Advanced Kubernetes — high availability, resilience and secrets
A single-control-node cluster has no place in production, and a cluster database backup that has never been restored is not a backup. This course covers control plane redundancy, mastering the configuration store, cluster upgrades, advanced declarative management and securing traffic and secrets.
Training objectives
- Design a redundant control plane and its load balancer.
- Extend a cluster and master the configuration store quorum.
- Back up, restore and optimize the cluster configuration store.
- Run resilience tests and carry out a cluster upgrade.
- Structure declarative deployment and enforce admission policies.
- Secure ingress traffic and externalize secret management.
Target audience
- SRE engineers and container platform administrators.
- Cloud native architects.
- Operations teams responsible for service continuity.
Prerequisites
- Kubernetes administration course or equivalent practice.
- Advanced Linux administration.
Detailed program
Day 1 — Control plane architecture
- Limits of a single control plane and recommended architecture
- Control plane load balancer, virtual address and health checks
- Adding control nodes, certificate distribution and quorum
Day 2 — Cluster configuration store
- Architecture, consensus protocol and mutual authentication
- Exploration, metrics, compaction and defragmentation
- Backup, restore and retention strategies
Day 3 — Resilience and declarative management
- Resilience testing: failure types, failover, recovery objectives
- Upgrading a cluster and its components
- Advanced manifests and customization overlays
Day 4 — Policies, encryption and secrets
- Admission policies and enforcing requests and limits
- Automated certificate management and encrypted exposure
- Externalized secret management and closing workshop
Certification
At the end of this training, you will receive a certificate of participation issued by squint.
Other training courses that might interest you
Kubernetes — administering and running applications
Présentiel et distancielKubernetes has become the foundation of modern application platforms, and its adoption shifts the difficulty from deployment to operations. This …
Cilium and eBPF — Kubernetes networking, security and observability
Présentiel et distancielCilium has moved Kubernetes networking into the kernel: eBPF replaces the service proxy, carries identity-based policies, load balancing and encryption, …
OpenShift 4 — bare metal deployment with provisioned installation
Présentiel et distancielInstalling OpenShift on bare metal is not a console operation: automated provisioning, hardware management controllers, infrastructure services, addressing plan and …
Ready to develop your skills?
Join hundreds of professionals who have trusted squint for their skills.
View all our training courses