DevOps Kubernetes Lab
Cloud Native

DevOps practices and orchestration of Kubernetes

Comprehensive DevOps guide: CI/CD pipelines, Docker containerization, kubernetes orchestration, monitoring, and infrastructure as code (IaC).

Docker Kubernetes GitLab CI Terraform

What is DevOps and Cloud Native

DevOps — a culture, practices, and tools that integrate development (Development) and operations (Operations) to accelerate software delivery. Cloud Native — an approach to building and running applications that leverages the benefits of cloud computing.

01

Continuous Integration

Automated code build and testing on every commit. Ensures early problem detection and fast feedback loop for developers.

02

Continuous Delivery

Automatic code deployment to production-like environments. Deployment becomes a routine, predictable operation, not a stressful event.

03

Infrastructure as Code

Managing infrastructure through configuration files. Terraform, Ansible, Pulumi allow versioning and reproducing infrastructure.

CI/CD Pipeline: from commit to production

A typical pipeline consists of several stages, each with a clear input/output contract and automatic quality gates.

Build
→
Test
→
Security Scan
→
Deploy

GitOps approach

Git as the single source of truth. All infrastructure changes go through pull requests. ArgoCD or Flux automatically synchronize the cluster state with the Git repository. This provides a full history of changes and the ability to quickly rollback.

Blue-Green Deployment

Two identical environments: blue (current) and green (new). The new version is deployed to green, tested there, then traffic is switched. In case of issues, a quick rollback is performed by switching back.

Kubernetes Resource Calculator

Calculate required resources for the K8s cluster based on load, replicas, and reservations for availability

At least 3 nodes recommended for production HA
Total pods -
CPU (cores) -
RAM (GB) -
Resource per node -
Resource distribution across cluster nodes

Kubernetes manifests and Helm charts

Declarative infrastructure description. YAML manifests define the desired state, while Kubernetes controllers continuously strive to achieve it.

# deployment.yaml
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+  name: web-app
+  namespace: production
+spec:
+  replicas: 3
+  selector:
+    matchLabels:
+      app: web-app
+  template:
+    metadata:
+      labels:
+        app: web-app
+    spec:
+      containers:
+      - name: app
+        image: registry/app:v1.2.3
+        ports:
+        - containerPort: 8080
+        resources:
+          requests:
+            memory: "256Mi"
+            cpu: "250m"
+          limits:
+            memory: "512Mi"
+            cpu: "500m"
+        livenessProbe:
+          httpGet:
+            path: /health
+            port: 8080
+          initialDelaySeconds: 10
+          periodSeconds: 5
# service-ingress.yaml
+apiVersion: v1
+kind: Service
+metadata:
+  name: web-app-service
+spec:
+  selector:
+    app: web-app
+  ports:
+  - port: 80
+    targetPort: 8080
+  type: ClusterIP
+---
+apiVersion: networking.k8s.io/v1
+kind: Ingress
+metadata:
+  name: web-app-ingress
+  annotations:
+    cert-manager.io/cluster-issuer: "letsencrypt"
+spec:
+  tls:
+  - hosts:
+    - app.example.com
+    secretName: app-tls
+  rules:
+  - host: app.example.com
+    http:
+      paths:
+      - path: /
+        pathType: Prefix
+        backend:
+          service:
+            name: web-app-service
+            port:
+              number: 80

Kubernetes cluster architecture

Control Plane manages the cluster state, while Worker Nodes run containerized applications. Understanding the components is crucial for troubleshooting and optimization.

🔧 Control Plane

etcd API Server Scheduler Controller Manager
↓

⚙️ Worker Nodes

kubelet kube-proxy Container Runtime Pod 1 Pod 2 Pod 3
Component Role High availability
API Server Frontend for the cluster, handling REST requests Load balancer in front of multiple instances
etcd Distributed state storage for the cluster 3+ nodes, quorum (n/2)+1
Scheduler Assignment of pods to nodes Leader election, standby instances
Controller Manager Maintains the desired state (reconciliation loop) Leader election
kubelet Agent on each node, managing pods Self-healing via systemd

Anti-patterns in Kubernetes

  • Running pods without resource limits — risk of noisy neighbor.
  • Using the latest image tag — impossible to rollback.
  • Storing secrets in ConfigMap — use Secrets + sealing.
  • Running as root — configure a securityContext.
  • Lack of health checks — Kubernetes is unaware of issues.

DevOps Engineer Career Path

Junior DevOps

Linux, Bash, Docker basics, CI/CD configuration. Understanding cloud concepts.

DevOps Engineer

Kubernetes administration, Terraform, monitoring (Prometheus/Grafana). AWS/GCP/Azure certified.

Senior / Platform Engineer

Architecture design, cost optimization, security hardening. Custom operators, service mesh (Istio/Linkerd).

DevOps Lead / SRE

Strategy, culture, SLO/SLI, chaos engineering, incident management.

FAQ

What is the difference between Docker and Kubernetes?

Docker — containerization technology for packaging and running applications. Runs on one host.

Kubernetes — orchestrator managing multiple containers on many hosts:

  • Automatic scaling (Horizontal Pod Autoscaler).
  • Self-healing on node failure.
  • Service discovery and load balancing.
  • Managing configurations and secrets.
What is Helm and why do we need it?

Helm — package manager for Kubernetes. Allows:

  • Install complex applications with one command: helm install postgres bitnami/postgresql.
  • Template YAML with values.yaml for different environments.
  • Control the lifecycle: upgrade, rollback to previous versions.

Chart — a package containing all K8s resources for an application.

How to ensure High Availability in K8s?
  • Control Plane: 3+ master nodes, etcd on separate SSD disks.
  • Worker Nodes: minimum 3 availability zones (AZ).
  • Pod Disruption Budgets: guarantee of minimum replica count.
  • Anti-affinity rules: replicas distributed across different nodes.
  • Cluster Autoscaler: automatic node addition under load.
What is Service Mesh (Istio/Linkerd)?

Infrastructure layer for managing service-to-service communications:

  • mTLS enabled by default — encryption of traffic between services.
  • Traffic splitting — canary deployments, A/B testing.
  • Retries, circuit breakers, timeouts — resilience patterns.
  • Observability — distributed tracing (Jaeger), metrics.

Sidecar proxy (Envoy) is injected into each pod.

How to monitor a Kubernetes cluster?

Metrics: Prometheus + Grafana for collection and visualization.

Logs: EFK (Elasticsearch, Fluentd, Kibana) or Loki + Grafana.

Tracing: Jaeger or Tempo for distributed tracing.

Alerts: Alertmanager for notifications (PagerDuty, Slack).

Golden signals: Latency, Traffic, Errors, Saturation.

Which cloud providers support Kubernetes?
  • Managed K8s: EKS (AWS), GKE (Google Cloud), AKS (Azure) — the provider manages the control plane.
  • On-premises: OpenShift (Red Hat), Rancher, vanilla K8s.
  • Multi-cloud: Anthos (Google), Tanzu (VMware).

CNCF-certified distributions guarantee portability of manifests.

Cloud Native Glossary

Pod

The smallest deployable unit in K8s. Can contain multiple containers that share network and storage. Typically 1 container = 1 pod.

ReplicaSet / Deployment

Deployment declaratively manages a ReplicaSet, which ensures a specified number of pod replicas. It provides rolling updates and rollbacks.

Service

Abstraction for accessing a group of pods. Types: ClusterIP (internal), NodePort (external via node port), LoadBalancer (cloud load balancer).

ConfigMap / Secret

ConfigMap for non-confidential data (settings). Secret for passwords, tokens (base64 encoded, but not encrypted by default).

Persistent Volume

Storage abstraction in K8s. PV — cluster resource, PVC — request for usage. Supports NFS, cloud disks (EBS, GCE PD).

Namespace

Virtual cluster within a physical one. Used for isolating environments (dev, staging, production) and multi-tenancy.