Course Outline
Day 1 – Containers and Image Management
Introduction to Container Platforms
- Comparison of traditional application deployment versus container-based deployment
- Differences between containers and virtual machines
- Container runtimes and container engines
- The respective roles of Docker, Kubernetes, and OpenShift
- Common architectures for container platforms
- Workflows for development, testing, and production
Working with Containers
- Executing and managing containers
- The container lifecycle
- Initiating, halting, and removing containers
- Running commands within containers
- Utilising environment variables
- Mapping ports
- Accessing container logs
- Inspecting resource usage and processes
Building Container Images
- Understanding image structure and layers
- Authoring Dockerfiles and Containerfiles
- Selecting appropriate base images
- Incorporating application dependencies
- Configuring entry points and commands
- Leveraging image caching for efficiency
- Strategies to reduce image size
- Ensuring reproducibility in image builds
Container Registries
- Distinguishing between public and private registries
- Tagging and versioning images
- Pushing and pulling images
- Image authentication mechanisms
- Managing image retention and cleanup
- Essential security considerations for images
Container Networking and Storage
- Fundamental container network concepts
- Bridge networking setups
- Exposing ports
- Facilitating container-to-container communication
- Using bind mounts and volumes
- Maintaining persistent container data
- Considerations for backups
Hands-on Exercises
- Running and inspecting containers
- Constructing an application image
- Configuring ports and environment variables
- Publishing an image to a registry
- Storing persistent data external to the container
Day 2 – Kubernetes Architecture and Workloads
Kubernetes Fundamentals
- The purpose of container orchestration
- Overview of Kubernetes architecture
- Components of the control plane
- Functionality of worker nodes
- The role of the API server
- The scheduler's function
- Controllers in operation
- Differentiating between cluster state and desired state
- Interacting with the cluster via kubectl
Kubernetes Resources
- Pods
- ReplicaSets
- Deployments
- Namespaces
- Labels and annotations
- Selectors
- Declarative resource definitions
- YAML manifests
Deploying Applications
- Creating and managing Deployments
- Scaling workloads up or down
- Updating container images
- Implementing rolling updates
- Executing rollbacks
- Reviewing deployment history
- Restarting workloads as needed
- Managing application replicas
Application Configuration
- Utilising ConfigMaps
- Managing Secrets
- Setting environment variables
- Handling configuration files
- Decoupling application code from configuration
- Managing settings specific to different environments
Resource Management
- Setting CPU and memory requests
- Defining CPU and memory limits
- Applying resource quotas
- Establishing limit ranges
- Understanding scheduling implications
- Diagnosing failures related to resources
Hands-on Exercises
- Deploying a containerised application
- Creating and updating Kubernetes manifests
- Scaling an application
- Performing a rolling update and subsequent rollback
- Configuring the application using ConfigMaps and Secrets
- Applying resource requests and limits
Day 3 – Kubernetes Networking, Storage and Security
Kubernetes Networking
- The cluster networking model
- Facilitating pod-to-pod communication
- Service discovery mechanisms
- DNS functionality within the cluster
- ClusterIP services
- NodePort services
- LoadBalancer services
- Ingress concepts
- Patterns for exposing applications
Network Policies
- Controlling traffic flow between workloads
- Defining ingress and egress rules
- Implementing namespace-based traffic control
- Testing network connectivity
- Troubleshooting service communication issues
Persistent Storage
- Distinguishing ephemeral from persistent storage
- Volumes
- PersistentVolumes (PVs)
- PersistentVolumeClaims (PVCs)
- StorageClasses
- Dynamic provisioning techniques
- Access modes
- Reclaim policies
- Storage requirements for stateful applications
Kubernetes Access Control
- Concepts of authentication and authorization
- Role-Based Access Control (RBAC)
- Roles and ClusterRoles
- RoleBindings and ClusterRoleBindings
- Service accounts
- Implementing least-privilege access
- Inspecting effective permissions
Workload Security
- Security contexts
- Running containers with non-root privileges
- Managing Linux capabilities
- Implementing read-only filesystems
- Handling secrets securely
- Verifying image provenance
- Acknowledging common configuration risks
Hands-on Exercises
- Exposing an application via Kubernetes services
- Configuring ingress rules
- Restricting traffic using network policies
- Provisioning persistent storage
- Configuring RBAC permissions
- Running a workload with an appropriate security context
Day 4 – Working with OpenShift Environments
Introduction to OpenShift
- OpenShift as a Kubernetes-based application platform
- Kubernetes resources within an OpenShift environment
- OpenShift cluster architecture
- Differences between projects and namespaces
- Platform users and service accounts
- Navigating the web console
- Utilising the OpenShift CLI
Managing Projects and Access
- Creating and managing projects
- Assigning user permissions
- Project-level roles
- Gaining administrative access
- Setting resource quotas
- Defining limit ranges
- Using service accounts
- Reviewing project resources
Deploying Applications
- Deploying container images
- Creating application workloads
- Managing deployments
- Scaling applications
- Updating application versions
- Executing rollbacks
- Managing application configuration
- Working with secrets
Application Exposure
- Services in OpenShift
- Routes
- TLS concepts
- Internal and external application access methods
- Managing hostnames and certificates
- Diagnosing issues with routes and services
Storage in OpenShift
- Persistent Volume Claims
- StorageClasses
- Attaching storage to workloads
- Managing stateful workloads
- Configuring storage access permissions
- Troubleshooting volume mounting issues
Scheduling and Node Management
- Labels and selectors
- Node selectors
- Taints and tolerations
- Affinity and anti-affinity concepts
- Workload placement strategies
- Cordoning and draining nodes
- Considerations for node maintenance
Hands-on Exercises
- Accessing an OpenShift environment
- Creating and configuring a project
- Deploying and exposing an application
- Configuring user and service-account access
- Attaching persistent storage
- Scaling and updating a running workload
Day 5 – Operations, Monitoring and Troubleshooting
Platform Monitoring
- Monitoring cluster and application health
- Analyzing resource metrics
- Assessing node health
- Checking workload status
- Evaluating capacity and resource utilization
- Identifying performance constraints
Logging and Events
- Accessing container logs
- Accessing pod logs
- Retrieving previous container logs
- Reviewing Kubernetes events
- Analyzing application and platform messages
- Filtering and interpreting operational data
Health Checks
- Startup probes
- Readiness probes
- Liveness probes
- Designing useful health endpoints
- Diagnosing probe failures
- Preventing unnecessary application restarts
Troubleshooting Workloads
- Resolving pending pods
- Addressing image pull failures
- Troubleshooting crash loops
- Correcting misconfigured environment variables
- Fixing failed mounts
- Handling insufficient resources
- Resolving permission errors
- Troubleshooting service and route connectivity problems
- Addressing DNS issues
- Investigating application startup failures
Operational Security
- Reviewing permissions
- Proper service account usage
- Secure handling of credentials
- Adhering to image security practices
- Ensuring network isolation
- Auditing platform access
- Applying the principle of least privilege
Maintenance and Lifecycle Management
- Conducting routine platform checks
- Performing node maintenance
- Considering application backup strategies
- Backing up configuration files
- Planning updates
- Managing changes effectively
- Testing updates thoroughly
- Preparing rollback plans
- Understanding disaster recovery concepts
Final Practical Workshop
Participants will complete an end-to-end operational scenario:
- Building and tagging a container image.
- Publishing the image to a registry.
- Deploying the application to Kubernetes or OpenShift.
- Configuring application settings and credentials.
- Exposing the application.
- Attaching persistent storage.
- Configuring access permissions.
- Adding health checks.
- Scaling and updating the application.
- Diagnosing and resolving an introduced failure.
Course Format
- Interactive lectures and technical discussions.
- Instructor demonstrations.
- Extensive hands-on exercises.
- Scenario-based administration and troubleshooting workshops.
- Practical work in container, Kubernetes, and OpenShift environments.
Course Customization Options
- The course can be adapted to fit the participant's existing infrastructure, cloud provider, and container tooling.
- The balance between Docker, Kubernetes, and OpenShift topics can be adjusted according to the team's experience.
- Practical exercises can be tailored to the organization's applications, deployment processes, and operational requirements.
Trademark Notice
OpenShift is a trademark of Red Hat, Inc. This independently developed training is not affiliated with, endorsed by, or authorized by Red Hat.
Requirements
Participants should possess:
- Experience working with the Linux command line.
- Foundational knowledge of system administration or DevOps practices.
- A general understanding of networking concepts.
- Familiarity with software deployment processes.
While prior experience with Docker, Kubernetes, or OpenShift is advantageous, it is not a prerequisite.
Testimonials (7)
Reda explanations and he simplified alot of the understanding
Eric Van Wyk
Course - Docker, Kubernetes and OpenShift 3 for Administrators
The labs were the best. Very practical and provides hands-on experience. I personally think that it is the most effective means of truly understanding the course and applying the concepts that were covered.
Hishaam Johnstone
Course - Docker, Kubernetes and OpenShift 3 for Administrators
I loved the willingness to help and explain further when uncertain
Letlotlo Miffi
Course - Docker, Kubernetes and OpenShift 3 for Administrators
Adriano studied the subject very deeply which is the style i mostly prefer ie: less about the commands more on the mechanism behind it. Discussed scenarios were well supported by the practical examples which helped a lot to understand the presented stuff.
Mariusz BANASZCZYK - Sopra Steria
Course - Docker, Kubernetes and OpenShift for Administrators
Deep knowledge of Adriano. Explanation of base concepts
Tomasz Szalankiewicz - LPP SA
Course - Docker, Kubernetes and OpenShift for Administrators
I generally liked the presenter.
Josif Kovacevic - ANZ
Course - Docker, Kubernetes and OpenShift for Administrators
Adrian clearly knows and enjoys this technology.