← All courses

Training

Kubernetes and Docker Course

Kubernetes and Docker Course

Course Overview: Containerization has changed the DevOps game completely, with Docker and Kubernetes playing important roles in altering the flow of app creation and deployment. This course will help you acquire the knowledge and tools required to integrate Kubernetes clusters in an enterprise environment.

What you’ll learn: The course begins by introducing you to Docker and Kubernetes fundamentals, including a review of basic Kubernetes objects. You’ll then get to grips with containerization and understand its core functionalities, including how to create ephemeral multi node clusters using KinD. As you make progress, you’ll learn about cluster architecture, Kubernetes cluster deployment, and cluster management, and get started with application deployment. Moving on, you’ll find out how to integrate your container to a cloud platform and integrate tools including MetalLB, externalDNS, OpenID connect (OIDC), pod security policies (PSPs), Open Policy Agent (OPA), Falco, and Velero. Finally, you will discover how to deploy an entire platform to the cloud using continuous integration and continuous delivery (CI/CD).

By the end of this course, you will have learned how to create development clusters for testing applications and Kubernetes components, and be able to secure and audit a cluster by implementing various open-source solutions including OpenUnison, OPA, Falco, Kibana, and Velero.

Section 1: Docker Containers and Fundamentals

  1. Docker and Container Essentials
    1. Introduction
    2. Understanding the need for containerization
    3. Understanding Docker
    4. Installing Docker
    5. Using the Docker CLI
  2. Working with Docker Data
    1. Introduction
    2. Why you need persistent data
    3. Docker Volumes
    4. Docker bind mounts
    5. Docker tmpfs mounts
  3. Understanding Docker Networking
    1. Introduction
    2. Exploring Docker Networking
    3. Creating user-defined bridge networks

Section 2: Creating Kubernetes Development Clusters,understanding objects, and Exposing Services

  1. Deploying Kubernetes using KinD
    1. Introduction
    2. Kubernetes components and objects
    3. Installing KinD
    4. Creating a KinD cluster
    5. Reviewing KinD cluster
    6. Adding a custom load balancer for Ingress
  2. K8 Bootcamp
    1. Understanding full components of K8
    2. Exploring the control panel
    3. Understanding the worker node component
    4. Interacting with the API server
    5. K8 objects
  3. Services, Load Balancing, and External DNS
    1. Introduction
    2. Exposing workloads to requests
    3. Introduction to load balancer
    4. Layer 7 load balancers
    5. Layer 4 load balancers
    6. Making service names available externally

Section 3: Running Kubernetes in the Enterprise

  1. Integrating Authentication into your Cluster
    1. Introduction
    2. Understanding how Kubernetes knows who you are
    3. Understanding OpenID Connect
    4. Configuring KinD for OpenID Connect
    5. Introducing impersonation to integrate authentication with cloud-managed clusters
    6. Configuring your cluster for impersonation
    7. Configuring Impersonation without OpenUnison
  2. RBAC Policies and Auditing
    1. Introduction
    2. What's a Role?
    3. Mapping enterprise identities to Kubernetes to authorize access to resources
    4. Implementing namespace multi-tenancy
    5. Kubernetes auditing
    6. Using audit2rbac to debug policies
  3. Deploying a Secured Kubernetes Dashboard
    1. Introduction
    2. How does the dashboard know who you are?
    3. Understanding dashboard security risks
    4. Deploying the dashboard with a reverse proxy
    5. Integrating the dashboard with OpenUnison
  4. Creating PodSecurityPolicies
    1. Introduction
    2. What is a PodSecurityPolicy?
    3. Enabling PSPs
    4. Alternatives to PSPs
  5. Extending Security Using Open Policy Agent
    1. Introduction
    2. Introduction to dynamic admission controllers
    3. What is OPA and how does it work?
    4. Using Rego to write policies
    5. Enforcing memory constraints
    6. Enforcing Pod Security Policies using OPA
  6. Auditing using Falco and EFK
    1. Introduction
    2. Exploring auditing
    3. Introducing Falco
    4. Exploring Falco's configuration files
    5. Deploying Falco
    6. Falco kernel module
  7. Backing Up Workloads
    1. Introduction
    2. Understanding Kubernetes backups
    3. Performing an etcd backup
    4. Introducing and setting up Heptio's Velero
    5. Using Velero to back up workloads
    6. Managing Velero using the CLI
    7. Restoring from a backup
  8. Provisioning a Platform
    1. Introduction
    2. Designing a pipeline
    3. Preparing our cluster
    4. Deploying GitLab
    5. Deploying Tekton
    6. Deploying ArgoCD
    7. Automating project onboarding using OpenUnison

Practical, connected learning

My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.