Get in Touch

Course Outline

Introduction to Self-Managed Kubernetes

  • Overview of Kubernetes architecture and core components
  • Evaluating trade-offs between managed and self-managed Kubernetes
  • Addressing vendor lock-in concerns and achieving sovereignty benefits
  • Deployment methods: kubeadm, kOps, and manual installation processes

Infrastructure Planning

  • Determining hardware sizing for control plane and worker nodes
  • Assessing high availability requirements and network topologies
  • Selecting and preparing operating systems (Ubuntu, RHEL, Rocky Linux)
  • Establishing network prerequisites and configuring firewalls

Installing Container Runtimes

  • Comparing container runtime options: containerd vs. CRI-O
  • Steps for installing and configuring containerd
  • Steps for installing and configuring CRI-O
  • Key considerations for runtime security

Bootstrapping the Cluster with kubeadm

  • Installation of kubeadm, kubelet, and kubectl components
  • Initializing the primary control plane node
  • Configuring kubeconfig for secure cluster access
  • Adding additional control plane nodes to ensure high availability
  • Connecting worker nodes to the newly formed cluster

Configuring High Availability

  • Distinguishing between stacked and external etcd topologies
  • Deploying HAProxy or Keepalived for API server load balancing
  • Managing certificates and setting up renewal processes
  • Developing backup and recovery strategies for etcd data

Container Networking

  • Selecting CNI plugins: Calico, Cilium, Flannel, Weave
  • Installing and configuring Calico network plugin
  • Implementing network policies for enhanced security
  • Facilitating node-to-node communication and pod networking
  • Exposing services without relying on cloud load balancers

Service Load Balancing

  • Utilizing MetalLB for bare-metal load balancing capabilities
  • Configuring Layer 2 and BGP operational modes
  • Evaluating Keepalived and HAProxy as alternative solutions
  • Deploying ingress controllers such as nginx or Traefik

Storage Solutions

  • Understanding storage classes and CSI driver mechanisms
  • Implementing local persistent volumes
  • Setting up NFS provisioners
  • Evaluating distributed storage options: Ceph RBD, OpenEBS
  • Leveraging snapshot and cloning functionalities

Cluster Security

  • Managing Certificate Authorities and Public Key Infrastructure (PKI)
  • Configuring RBAC policies and managing service accounts
  • Enforcing pod security standards and admission controllers
  • Securing the API server and etcd components
  • Implementing image signing and verification processes

Self-Hosted Container Registry

  • Deploying the Harbor registry platform
  • Setting up Docker Registry instances
  • Configuring image replication and vulnerability scanning tools
  • Establishing registry authentication and integration workflows

Monitoring and Observability

  • Deploying the Prometheus and Grafana stack
  • Evaluating VictoriaMetrics as a lightweight alternative
  • Collecting metrics from nodes and pods
  • Creating custom alerting rules and dashboards
  • Aggregating logs using Loki or Fluentd

Cluster Maintenance

  • Upgrading Kubernetes versions using kubeadm
  • Performing rolling updates for control plane components
  • Executing certificate rotation procedures
  • Conducting node maintenance and cordoning operations

Backup and Disaster Recovery

  • Procedures for etcd backup and restoration
  • Utilizing Velero for backing up cluster resources and persistent volumes
  • Developing cross-site replication strategies
  • Validating recovery procedures through testing

Multi-Cluster Management

  • Using Rancher or Portainer for centralized cluster management
  • Understanding cluster federation concepts
  • Implementing workload distribution strategies

Requirements

  • Foundational knowledge of containers and containerization concepts
  • Practical experience in Linux system administration
  • Basic understanding of networking principles
  • Familiarity with command-line interfaces and SSH protocols

Target Audience

  • DevOps/SRE engineers
  • System administrators
  • Technical architects
  • Infrastructure engineers aiming for vendor independence
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories