HTML Deck

Kubernetes Foundations: Zero to Cluster Operator

Deck 1 of 7 (82 slides). Everything you need to understand how Kubernetes actually works: why it exists, the control plane and etcd, the node agents, scheduling, every core workload object, Services/DNS/Ingress/Gateway, and storage. Animated reveal-step flows, official icons, comprehensive infographic posters, a collapsible study-notes panel on every slide, real scenarios on GKE, EKS and on-prem (Rancher), and a 15-question quiz with explanations.

82 slides16:9 widescreenHTML + CSS + JSIvory & Cobalt
Live preview

Slides

01Preview slide

Kubernetes, from zero to operator

Cover: what this foundations deck teaches and who it is for.

02Preview slide

Seven decks, one continuous path

The seven-deck learning path and where Foundations fits.

03Preview slide

Five questions you would otherwise answer by hand

Introduces the five operational problems orchestration solves, revealed one at a time.

04Preview slide

From Borg to a universal control plane

A short history and the three design choices that made Kubernetes the standard.

05Preview slide

Declare the state; controllers close the gap

Introduces the observe-compare-act loop and declarative vs imperative management.

06Preview slide

Brain and muscle: control plane and worker nodes

Control plane versus worker nodes, with the component roster.

07Preview slide

Managed or self-managed: who owns which layer

Shared responsibility across GKE, EKS and self-managed clusters, plus the course scenario.

08Preview slide

Orientation on one page: five questions, five automatic answers

One-page revision poster for the orientation module.

09Preview slide

Core objects: the vocabulary of every manifest

Opens the core-objects module with its questions and map.

10Preview slide

A Pod is the smallest thing Kubernetes runs

What a Pod is, what its containers share, and why Pods are disposable.

11Preview slide

Every manifest has the same five-part shape

Anatomy of a Kubernetes manifest and the spec versus status distinction.

12Preview slide

Labels are the glue between objects

How labels and selectors connect Services, Deployments and other objects.

13Preview slide

Namespaces partition one cluster; contexts choose where kubectl points

What namespaces scope and what they do not, plus kubeconfig contexts.

14Preview slide

kubectl: get, describe, events first

The core kubectl workflow and where to practise locally.

15Preview slide

Keep configuration out of the image

ConfigMaps versus Secrets and the two ways to consume them.

16Preview slide

Probes tell Kubernetes when to restart and when to send traffic

Differences between liveness, readiness and startup probes with an overload timeline.

17Preview slide

Core objects on one page

Revision poster for the core-objects module.

18Preview slide

The control plane: the brain that decides and records

Opens the control-plane module.

19Preview slide

Everything talks to one front door

The API server as the single gateway between all clients and etcd.

20Preview slide

Every request passes three gates before it is stored

The ordered authentication, authorization and admission chain.

21Preview slide

Admission webhooks: mutate first, then validate

Mutating then validating webhooks and the failurePolicy trade-off.

22Preview slide

etcd is the cluster's entire memory

What etcd stores, why it is critical, and how to snapshot it.

23Preview slide

Raft: a majority must agree before any write commits

Quorum arithmetic for odd and even etcd cluster sizes and the leader-follower flow.

24Preview slide

etcd needs housekeeping: compact, then defragment

Compaction versus defragmentation and the NOSPACE alarm.

25Preview slide

Controllers compare desired with actual, forever

Three reconciliation scenarios for a Deployment controller.

26Preview slide

Only one controller manager acts: leader election with a Lease

Leader election via Lease objects for the controller manager and scheduler.

27Preview slide

The API server scales out because it is stateless

Stateless API server replicas behind a load balancer and the watch cache.

28Preview slide

CRDs and aggregated APIs extend the API in two different ways

CRDs versus aggregated API servers.

29Preview slide

Versions, ports and health checks you will actually use

API maturity levels, key ports, health endpoints and the deprecated-API check.

30Preview slide

The control plane on one page

Revision poster for the control-plane module.

31Preview slide

Worker nodes: where containers actually run

Opens the worker-node module.

32Preview slide

The kubelet is the node's local agent

What the kubelet does and how it relates to the runtime, probes and node status.

33Preview slide

Nodes report in; silence is tolerated, then acted on

Node heartbeats, the Unknown state, taint-based eviction and node conditions.

34Preview slide

kube-proxy builds Service routing; the runtime runs containers

What kube-proxy programs and how the CRI abstracts the container runtime.

35Preview slide

The full journey from kubectl apply to a running container

Animated sequence of the components involved from kubectl apply to a running Pod.

36Preview slide

From kubectl apply to a running Pod on one page

Revision poster for the worker-node module.

37Preview slide

Scheduling: deciding where every Pod runs

Opens the scheduling module.

38Preview slide

Two phases: rule out, then rank

Filter and score phases of scheduling illustrated on five nodes.

39Preview slide

The scheduler is a pipeline of plugins

The scheduling framework extension points and what typically hooks into them.

40Preview slide

Requests decide placement; limits decide enforcement

Requests versus limits, throttling versus OOM kill, and the three QoS classes.

41Preview slide

Namespaces get budgets and defaults

ResourceQuota and LimitRange and how a quota rejection differs from a scheduling failure.

42Preview slide

Taints repel; tolerations are permission slips

Taints, tolerations and the three taint effects.

43Preview slide

Node affinity: Pods choosing their nodes

Hard and soft node affinity and what IgnoredDuringExecution means.

44Preview slide

Spread replicas across failure domains

Pod anti-affinity versus topology spread constraints across nodes and zones.

45Preview slide

Priority, preemption and disruption budgets

Preemption flow and PodDisruptionBudget semantics.

46Preview slide

Scheduling on one page

Revision poster for the scheduling module.

47Preview slide

Workloads: the objects that create and manage Pods

Opens the workloads module.

48Preview slide

Deployment owns a ReplicaSet, which owns the Pods

Deployment to ReplicaSet to Pod ownership and how rollback works.

49Preview slide

A rolling update replaces Pods gradually and waits for readiness

Step-by-step rolling update with maxSurge 1 and maxUnavailable 1.

50Preview slide

StatefulSet: stable identity and storage

StatefulSet identity, ordered lifecycle, partitions and per-replica storage.

51Preview slide

DaemonSets run everywhere; Jobs run to completion

DaemonSet, Job and CronJob behaviour and typical misuse.

52Preview slide

Init containers run first; native sidecars live alongside

Init containers and native sidecar lifecycle.

53Preview slide

Choosing the right workload object

Decision tree for choosing Deployment, StatefulSet, DaemonSet, Job or CronJob.

54Preview slide

Workloads on one page

Revision poster for the workloads module.

55Preview slide

Networking: flat Pod IPs, stable Services, controlled traffic

Opens the networking module.

56Preview slide

Every Pod gets its own IP, reachable without NAT

The three network rules and the CNI plugin concept.

57Preview slide

A Service is a stable address for changing Pods

The four Service types and a basic Service manifest.

58Preview slide

Headless Services and the EndpointSlice behind every Service

EndpointSlices, readiness-driven endpoint removal and headless Services.

59Preview slide

CoreDNS turns names into Service IPs

How Service names resolve through CoreDNS and common DNS pitfalls.

60Preview slide

NetworkPolicy: from default-open to default-deny

Default-deny NetworkPolicy, allow rules, AND versus OR and enforcement requirements.

61Preview slide

Ingress and Gateway API bring HTTP traffic in

Ingress compared with the Gateway API resource model.

62Preview slide

A request from the internet to a Pod

Animated request path from browser to Pod through DNS, load balancer, gateway, Service and Pod.

63Preview slide

Networking on one page

Revision poster for the networking module.

64Preview slide

Storage: data that outlives Pods

Opens the storage module.

65Preview slide

A claim asks, a class provisions, a driver delivers

PV, PVC and StorageClass dynamic provisioning flow.

66Preview slide

Zones and access modes decide whether a volume can attach

WaitForFirstConsumer and RWO versus RWX access modes.

67Preview slide

CSI adds snapshots, clones and online expansion

CSI snapshots, clones and expansion, and their limits.

68Preview slide

Storage on one page

Revision poster for the storage module.

69Preview slide

Real-world platforms: GKE, EKS and an on-prem Rancher fleet

Opens the real-world synthesis module.

70Preview slide

The Shopwave estate: three platforms, one Git repository

Shopwave's mixed estate across GKE, EKS and on-prem Rancher-managed clusters.

71Preview slide

Same manifest, three platforms: what actually changes

Comparison of load balancing, storage, ingress, identity, scaling and upgrades across platforms.

72Preview slide

Rancher: one control point for many clusters

Rancher's management server, provisioned and imported downstream clusters, and Fleet GitOps.

73Preview slide

Three foundations-level incidents, one cause each

Three incident case studies tied to foundations-level mechanisms.

74Preview slide

kubectl cheat sheet for this deck

Grouped kubectl commands for looking, changing, networking and storage.

75Preview slide

Who owns what on one page

Revision poster for platform ownership.

76Preview slide

What you should be able to explain now

Recap checklist across architecture, scheduling, workloads, networking and storage.

77Preview slide

Quiz 1 of 5: Architecture and control plane

Questions 1 to 3 with Check answer and explanations.

78Preview slide

Quiz 2 of 5: Control plane, scheduling and failures

Questions 4 to 6 with Check answer and explanations.

79Preview slide

Quiz 3 of 5: Scheduling, workloads and platforms

Questions 7 to 9 with Check answer and explanations.

80Preview slide

Quiz 4 of 5: Workloads, probes and Services

Questions 10 to 12 with Check answer and explanations.

81Preview slide

Quiz 5 of 5: Networking and storage

Questions 13 to 15 with Check answer and explanations.

82Preview slide

Your score and what to review

Score summary and a map from missed questions to modules.