to Kubernetes, engineers preparing for the CKAD, CKA or CKS certification, and platform, DevOps and SRE engineers who want to understand the cluster rather than memorise commands.

Common questions

Does this cover the CKAD, CKA and CKS exams?

Yes. Every competency in the official CKAD, CKA and CKS curricula for Kubernetes v1.35 is mapped to a lesson; the exam blueprint page lists them line by line. The timed drills practise the hands-on format of the exams.

Do I need a cluster or Docker installed?

No. The cluster is simulated in your browser. You can type kubectl commands and see realistic output without installing anything.

Should I learn Linux and networking first?

It helps. Kubernetes is built from Linux processes, namespaces and cgroups, and from ordinary networking. The Linux and Networking subjects on this site cover exactly the parts Kubernetes relies on.