Course Outline
Day 1 – Containers and Image Management
Introduction to Container Platforms
- Comparison of traditional application deployment versus container-based deployment
- Containers vs. virtual machines
- Container runtimes and container engines
- The specific roles of Docker, Kubernetes, and OpenShift
- Common container platform architectures
- Workflows for development, testing, and production
Working with Containers
- Running and managing containers
- Understanding the container lifecycle
- Starting, stopping, and removing containers
- Executing commands inside containers
- Utilizing environment variables
- Port mapping techniques
- Accessing container logs
- Inspecting resource usage and processes
Building Container Images
- Image structure and layer composition
- Creating Dockerfiles and Containerfiles
- Selecting appropriate base images
- Incorporating application dependencies
- Configuring entry points and commands
- Leveraging image caching
- Strategies for reducing image size
- Building reproducible images
Container Registries
- Differentiating between public and private registries
- Tagging and versioning images
- Pushing and pulling images
- Implementing image authentication
- Managing image retention and cleanup
- Considering basic image security aspects
Container Networking and Storage
- Fundamentals of container networking
- Bridge networking configurations
- Port exposure mechanisms
- Facilitating container-to-container communication
- Utilizing bind mounts and volumes
- Managing persistent container data
- Key considerations for backups
Hands-on Exercises
- Running and inspecting containers
- Building an application image
- Configuring ports and environment variables
- Publishing an image to a registry
- Storing persistent data outside the container
Day 2 – Kubernetes Architecture and Workloads
Kubernetes Fundamentals
- The purpose of container orchestration
- Overview of Kubernetes architecture
- Control plane components
- Worker nodes
- API server functions
- The role of the scheduler
- Controllers in action
- Distinguishing cluster state from desired state
- Interacting with the cluster using kubectl
Kubernetes Resources
- Pods
- ReplicaSets
- Deployments
- Namespaces
- Labels and annotations
- Selectors
- Declarative resource definitions
- YAML manifests
Deploying Applications
- Creating and managing Deployments
- Scaling workloads up or down
- Updating container images
- Executing rolling updates
- Performing rollbacks
- Reviewing deployment history
- Restarting workloads when necessary
- Managing application replicas
Application Configuration
- Utilizing ConfigMaps
- Utilizing Secrets
- Setting environment variables
- Managing configuration files
- Separating application code from configuration
- Handling environment-specific settings
Resource Management
- Defining CPU and memory requests
- Setting CPU and memory limits
- Implementing resource quotas
- Applying limit ranges
- Understanding scheduling implications
- Diagnosing resource-related failures
Hands-on Exercises
- Deploying a containerized application
- Creating and updating Kubernetes manifests
- Scaling an application
- Performing rolling updates and rollbacks
- Configuring the application using ConfigMaps and Secrets
- Applying resource requests and limits
Day 3 – Kubernetes Networking, Storage, and Security
Kubernetes Networking
- The cluster networking model
- Pod-to-pod communication mechanisms
- Service discovery processes
- DNS resolution within the cluster
- ClusterIP services
- NodePort services
- LoadBalancer services
- Ingress concepts
- Patterns for application exposure
Network Policies
- Controlling traffic between workloads
- Defining ingress and egress rules
- Implementing namespace-based traffic control
- Testing network connectivity
- Troubleshooting service communication issues
Persistent Storage
- Distinguishing ephemeral from persistent storage
- Volumes
- PersistentVolumes (PVs)
- PersistentVolumeClaims (PVCs)
- StorageClasses
- Dynamic provisioning
- Access modes
- Reclaim policies
- Storage requirements for stateful applications
Kubernetes Access Control
- Authentication and authorization concepts
- Role-Based Access Control (RBAC)
- Roles and ClusterRoles
- RoleBindings and ClusterRoleBindings
- Service accounts
- Adhering to least-privilege access principles
- Inspecting effective permissions
Workload Security
- Understanding security contexts
- Running containers as non-root users
- Managing Linux capabilities
- Implementing read-only filesystems
- Handling secrets securely
- Verifying image provenance
- Awareness of common configuration risks
Hands-on Exercises
- Exposing an application via Kubernetes services
- Configuring ingress rules
- Restricting traffic using network policies
- Provisioning persistent storage
- Configuring RBAC permissions
- Running a workload with an appropriate security context
Day 4 – Working with OpenShift Environments
Introduction to OpenShift
- OpenShift as a Kubernetes-based application platform
- Mapping Kubernetes resources within an OpenShift environment
- OpenShift cluster architecture
- Differences between projects and namespaces
- Platform users and service accounts
- Navigating the web console
- Using the OpenShift CLI
Managing Projects and Access
- Creating and managing projects
- Assigning user permissions
- Project-level roles
- Administrative access controls
- Resource quotas
- Limit ranges
- Service accounts
- Reviewing project resources
Deploying Applications
- Deploying container images
- Creating application workloads
- Managing deployments
- Scaling applications
- Updating application versions
- Performing rollbacks
- Managing application configuration
- Working with secrets
Application Exposure
- Services in OpenShift
- Routes
- TLS concepts
- Internal and external application access
- Managing hostnames and certificates
- Diagnosing route and service issues
Storage in OpenShift
- Persistent Volume Claims (PVCs)
- StorageClasses
- Attaching storage to workloads
- Managing stateful workloads
- Storage access permissions
- Troubleshooting volume mounting issues
Scheduling and Node Management
- Labels and selectors
- Node selectors
- Taints and tolerations
- Affinity and anti-affinity concepts
- Workload placement strategies
- Cordoning and draining nodes
- Considerations for node maintenance
Hands-on Exercises
- Accessing an OpenShift environment
- Creating and configuring a project
- Deploying and exposing an application
- Configuring user and service-account access
- Attaching persistent storage
- Scaling and updating a running workload
Day 5 – Operations, Monitoring, and Troubleshooting
Platform Monitoring
- Monitoring cluster and application health
- Analyzing resource metrics
- Assessing node health
- Checking workload status
- Evaluating capacity and resource utilization
- Identifying performance constraints
Logging and Events
- Accessing container logs
- Retrieving pod logs
- Viewing previous container logs
- Monitoring Kubernetes events
- Analyzing application and platform messages
- Filtering and interpreting operational data
Health Checks
- Startup probes
- Readiness probes
- Liveness probes
- Designing useful health endpoints
- Diagnosing probe failures
- Preventing unnecessary application restarts
Troubleshooting Workloads
- Resolving pending pods
- Addressing image pull failures
- Fixing crash loops
- Correcting misconfigured environment variables
- Handling failed mounts
- Addressing insufficient resources
- Resolving permission errors
- Troubleshooting service and route connectivity problems
- Diagnosing DNS issues
- Investigating application startup failures
Operational Security
- Reviewing permissions
- Evaluating service account usage
- Secure handling of credentials
- Implementing image security practices
- Enforcing network isolation
- Auditing platform access
- Applying the principle of least privilege
Maintenance and Lifecycle Management
- Conducting routine platform checks
- Performing node maintenance
- Considering application backup strategies
- Backing up configuration data
- Planning updates
- Managing changes
- Testing updates
- Planning rollbacks
- Understanding disaster recovery concepts
Final Practical Workshop
Participants complete an end-to-end operational scenario:
- Build and tag a container image.
- Publish the image to a registry.
- Deploy the application to Kubernetes or OpenShift.
- Configure application settings and credentials.
- Expose the application.
- Attach persistent storage.
- Configure access permissions.
- Add health checks.
- Scale and update the application.
- Diagnose and resolve an introduced failure.
Course Format
- Interactive lectures and technical discussions.
- Instructor demonstrations.
- Extensive hands-on exercises.
- Scenario-based administration and troubleshooting workshops.
- Practical work in container, Kubernetes, and OpenShift environments.
Course Customization Options
- The course can be adapted to the participant's existing infrastructure, cloud provider, and container tooling.
- The balance between Docker, Kubernetes, and OpenShift topics can be adjusted according to the team's experience.
- Practical exercises can be tailored to the organization's applications, deployment processes, and operational requirements.
Trademark Notice
OpenShift is a trademark of Red Hat, Inc. This independently developed training is not affiliated with, endorsed by, or authorized by Red Hat.
Requirements
Participants are expected to possess:
- Experience using the Linux command line.
- Foundational knowledge of system administration or DevOps practices.
- A general understanding of networking concepts.
- Familiarity with software deployment processes.
While previous experience with Docker, Kubernetes, or OpenShift is beneficial, it is not a prerequisite for enrollment.
Testimonials (7)
Reda explanations and he simplified alot of the understanding
Eric Van Wyk
Course - Docker, Kubernetes and OpenShift 3 for Administrators
The labs were the best. Very practical and provides hands-on experience. I personally think that it is the most effective means of truly understanding the course and applying the concepts that were covered.
Hishaam Johnstone
Course - Docker, Kubernetes and OpenShift 3 for Administrators
I loved the willingness to help and explain further when uncertain
Letlotlo Miffi
Course - Docker, Kubernetes and OpenShift 3 for Administrators
Adriano studied the subject very deeply which is the style i mostly prefer ie: less about the commands more on the mechanism behind it. Discussed scenarios were well supported by the practical examples which helped a lot to understand the presented stuff.
Mariusz BANASZCZYK - Sopra Steria
Course - Docker, Kubernetes and OpenShift for Administrators
Deep knowledge of Adriano. Explanation of base concepts
Tomasz Szalankiewicz - LPP SA
Course - Docker, Kubernetes and OpenShift for Administrators
I generally liked the presenter.
Josif Kovacevic - ANZ
Course - Docker, Kubernetes and OpenShift for Administrators
Adrian clearly knows and enjoys this technology.