Kubernetes
From core primitives (pods, services, deployments) to advanced operators and CRDs.
“Duolingo for DevOps. One concept = one 2-4 minute video. Never introduce a concept before its prerequisites. Every lesson builds on the last.”
0 / 99 lessons readyaudience: devops & sre99 lessons planned
1. Kubernetes Core
65 lessonsKubernetes is where most beginners drown. This module carves it into tiny lessons — one primitive at a time, each with a concrete visual mental model.
Why Kubernetes Exists
- What problem does Kubernetes solve?2m 30sComing soon
- From Borg to Kubernetes — the lineage3m 00sComing soon
- Desired state vs actual state3m 30sComing soon
- Declarative vs imperative3m 00sComing soon
Cluster Architecture
- Cluster, nodes, control plane3m 30sComing soon
- The API server — Kubernetes' front door3m 30sComing soon
- etcd — the cluster's source of truth3m 30sComing soon
- The scheduler — placing pods on nodes3m 30sComing soon
- Controller manager and control loops3m 30sComing soon
- kubelet — the node agent3m 00sComing soon
- kube-proxy and iptables rules3m 30sComing soon
- CRI — how kubelet runs containers3m 30sComing soon
YAML and Manifests
- YAML basics3m 30sComing soon
- Manifest structure — apiVersion, kind, metadata, spec3m 30sComing soon
- kubectl apply — declarative in action3m 00sComing soon
- Labels and selectors3m 30sComing soon
- Annotations vs labels3m 00sComing soon
Pods
- What is a Pod?2m 30sComing soon
- Pod lifecycle — pending, running, succeeded, failed3m 30sComing soon
- Multi-container pods3m 30sComing soon
- Init containers3m 30sComing soon
- Sidecar containers3m 30sComing soon
- Liveness, readiness, startup probes4m 00sComing soon
- resources.requests vs resources.limits3m 30sComing soon
Deployments and Workloads
- ReplicaSets3m 00sComing soon
- Deployments — desired state3m 30sComing soon
- Rolling updates without downtime4m 00sComing soon
- Rollback in one command3m 00sComing soon
- DaemonSets — one pod per node3m 30sComing soon
- Jobs — run to completion3m 30sComing soon
- CronJobs — jobs on a schedule3m 30sComing soon
Kubernetes Networking
- Services — a stable address for pods3m 30sComing soon
- ClusterIP — the default3m 00sComing soon
- NodePort — exposing on every node3m 00sComing soon
- LoadBalancer service3m 30sComing soon
- Headless services3m 30sComing soon
- Endpoints and EndpointSlices3m 30sComing soon
- Ingress — routing traffic in3m 30sComing soon
- Ingress controllers — nginx, traefik3m 30sComing soon
- CoreDNS and service discovery3m 30sComing soon
- Network policies — firewalls for pods4m 00sComing soon
ConfigMaps and Secrets
- ConfigMaps — config as data3m 30sComing soon
- Secrets — sensitive config3m 30sComing soon
- envFrom and env — injecting into pods3m 30sComing soon
- Config as mounted files3m 30sComing soon
- Secret types — Opaque, TLS, dockerconfigjson3m 30sComing soon
- Rotating secrets safely4m 00sComing soon
Storage
- Volumes in Kubernetes3m 30sComing soon
- PersistentVolumes4m 00sComing soon
- PersistentVolumeClaims3m 30sComing soon
- StorageClasses and dynamic provisioning4m 00sComing soon
- CSI — the storage plug-in interface4m 00sComing soon
- Reclaim policies — delete vs retain3m 30sComing soon
Namespaces and RBAC
- Namespaces — logical isolation3m 00sComing soon
- ResourceQuotas per namespace3m 30sComing soon
- LimitRanges3m 30sComing soon
- ServiceAccounts3m 30sComing soon
- RBAC — Role and RoleBinding4m 00sComing soon
- ClusterRole vs Role3m 30sComing soon
Debugging Kubernetes
- kubectl get and kubectl describe3m 30sComing soon
- kubectl logs — and when they lie3m 30sComing soon
- kubectl exec — a shell in a pod3m 30sComing soon
- kubectl get events — the debug goldmine3m 30sComing soon
- kubectl port-forward for local debugging3m 30sComing soon
- CrashLoopBackOff — reading the signal4m 00sComing soon
2. Kubernetes Advanced
34 lessonsOnce you can deploy a stateless service, the next tier: scheduling, autoscaling, stateful workloads, and extending Kubernetes itself.
Advanced Scheduling
- Node affinity — where should this pod land?4m 00sComing soon
- Pod affinity and anti-affinity4m 00sComing soon
- Taints and tolerations4m 00sComing soon
- PriorityClasses and preemption4m 00sComing soon
- Topology spread constraints4m 00sComing soon
- PodDisruptionBudgets4m 00sComing soon
Autoscaling
- metrics-server — the source of truth3m 30sComing soon
- Horizontal Pod Autoscaler4m 00sComing soon
- Vertical Pod Autoscaler4m 00sComing soon
- Cluster Autoscaler4m 00sComing soon
- KEDA — event-driven autoscaling4m 00sComing soon
- QoS classes and eviction4m 00sComing soon
StatefulSets and Storage
- StatefulSets vs Deployments4m 00sComing soon
- Stable network identities for pods4m 00sComing soon
- PVC-to-PV binding rules4m 00sComing soon
- Ordered pod startup and shutdown4m 00sComing soon
- Backup and restore patterns4m 00sComing soon
- Should you run a database in Kubernetes?4m 00sComing soon
Operators and CRDs
- Custom Resource Definitions4m 00sComing soon
- The Operator pattern4m 00sComing soon
- operator-sdk and kubebuilder4m 00sComing soon
- Finalizers — cleanup on delete4m 00sComing soon
- Admission controllers4m 00sComing soon
- Mutating vs validating webhooks4m 00sComing soon
- Gatekeeper and OPA policies4m 00sComing soon
Service Mesh
- What is a service mesh?4m 00sComing soon
- Istio — a quick tour4m 00sComing soon
- Linkerd — the lightweight alternative4m 00sComing soon
- Envoy sidecars4m 00sComing soon
- mTLS between services4m 00sComing soon
- Canary and traffic splitting4m 00sComing soon
Gateway API and Modern Routing
- Gateway API vs Ingress4m 00sComing soon
- HTTPRoute and TCPRoute4m 00sComing soon
- Multi-cluster Kubernetes — the shape4m 00sComing soon