CLOUD / PLATFORM ENGINEERING

Kubernetes from Zero: Containers, Clusters, and Operations

Build the substrate knowledge that production platforms depend on

CURRICULUM

A beginner-first path from laptop processes and containers through Kubernetes workloads, networking, storage, security, and troubleshooting, using the public HelixWorks monorepo as one recurring system.

  1. 00Build HelixWorks from Laptop to AWS: the 61-Day Dependency MapPublished 21 Jun 20266 sections
  2. 01Docker FundamentalsPublished 21 Jun 202613 sections
  3. 02How To Dockerize a ProjectPublished 21 Jun 202614 sections
  4. 03Multi-Stage Docker BuildPublished 21 Jun 202614 sections
  5. 04Why Kubernetes Is UsedPublished 21 Jun 202612 sections
  6. 05What is Kubernetes? Architecture ExplainedPublished 21 Jun 202612 sections
  7. 06Multi-Node Cluster Setup with KindPublished 21 Jun 202614 sections
  8. 07Pods: Imperative vs Declarative & YAMLPublished 21 Jun 202615 sections
  9. 08Deployment, Replication Controller & ReplicaSetPublished 21 Jun 202614 sections
  10. 09Kubernetes Services: ClusterIP vs NodePort vs LoadBalancer vs ExternalNamePublished 21 Jun 202615 sections
  11. 10Kubernetes NamespacesPublished 21 Jun 202616 sections
  12. 11Multi-Container Pods: Sidecar vs Init ContainerPublished 21 Jun 202617 sections
  13. 12DaemonSet, Job & CronJobPublished 21 Jun 202615 sections
  14. 13Static Pods, Manual Scheduling, Labels & SelectorsPublished 21 Jun 202614 sections
  15. 14Taints and TolerationsPublished 21 Jun 202615 sections
  16. 15Node AffinityPublished 21 Jun 202618 sections
  17. 16Resource Requests and LimitsPublished 21 Jun 202617 sections
  18. 17Autoscaling: HPA vs VPAPublished 21 Jun 202615 sections
  19. 18Health Probes: Liveness vs Readiness (vs Startup)Published 21 Jun 202618 sections
  20. 19ConfigMap and SecretPublished 21 Jun 202616 sections
  21. 20SSL/TLS Explained SimplyPublished 21 Jun 202623 sections
  22. 21TLS in KubernetesPublished 21 Jun 202620 sections
  23. 22Authentication and AuthorizationPublished 21 Jun 202613 sections
  24. 23RBAC: Role and RoleBindingPublished 21 Jun 202615 sections
  25. 24ClusterRole and ClusterRoleBindingPublished 21 Jun 202616 sections
  26. 25Service AccountsPublished 21 Jun 202614 sections
  27. 26Network PoliciesPublished 21 Jun 202615 sections
  28. 27Production Multi-Node Cluster with kubeadmPublished 21 Jun 202621 sections
  29. 28Docker Storage FundamentalsPublished 21 Jun 202614 sections
  30. 29Storage in Kubernetes (Volumes, PV, PVC, StorageClass)Published 21 Jun 202618 sections
  31. 30How DNS Works55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202612 sections
  32. 31DNS in Kubernetes (CoreDNS)55 Days of Kubernetes playlist: • [https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGC](https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGC)Published 21 Jun 202613 sections
  33. 32Kubernetes Networking (CNI & Container Runtimes)55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202613 sections
  34. 33Ingress Controllers and Ingress Resources55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202618 sections
  35. 34Cluster Version Upgrade with kubeadm55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202616 sections
  36. 35etcd Backup and Restore55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202614 sections
  37. 36Monitoring, Logging, and Alerting55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202612 sections
  38. 37Troubleshoot Application Failure55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202613 sections
  39. 38Troubleshoot Cluster Component Failure55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202614 sections
  40. 39Network Troubleshooting & Node Maintenance55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202612 sections
  41. 40JSONPath & Advanced kubectl55 Days of Kubernetes playlist: • https://www.youtube.com/playlist?list=PLl4APkPHzsUUOkOv3i62UidrLmSB8DcGCPublished 21 Jun 202614 sections
  42. 41CKA Exam Tips: How to Clear the CKA ExamCKA prep • Exam strategy, killer.sh, time management, kubectl speed, must-know topicsPublished 22 Jun 202614 sections
  43. 42Host Your Private Docker Registry on KubernetesCKA prep • Run registry:2 in-cluster with PVC persistence, TLS, htpasswd auth, imagePullSecretsPublished 22 Jun 202615 sections
  44. 43Helm ChartsCKA prep • The Kubernetes package manager: charts, templates/values, releases, reposPublished 22 Jun 202614 sections
  45. 44KustomizeCKA prep • Template-free customization: bases, overlays, patches, kubectl -kPublished 22 Jun 202615 sections
  46. 45StatefulSetsCKA prep • Stable identity, ordered rollout, headless Service, volumeClaimTemplatesPublished 22 Jun 202614 sections
  47. 46Pod Priority and PreemptionCKA prep • PriorityClass, preemption flow, scheduler behavior, globalDefault, preemptionPolicyPublished 22 Jun 202613 sections
  48. 47Kubernetes Gateway API: Ingress vs Gateway APICKA prep • GatewayClass / Gateway / HTTPRoute, the role-oriented model, why it supersedes IngressPublished 22 Jun 202615 sections
  49. 48Migrate Ingress to Gateway APICKA prep • ingress2gateway, mapping Ingress rules to HTTPRoute, step-by-step cutover, gotchasPublished 22 Jun 202614 sections
  50. 49Custom Resource Definitions (CRD & CR)Theme: teach the API server new object kinds without recompiling it.Published 22 Jun 202613 sections
  51. 50Kubernetes OperatorsTheme: encode a human operator's run-book as a controller that reconciles a CRD.Published 22 Jun 202612 sections
  52. 51Admission ControllersTheme: the gatekeepers that mutate and validate every request after authn/authz.Published 22 Jun 202613 sections
  53. 52Storage Classes: Static vs Dynamic ProvisioningTheme: stop hand-making PVs; let a provisioner carve volumes on demand.Published 22 Jun 202615 sections
  54. 53Install cri-dockerd Container Runtime on KubernetesTheme: why Docker needs a shim post-1.24 and how to wire one to the kubelet.Published 22 Jun 202614 sections
  55. 54Pod Security Standards, Linux Capabilities, and Security ContextTheme: lock pods down with PSS levels, capabilities, and a tight securityContext.Published 22 Jun 202614 sections
  56. 55Multi-Master Cluster Setup with Load BalancerTheme: survive a control-plane node loss with multiple masters behind an LB.Published 22 Jun 202614 sections
  57. 56Prometheus and Mimir: From Metric to IncidentBuild the whole path on Kind: an application emits a metric, Prometheus • scrapes it, Mimir stores it, a rule fires, Alertmanager routes it, and a local • webhook receives both the firing and resolved notifications. • Canonical deep dives: [Mimir’s distributed write/read architecture](/en/courses/observability-platform/day-09-mimir-distributed-metrics-backend) and [Prometheus remote-write delivery and recovery](/en/courses/observability-platform/day-10-prometheus-remote-write). This Kubernetes lab remains the hands-on metric-to-incident exercise.Published 17 Jul 202625 sections
  58. 57Kubernetes Memory: From Physical RAM to PodsWhat “increase memory” physically means—from DRAM and cloud machines to nodes, cgroups, containers, and pods.Published 06 Aug 202611 sections
  59. 58OOM-Killed Enterprise Workflow: Incident AnatomyFollow the enterprise AI workflow platform's failed request from physical RAM to Kubernetes evidence, then prove the smallest safe recovery.Published 11 Aug 20266 sections
  60. 59On-Premises Kubernetes: From Rack to ClusterBuild the machine, network, storage, and control-plane chain that keeps an enterprise AI workflow platform running when your team owns the data centre.Published 11 Aug 20266 sections
  61. 60Managed Kubernetes: Cloud Shared ResponsibilityDecide what a cloud Kubernetes service operates, what your team still owns, and where the enterprise AI workflow platform's OOM recovery actually lands.Published 11 Aug 20267 sections