Learn Kubernetes on a real cluster.
Every episode is a real terminal session: commands typed live on a real Kubernetes cluster, recorded and narrated, one a day. Sixty episodes, from your first cluster to a production checklist.
New episode every morning at 7:30 AM Pacific.
Episodes
Four parts of fifteen. Each title turns into a link the morning its episode goes public.
Part 1 · Kubernetes from zero
- 01 Kubernetes Tutorial for Beginners: Your First Cluster Heals Itself
- 02 Docker Containers Explained: Run, Inspect and Stop a Container
- 03 Dockerfile Tutorial: Build Your Own Container Image
- 04 Run Your Own Image in Kubernetes: kind and a Local Registry
- 05 Kubernetes Pods Explained: Run, Describe, Logs and Exec
- 06 Kubernetes Labels and Selectors: How Kubernetes Finds Your Pods
- 07 Kubernetes Deployments: Rolling Updates and Rollbacks
- 08 Kubernetes Services Explained: ClusterIP, DNS and Load Balancing
- 09 Reach Your App From Outside: kubectl port-forward vs NodePort
- 10 Kubernetes Namespaces: Organize and Isolate Workloads
- 11 Kubernetes ConfigMaps: Environment Variables vs Mounted Files
- 12 Kubernetes Secrets: Why Base64 Is Not Encryption
- 13 kubectl apply, diff and explain: Declarative Kubernetes
- 14 Kubernetes Probes: Liveness, Readiness and Startup
- 15 Kubernetes Requests and Limits: OOMKilled and Pending, Live
Part 2 · Running real apps
- 16 Multi-Node Kubernetes With kind: Where Do Pods Land?
- 17 Kubernetes Node Affinity and Pod Anti-Affinity
- 18 Kubernetes Taints and Tolerations Explained
- 19 Kubernetes Topology Spread Constraints: Even Pods Across Zones
- 20 Kubernetes Persistent Volumes: Data That Survives a Pod
- 21 Kubernetes StatefulSets: Stable Names and Storage
- 22 Kubernetes Jobs and CronJobs: Run Tasks to Completion
- 23 Kubernetes DaemonSets: One Pod on Every Node
- 24 Kubernetes Init Containers and Native Sidecars
- 25 Kubernetes Rolling Updates: maxSurge and maxUnavailable
- 26 Blue-Green and Canary Deployments in Kubernetes
- 27 Kubernetes Gateway API: Route Traffic by Host and Path
- 28 Helm Tutorial: Install, Upgrade and Roll Back a Chart
- 29 Kustomize Tutorial: One Base, Many Environments
- 30 Kubernetes Autoscaling: HPA Under Real Load
Part 3 · Secure by default
- 31 Kubernetes RBAC Explained: Roles, Bindings and can-i
- 32 Kubernetes Service Accounts: What Your Pods Can Do
- 33 Kubernetes ClusterRoles: view, edit and admin
- 34 Audit Kubernetes RBAC: Find Over-Privileged Accounts
- 35 Kubernetes Network Policies: Default Deny, Then Allow
- 36 Kubernetes Egress Network Policies: Allow DNS, Block the Rest
- 37 Kubernetes Pod Security Standards: Enforce Restricted
- 38 Kubernetes securityContext: Harden Every Container
- 39 Kubernetes Secrets in etcd: Why Encryption at Rest Matters
- 40 Container Image Security: Digests, Tags and Scanning
- 41 Kubernetes Admission Policies With CEL: Block Bad Deployments
- 42 Kubernetes ResourceQuotas and LimitRanges
- 43 Kubernetes Audit Logs: See Who Did What
- 44 Kubernetes Users and kubeconfig: Certificates and Contexts
- 45 Kubernetes Security Review: Fix a Risky Workload
Part 4 · Operate and debug
- 46 Fix CrashLoopBackOff in Kubernetes: Logs, Events and Exit Codes
- 47 Fix ImagePullBackOff: Tags, Registries and Pull Secrets
- 48 Why Is My Pod Pending? Kubernetes Scheduling Failures
- 49 Debug Kubernetes Services: Empty Endpoints and DNS
- 50 kubectl debug: Ephemeral Containers and Node Debugging
- 51 Kubernetes Events and Logs Across Many Pods
- 52 Kubernetes Node Maintenance: Cordon, Drain and PDBs
- 53 Kubernetes Graceful Shutdown: preStop Hooks and SIGTERM
- 54 Back Up Kubernetes: etcd Snapshots and Manifests
- 55 Kubernetes API Deprecations: Find Old APIs Before an Upgrade
- 56 Kubernetes Monitoring Basics: kubectl top and metrics-server
- 57 GitOps With Argo CD on a Local Cluster
- 58 Right-Size Kubernetes Pods: Requests From Real Usage
- 59 Kubernetes Multi-Tenancy: Namespaces, RBAC, Quotas, Policies
- 60 Kubernetes Production Checklist: 20 Checks on One App
The free field guide
Every command from the series, with what it does, one section per episode. Download it now with no email required, or join the list to get each new section as the series airs.
Kubernetes Hands-On Field Guide
Every command from the series, with what it does. It grows as new episodes air.
Download the PDF →Get each new section by email.
The field guide plus a short note as new episodes air. Free.
No spam. Unsubscribe anytime.
Kubernetes is a registered trademark of The Linux Foundation. Kubernetes Hands-On is an independent series from AIS and is not affiliated with or endorsed by The Linux Foundation.