Kubernetes Foundations: Zero to Cluster Operator
Deck 1 of 7 (82 slides). Everything you need to understand how Kubernetes actually works: why it exists, the control plane and etcd, the node agents, scheduling, every core workload object, Services/DNS/Ingress/Gateway, and storage. Animated reveal-step flows, official icons, comprehensive infographic posters, a collapsible study-notes panel on every slide, real scenarios on GKE, EKS and on-prem (Rancher), and a 15-question quiz with explanations.
Slides
Kubernetes, from zero to operator
Cover: what this foundations deck teaches and who it is for.
Seven decks, one continuous path
The seven-deck learning path and where Foundations fits.
Five questions you would otherwise answer by hand
Introduces the five operational problems orchestration solves, revealed one at a time.
From Borg to a universal control plane
A short history and the three design choices that made Kubernetes the standard.
Declare the state; controllers close the gap
Introduces the observe-compare-act loop and declarative vs imperative management.
Brain and muscle: control plane and worker nodes
Control plane versus worker nodes, with the component roster.
Managed or self-managed: who owns which layer
Shared responsibility across GKE, EKS and self-managed clusters, plus the course scenario.
Orientation on one page: five questions, five automatic answers
One-page revision poster for the orientation module.
Core objects: the vocabulary of every manifest
Opens the core-objects module with its questions and map.
A Pod is the smallest thing Kubernetes runs
What a Pod is, what its containers share, and why Pods are disposable.
Every manifest has the same five-part shape
Anatomy of a Kubernetes manifest and the spec versus status distinction.
Labels are the glue between objects
How labels and selectors connect Services, Deployments and other objects.
Namespaces partition one cluster; contexts choose where kubectl points
What namespaces scope and what they do not, plus kubeconfig contexts.
kubectl: get, describe, events first
The core kubectl workflow and where to practise locally.
Keep configuration out of the image
ConfigMaps versus Secrets and the two ways to consume them.
Probes tell Kubernetes when to restart and when to send traffic
Differences between liveness, readiness and startup probes with an overload timeline.
Core objects on one page
Revision poster for the core-objects module.
The control plane: the brain that decides and records
Opens the control-plane module.
Everything talks to one front door
The API server as the single gateway between all clients and etcd.
Every request passes three gates before it is stored
The ordered authentication, authorization and admission chain.
Admission webhooks: mutate first, then validate
Mutating then validating webhooks and the failurePolicy trade-off.
etcd is the cluster's entire memory
What etcd stores, why it is critical, and how to snapshot it.
Raft: a majority must agree before any write commits
Quorum arithmetic for odd and even etcd cluster sizes and the leader-follower flow.
etcd needs housekeeping: compact, then defragment
Compaction versus defragmentation and the NOSPACE alarm.
Controllers compare desired with actual, forever
Three reconciliation scenarios for a Deployment controller.
Only one controller manager acts: leader election with a Lease
Leader election via Lease objects for the controller manager and scheduler.
The API server scales out because it is stateless
Stateless API server replicas behind a load balancer and the watch cache.
CRDs and aggregated APIs extend the API in two different ways
CRDs versus aggregated API servers.
Versions, ports and health checks you will actually use
API maturity levels, key ports, health endpoints and the deprecated-API check.
The control plane on one page
Revision poster for the control-plane module.
Worker nodes: where containers actually run
Opens the worker-node module.
The kubelet is the node's local agent
What the kubelet does and how it relates to the runtime, probes and node status.
Nodes report in; silence is tolerated, then acted on
Node heartbeats, the Unknown state, taint-based eviction and node conditions.
kube-proxy builds Service routing; the runtime runs containers
What kube-proxy programs and how the CRI abstracts the container runtime.
The full journey from kubectl apply to a running container
Animated sequence of the components involved from kubectl apply to a running Pod.
From kubectl apply to a running Pod on one page
Revision poster for the worker-node module.
Scheduling: deciding where every Pod runs
Opens the scheduling module.
Two phases: rule out, then rank
Filter and score phases of scheduling illustrated on five nodes.
The scheduler is a pipeline of plugins
The scheduling framework extension points and what typically hooks into them.
Requests decide placement; limits decide enforcement
Requests versus limits, throttling versus OOM kill, and the three QoS classes.
Namespaces get budgets and defaults
ResourceQuota and LimitRange and how a quota rejection differs from a scheduling failure.
Taints repel; tolerations are permission slips
Taints, tolerations and the three taint effects.
Node affinity: Pods choosing their nodes
Hard and soft node affinity and what IgnoredDuringExecution means.
Spread replicas across failure domains
Pod anti-affinity versus topology spread constraints across nodes and zones.
Priority, preemption and disruption budgets
Preemption flow and PodDisruptionBudget semantics.
Scheduling on one page
Revision poster for the scheduling module.
Workloads: the objects that create and manage Pods
Opens the workloads module.
Deployment owns a ReplicaSet, which owns the Pods
Deployment to ReplicaSet to Pod ownership and how rollback works.
A rolling update replaces Pods gradually and waits for readiness
Step-by-step rolling update with maxSurge 1 and maxUnavailable 1.
StatefulSet: stable identity and storage
StatefulSet identity, ordered lifecycle, partitions and per-replica storage.
DaemonSets run everywhere; Jobs run to completion
DaemonSet, Job and CronJob behaviour and typical misuse.
Init containers run first; native sidecars live alongside
Init containers and native sidecar lifecycle.
Choosing the right workload object
Decision tree for choosing Deployment, StatefulSet, DaemonSet, Job or CronJob.
Workloads on one page
Revision poster for the workloads module.
Networking: flat Pod IPs, stable Services, controlled traffic
Opens the networking module.
Every Pod gets its own IP, reachable without NAT
The three network rules and the CNI plugin concept.
A Service is a stable address for changing Pods
The four Service types and a basic Service manifest.
Headless Services and the EndpointSlice behind every Service
EndpointSlices, readiness-driven endpoint removal and headless Services.
CoreDNS turns names into Service IPs
How Service names resolve through CoreDNS and common DNS pitfalls.
NetworkPolicy: from default-open to default-deny
Default-deny NetworkPolicy, allow rules, AND versus OR and enforcement requirements.
Ingress and Gateway API bring HTTP traffic in
Ingress compared with the Gateway API resource model.
A request from the internet to a Pod
Animated request path from browser to Pod through DNS, load balancer, gateway, Service and Pod.
Networking on one page
Revision poster for the networking module.
Storage: data that outlives Pods
Opens the storage module.
A claim asks, a class provisions, a driver delivers
PV, PVC and StorageClass dynamic provisioning flow.
Zones and access modes decide whether a volume can attach
WaitForFirstConsumer and RWO versus RWX access modes.
CSI adds snapshots, clones and online expansion
CSI snapshots, clones and expansion, and their limits.
Storage on one page
Revision poster for the storage module.
Real-world platforms: GKE, EKS and an on-prem Rancher fleet
Opens the real-world synthesis module.
The Shopwave estate: three platforms, one Git repository
Shopwave's mixed estate across GKE, EKS and on-prem Rancher-managed clusters.
Same manifest, three platforms: what actually changes
Comparison of load balancing, storage, ingress, identity, scaling and upgrades across platforms.
Rancher: one control point for many clusters
Rancher's management server, provisioned and imported downstream clusters, and Fleet GitOps.
Three foundations-level incidents, one cause each
Three incident case studies tied to foundations-level mechanisms.
kubectl cheat sheet for this deck
Grouped kubectl commands for looking, changing, networking and storage.
Who owns what on one page
Revision poster for platform ownership.
What you should be able to explain now
Recap checklist across architecture, scheduling, workloads, networking and storage.
Quiz 1 of 5: Architecture and control plane
Questions 1 to 3 with Check answer and explanations.
Quiz 2 of 5: Control plane, scheduling and failures
Questions 4 to 6 with Check answer and explanations.
Quiz 3 of 5: Scheduling, workloads and platforms
Questions 7 to 9 with Check answer and explanations.
Quiz 4 of 5: Workloads, probes and Services
Questions 10 to 12 with Check answer and explanations.
Quiz 5 of 5: Networking and storage
Questions 13 to 15 with Check answer and explanations.
Your score and what to review
Score summary and a map from missed questions to modules.