Kubernetes Zero-to-Hero
From your first container to running production clusters with GitOps, autoscaling, service mesh, and CKA-level operations.
Start the courseA complete, hands-on path through containers and Kubernetes: images and Docker, the cluster architecture, the core objects, Helm packaging, networking and service mesh, storage, autoscaling, security and policy, GitOps delivery, observability, and managed Kubernetes (AKS/EKS/GKE) — finishing with a production capstone and CKA/CKAD/CKS interview prep.
What you’ll be able to do
- Explain containers vs VMs vs serverless and build/run Docker images confidently
- Describe the Kubernetes control plane and node components and what each does
- Deploy and operate workloads with Pods, Deployments, Services, ConfigMaps and Helm
- Design pod networking, ingress/Gateway API and a service mesh with zero-trust mTLS
- Autoscale (HPA/KEDA/Karpenter), manage storage, and enforce policy and supply-chain security
- Deliver with GitOps (Argo CD / Flux) and run Day-2 ops, observability and backup/restore
- Operate managed Kubernetes (AKS/EKS/GKE) and be ready for CKAD/CKA/CKS and platform roles
Prerequisites
- Comfort with a Linux shell and basic networking (helpful, not mandatory)
- Docker Desktop or Podman, plus a free local cluster (kind / minikube / k3d) for the labs
Who it’s for
Developers and sysadmins new to containers, engineers moving to Kubernetes, and anyone targeting CKAD/CKA/CKS or real platform/SRE work.
Curriculum
Tier 1 · Foundation — Containers & the Cloud-Native Model
Start at the very beginning: containers, images, and how they differ from VMs and serverless.
- 1 Containers vs Serverless vs VMs: Picking a Compute Model
- 2 Containers & Docker Basics: Images, Layers, and Registries
- 3 Mastering Multi-Stage Dockerfiles: BuildKit Cache Mounts, Slim Images & Reproducible Builds
- 4 Multi-Architecture Container Builds with docker buildx bake: Remote Cache, Provenance, and Registry-Native Pipelines
Tier 1 · Foundation — Kubernetes Core Concepts (KCNA)
The cluster model and the core objects, hands-on with kubectl.
- 5 What Is Kubernetes? Control Plane, Nodes, etcd & the kubelet
- 6 Kubernetes Architecture Deep-Dive: Control Plane, etcd, Scheduler & the Request Flow
- 7 Pods, ReplicaSets, Deployments & Services: The Core Objects
- 8 kubectl First Steps: Your First Local Cluster & Deployment
- 9 Docker, kubectl & Helm: The Practical Command Reference (Basic → Advanced)
- 10 Kubernetes Pods, In Depth: Containers, Probes, Lifecycle, Init & Every Field
- 11 Kubernetes Deployments & ReplicaSets, In Depth: Rollouts, Rollback & Strategies
- 12 kubectl Mastery: Imperative vs Declarative, Contexts, and Every Core Command
- 13 Kubernetes Namespaces, ResourceQuotas & LimitRanges, In Depth
- 14 Kubernetes Labels, Selectors, Annotations & Field Selectors, In Depth
Tier 2 · Intermediate — Workloads & Scheduling (CKAD)
Run real workloads: scheduling, stateful apps, and autoscaling.
- 15 Advanced Kubernetes Scheduling: Affinity, Topology Spread Constraints, Taints, and Priority-Based Preemption
- 16 Running Stateful PostgreSQL on Kubernetes: StatefulSets, Operators, Automated Failover, and Point-in-Time Recovery
- 17 Kubernetes Autoscaling in Depth: HPA, KEDA Event-Driven Scaling & Node Autoscaling
- 18 Right-Sizing Kubernetes Workloads: Vertical Pod Autoscaler, Resource Recommendations, and Bin-Packing Efficiency
- 19 Kubernetes Jobs, CronJobs & DaemonSets, In Depth
- 20 Kubernetes StatefulSets, In Depth: Stable Identity, Ordered Lifecycle & Per-Pod Storage
- 21 Kubernetes Pod Autoscaling, In Depth: the HPA Algorithm, Metrics & VPA
Tier 2 · Intermediate — Packaging & Configuration (CKAD)
Package and configure apps: Helm, Kustomize and Dapr.
- 22 Authoring Production-Grade Helm Charts: Library Charts, Values Schemas & CI Testing
- 23 Helm for Complex Releases: Umbrella Charts, Library Charts, Lifecycle Hooks, and Safe Rollbacks
- 24 Kustomize in Depth: Overlays, Components, Strategic Merge Patches, and Secret/Config Generators
- 25 Configure Dapr on Kubernetes for Service Invocation, State, and Pub/Sub Building Blocks
- 26 Helm Fundamentals: Charts, Templates, Values, Releases & Repositories
- 27 Kubernetes ConfigMaps & Secrets, In Depth: Injection, Mounting, Immutability & Encryption
- 28 The Kubernetes Downward API, In Depth: Exposing Pod & Container Metadata to Workloads
Tier 2 · Intermediate — Networking & Ingress
Connect and expose workloads: network policies, the Gateway API, and bare-metal load balancing.
- 29 Designing Zero-Trust Pod Networking: Default-Deny NetworkPolicies and Cilium L7-Aware Rules
- 30 Adopting the Kubernetes Gateway API: GatewayClass, HTTPRoute Traffic Splitting, and Migrating off Ingress
- 31 Deploy MetalLB and kube-vip for Bare-Metal Kubernetes Load Balancing
- 32 Kubernetes Services & Networking, In Depth: ClusterIP, NodePort, LoadBalancer, Headless & DNS
- 33 Kubernetes Ingress, In Depth: Controllers, Rules, TLS, IngressClass & the Gateway API
Tier 2 · Intermediate — Storage
Persist data: the CSI, volume snapshots, cloning and resize.
Tier 2 · Intermediate — Production Readiness (Day-2)
What makes a workload production-ready: probes, PDBs, QoS, graceful shutdown and the Day-2 checklist.
Tier 3 · Advanced — Cluster Provisioning & Operations (CKA)
Build and run the cluster itself: kubeadm HA, immutable clusters, etcd backup and upgrades.
- 37 Provisioning Production Kubernetes: kubeadm, HA Control Plane, etcd Backup & Upgrades
- 38 Deploy Talos Linux Immutable Kubernetes Nodes with Cluster API
- 39 Set Up etcd Snapshot Backups and Disaster Restore for Self-Managed Kubernetes
- 40 Kubernetes Worker Node Internals, In Depth: kubelet, the CRI, kube-proxy & cgroups
Tier 3 · Advanced — Security & Supply Chain (CKS)
Harden everything: RBAC, Pod Security, policy engines, image signing, runtime security and secrets.
- 41 Designing Least-Privilege RBAC in Kubernetes: Roles, Aggregation & Auditing at Scale
- 42 Migrating to Pod Security Admission: Enforcing Baseline and Restricted Profiles Without Breaking Workloads
- 43 Deploy Kyverno Policies to Enforce Image Signing, Resource Limits, and Pod Security
- 44 Policy-as-Code with Kyverno: Validate, Mutate, Generate, and Verify Image Signatures Admission-Time
- 45 Policy-as-Code Guardrails with OPA Gatekeeper: Constraint Templates, Mutation, and CI Gating
- 46 Securing the Container Supply Chain: Signing with Cosign, SBOMs, and SLSA Provenance
- 47 Deploy Trivy Operator on Kubernetes for Continuous Vulnerability and Config Auditing
- 48 Configure Vault JWT/OIDC and Kubernetes Auth Methods for Secretless Workload Access
- 49 Hardening the Docker Daemon: Rootless Mode, User Namespace Remapping, and Custom seccomp/AppArmor Profiles
- 50 Working Directly with containerd: nerdctl, Encrypted Images, and Sandboxed Runtimes via RuntimeClass
- 51 Kubernetes RBAC & Service Accounts, In Depth (Fundamentals)
- 52 Kubernetes Admission Control, In Depth: Validating & Mutating Webhooks + ValidatingAdmissionPolicy
- 53 Kubernetes Security Contexts, In Depth: runAsNonRoot, Capabilities, seccomp & AppArmor
Tier 3 · Advanced — Networking Deep & Service Mesh
Datapath and mesh: Cilium/eBPF, Istio ambient, Linkerd, and cluster mesh.
- 54 Cilium and eBPF Network Policy: L3-L7 Segmentation and Hubble Flow Visibility
- 55 Istio Ambient Mesh in Practice: Zero-Trust mTLS, Traffic Management & L7 Authorization
- 56 Deploy Istio Ambient Mesh Waypoint Proxies for L7 Authorization Policies
- 57 Linkerd in Production: Automatic mTLS, Retry/Timeout Budgets, and Multicluster Failover
- 58 Cilium Beyond CNI: Cluster Mesh, Egress Gateway, and the BGP Control Plane
- 59 Kubernetes Networking Internals, In Depth: The Network Model, CNI, IPAM & the Datapath
Tier 3 · Advanced — GitOps & Progressive Delivery
Declarative delivery at scale: Argo CD, Flux, and progressive rollouts.
- 60 GitOps at Scale with Argo CD: App-of-Apps, ApplicationSets & Progressive Delivery
- 61 Scaling GitOps with Argo CD: App-of-Apps, ApplicationSets, and Multi-Cluster Fan-Out
- 62 GitOps with Flux: Image Update Automation, OCI Artifact Sources, and Hard Multi-Tenancy
- 63 Flux CD GitOps at Scale: Monorepo Structure, Kustomize Overlays, and Multi-Tenancy
- 64 Blue-Green on Kubernetes with Argo Rollouts: Preview Services, Analysis Gates, and Automated Promotion
- 65 Progressive Delivery on Kubernetes with Argo Rollouts: Canary, Analysis, and Automated Rollback
Tier 3 · Advanced — Observability & SRE
See inside the cluster: OpenTelemetry, APM and logs with SigNoz, Datadog, New Relic and Dynatrace.
- 66 Deploy SigNoz on Kubernetes for OpenTelemetry-Native APM and Log Management
- 67 Deploy the Datadog Agent and Cluster Agent on Kubernetes with APM and Log Collection
- 68 Deploy New Relic Infrastructure and APM Agents on Kubernetes with Pixie
- 69 Deploy Dynatrace OneAgent and OpenTelemetry Collector on EKS for Full-Stack Observability
- 70 Kubernetes Monitoring, In Depth: metrics-server, Prometheus, Grafana & Alerting
Tier 3 · Advanced — Backup, Recovery & DR
Protect cluster state and data: Velero, cross-cluster restore and application-consistent backups.
Tier 3 · Advanced — Extending Kubernetes
Build on the platform: operators with kubebuilder and aggregated API servers / CRDs.
Tier 4 · Expert — Multi-Tenancy & Platform Engineering
Run a platform many teams share: multi-tenancy, an internal developer portal, and cost control.
Tier 4 · Expert — Enterprise Architecture & Design
Design enterprise Kubernetes: managed-platform tradeoffs, reference microservices architectures, and modernisation.
- 80 Understanding Managed Kubernetes: AKS, EKS, and GKE Compared
- 81 Azure Enterprise Architecture: Production Microservices on AKS
- 82 AWS Enterprise Architecture: Production Microservices on EKS
- 83 GCP Enterprise Architecture: Production Microservices on GKE
- 84 Migrating a Monolith to Microservices on GKE: A Pragmatic Path
Tier 5 · Specialist — Amazon EKS
Master EKS: pod identity, Karpenter, VPC CNI networking, and fleet upgrades.
- 85 Running EKS at Scale: Pod Identity, Karpenter Autoscaling, and VPC CNI Networking
- 86 EKS Cluster Upgrades: Version Lifecycle, Add-on Compatibility, and Fleet Operations
- 87 Migrating EKS Workloads from IRSA to EKS Pod Identity: Mechanics, Trust, and Rollout
- 88 Solving EKS IP Exhaustion: VPC CNI Prefix Delegation, Custom Networking, and Security Groups for Pods
- 89 Deploy Karpenter on EKS with Consolidation, Spot Diversification, and Disruption Budgets
Tier 5 · Specialist — Azure AKS
Master AKS: day-2 upgrades, networking/observability, the Istio add-on, secrets CSI, Gateway and Arc.
- 90 AKS Day-2 Operations: Cluster Upgrades, Node Lifecycle, and Fleet Management
- 91 Production-Grade AKS: Networking, Ingress, and Observability
- 92 Running the Managed Istio Add-on on AKS: mTLS, Ingress Gateways, and Egress Control
- 93 Secrets Store CSI Driver on AKS: Mounting Key Vault Secrets with Rotation and K8s Sync
- 94 Application Gateway for Containers: Gateway API on AKS with Traffic Splitting, mTLS, and Header Routing
- 95 Azure Arc-Enabled Kubernetes: GitOps, Policy, and Fleet Governance for Hybrid Clusters
Tier 5 · Specialist — Google GKE
Master GKE: Autopilot hardening, Dataplane V2, the multi-cluster Gateway API, and Workload Identity.
Tier 5 · Specialist — Data & Streaming on Kubernetes
Run stateful data platforms: Kafka, Confluent, Flink, Trino and Airflow on Kubernetes.
- 100 Self-Managed Kafka on Kubernetes with Strimzi for a Trading Platform
- 101 Deploy Confluent Platform for Apache Kafka on Kubernetes with the Confluent Operator
- 102 Deploy Apache Flink on Kubernetes with the Flink Operator, Checkpointing, and Savepoints
- 103 Deploy Trino on Kubernetes for Federated Query Across Hive, Iceberg, and PostgreSQL
- 104 Deploy Apache Airflow on Kubernetes with the Official Helm Chart and KubernetesExecutor
Tier 5 · Specialist — AI/ML on Kubernetes
Serve models at scale: GPU scheduling and LLM inference platforms on Kubernetes.
Track · Troubleshooting (Easy → Complex)
Diagnose anything: a method and per-area playbooks, then control-plane/etcd complex incident RCA.
Track · Architecting (Easy → Complex)
Turn requirements into designs: a six-rung ladder from a single cluster to multi-region mission-critical.
Track · Certification Center
Pass the CNCF exams: the KCNA/CKAD/CKA/CKS prep kit plus interview & certification preparation.
Track · Job-Ready — Projects, Capstone & Interview
Get hired: a production capstone and a six-project portfolio ladder.