Get in Touch

Course Outline

Day 1 – Containers and Image Management

Introduction to Container Platforms

  • Comparison of traditional application deployment methodologies versus containerized approaches
  • Differentiation between containers and virtual machines
  • Overview of container runtimes and engine architectures
  • Strategic roles for Docker, Kubernetes, and OpenShift in federal IT environments
  • Standard architectures for container platforms used by government agencies
  • Integration of development, testing, and production workflows for government software delivery

Managing Container Operations

  • Initiation and management of container instances
  • Understanding the container lifecycle management process
  • Procedures for starting, stopping, and removing containers
  • Execution of administrative commands within container environments
  • Configuration and management of environment variables
  • Implementation of port mapping protocols
  • Accessing and analyzing container log outputs
  • M monitoring of resource consumption and process inspection

Constructing Container Images

  • Analysis of image structure and layer composition
  • Authoring Dockerfiles and Containerfiles for compliance
  • Selection of approved base images for government workloads
  • Incorporation of application dependencies
  • Configuration of entry points and executable commands
  • Leveraging image caching mechanisms for efficiency
  • Strategies for minimizing container image footprint
  • Establishing reproducible build processes for auditability

Container Registries

  • Differences between public and private registry infrastructures
  • Implementation of tagging and version control standards
  • Procedures for pushing and pulling container artifacts
  • Authentication protocols for image repository access
  • Policies for image retention lifecycle and cleanup
  • Essential security considerations for container artifact integrity

Container Networking and Storage

  • Fundamental concepts of container network architecture
  • Implementation of bridge networking models
  • Configuration of external port exposure
  • Protocols for inter-container communication
  • Utilization of bind mounts and volume configurations
  • Management of persistent data requirements within containers
  • Data backup and recovery considerations for stateful applications

Practical Application Exercises

  • Execution and inspection of container instances
  • Construction of application-specific container images
  • Configuration of network ports and environment variables
  • Publication of images to designated registry repositories
  • Mechanisms for storing persistent data external to the container boundary

Day 2 – Kubernetes Architecture and Workloads

Kubernetes Fundamentals

  • Objectives and benefits of container orchestration in federal systems
  • Structural overview of Kubernetes architecture
  • Components comprising the control plane
  • Function and role of worker nodes
  • Operations and responsibilities of the API server
  • Functionality of the scheduler component
  • Role of controllers in cluster management
  • Management of cluster state versus desired state configurations
  • Utilization of kubectl for secure cluster interaction

Kubernetes Resource Definitions

  • Definition and usage of Pods
  • Management of ReplicaSets
  • Administration of Deployments
  • Implementation of Namespaces for resource isolation
  • Application of labels and annotations for metadata
  • Utilization of selectors for object targeting
  • Adoption of declarative resource definition practices
  • Construction and management of YAML manifests

Application Deployment Strategies

  • Creation and administration of Deployment objects
  • Workload scaling methodologies
  • Updates to container image references
  • Execution of rolling update procedures
  • Implementation of rollback mechanisms
  • Audit and review of deployment history
  • Workload restart protocols
  • Management of application replica counts

Application Configuration Management

  • Utilization of ConfigMaps for configuration data
  • Secure management of Secrets
  • Injection of environment variables
  • Mounting of external configuration files
  • Decoupling application code from configuration settings
  • Management of environment-specific parameters

Resource Management and Quotas

  • Definition of CPU and memory requests
  • Establishment of CPU and memory limits
  • Implementation of resource quotas
  • Configuration of limit ranges
  • Analysis of scheduling implications for resource constraints
  • Troubleshooting of resource-related service failures

Practical Application Exercises

  • Deployment of containerized applications into the cluster
  • Creation and modification of Kubernetes manifests
  • Scaling of application workloads
  • Execution of rolling updates and subsequent rollbacks
  • Configuration of applications via ConfigMaps and Secrets
  • Application of resource requests and limits to workloads

Day 3 – Kubernetes Networking, Storage and Security

Kubernetes Networking Models

  • Overview of the cluster networking model
  • Mechanisms for pod-to-pod communication
  • Service discovery protocols within the cluster
  • DNS resolution services inside the cluster
  • Configuration and use of ClusterIP services
  • Implementation of NodePort services
  • Utilization of LoadBalancer services for external access
  • Fundamentals of Ingress controllers
  • Patterns for exposing applications to external networks

Network Policy Implementation

  • Control mechanisms for traffic flow between workloads
  • Configuration of ingress and egress rules
  • Implementation of namespace-based traffic controls
  • Validation techniques for network connectivity
  • Troubleshooting protocols for service communication issues

Persistent Storage Solutions

  • Differentiation between ephemeral and persistent storage types
  • Configuration of generic volumes
  • Management of PersistentVolumes
  • Submission of PersistentVolumeClaims
  • Definition and usage of StorageClasses
  • Implementation of dynamic provisioning mechanisms
  • Understanding of access mode configurations
  • Policies for data reclaim upon resource deletion
  • Storage requirements for stateful applications

Kubernetes Access Control Frameworks

  • Fundamentals of authentication and authorization mechanisms
  • Implementation of Role-Based Access Control (RBAC)
  • Definition of Roles and ClusterRoles
  • Configuration of RoleBindings and ClusterRoleBindings
  • Management of Service Accounts for workload identity
  • Adherence to least-privilege access principles
  • Audit procedures for effective permissions assessment

Workload Security Hardening

  • Definition and application of security contexts
  • Protocols for running containers as non-root users
  • Management of Linux capabilities
  • Implementation of read-only filesystem constraints
  • Secure handling and distribution of secrets
  • Verification of image provenance and integrity
  • Mitigation of common configuration vulnerabilities

Practical Application Exercises

  • Exposure of applications via Kubernetes services
  • Configuration of ingress controllers for external access
  • Implementation of network policies to restrict traffic flows
  • Provisioning of persistent storage resources
  • Configuration of RBAC permissions for users and service accounts
  • Execution of workloads with appropriate security context settings

Day 4 – Working with OpenShift Environments

Introduction to OpenShift

  • Overview of OpenShift as a Kubernetes-centric application platform for government use
  • Mapping Kubernetes resources within the OpenShift architecture
  • Structural components of an OpenShift cluster
  • Differentiation between Projects and Namespaces
  • Management of platform users and service accounts
  • Navigating and utilizing the web console interface
  • Utilization of the OpenShift Command Line Interface (CLI)

Project Management and Access Control

  • Creation and administration of projects
  • Assignment of user permissions and roles
  • Application of project-level role definitions
  • Administration of privileged access controls
  • Implementation of project-specific resource quotas
  • Configuration of limit ranges for resource enforcement
  • Management of service accounts within projects
  • Audit and review of project resources and configurations

Application Deployment in OpenShift

  • Deployment strategies for container images
  • Creation and management of application workloads
  • Administration of deployment lifecycle events
  • Scaling applications to meet demand
  • Version update procedures for applications
  • Execution of rollback operations
  • Management of application configuration settings
  • Secure handling of application secrets

Application Exposure Strategies

  • Role and function of Services in OpenShift
  • Configuration and management of Routes
  • Fundamentals of TLS implementation for secure communications
  • Management of internal versus external application access points
  • Administration of hostnames and SSL/TLS certificates
  • Troubleshooting procedures for route and service connectivity issues

Storage Management in OpenShift

  • Utilization of Persistent Volume Claims (PVCs)
  • Definition and selection of StorageClasses
  • Attachment of storage resources to workloads
  • Management of stateful workload requirements
  • Configuration of storage access permissions
  • Troubleshooting procedures for volume mounting failures

Scheduling and Node Management

  • Utilization of labels and selectors for object identification
  • Configuration of node selectors for workload placement
  • Application of taints and tolerations rules
  • Implementation of affinity and anti-affinity scheduling constraints
  • Strategies for workload distribution across nodes
  • Procedures for cordoning and draining nodes during maintenance
  • Considerations for effective node maintenance operations

Practical Application Exercises

  • Secure access to an OpenShift environment
  • Creation and configuration of a dedicated project space
  • Deployment and exposure of a sample application
  • Configuration of access permissions for users and service accounts
  • Attachment of persistent storage volumes to workloads
  • Scaling and updating of running application workloads

Day 5 – Operations, Monitoring and Troubleshooting

Platform Monitoring Protocols

  • Monitoring procedures for cluster and application health status
  • Analysis of resource metrics and utilization data
  • Assessment of node health indicators
  • Tracking of workload operational status
  • Evaluation of capacity planning and resource utilization trends
  • Identification of performance bottlenecks and constraints

Logging and Event Management

  • Access and analysis of container logs
  • Retrieval of pod-level log data
  • Access to logs from previous container executions
  • Audit and interpretation of Kubernetes events
  • Analysis of application and platform operational messages
  • Filtering techniques for relevant operational data review

Health Check Implementation

  • Configuration of startup probes for initialization validation
  • Implementation of readiness probes for service availability
  • Utilization of liveness probes for fault detection
  • Design principles for effective health check endpoints
  • Troubleshooting procedures for probe failure scenarios
  • Strategies to prevent unnecessary application restarts

Troubleshooting Workload Failures

  • Resolution of pending pod states
  • Diagnostics for image pull failures
  • Investigation of crash loop occurrences
  • Correction of misconfigured environment variables
  • Troubleshooting of failed volume mount operations
  • Diagnosis of insufficient resource allocation issues
  • Resolution of permission-based access errors
  • Analysis of service and route connectivity disruptions
  • Investigation of DNS resolution failures
  • Diagnosis of application startup errors

Operational Security Practices

  • Audit procedures for role permissions and access rights
  • Best practices for service account usage and management
  • Secure handling and rotation of credentials
  • Implementation of image security scanning and validation
  • Enforcement of network isolation controls
  • Auditing procedures for platform access logs
  • Application of the principle of least privilege across all operations

Maintenance and Lifecycle Management

  • Schedule and execution of routine platform health checks
  • Procedures for node-level maintenance activities
  • Guidelines for application backup strategies
  • Protocols for configuration data backup
  • Planning and coordination of system updates
  • Integration of updates with change management processes
  • Validation testing procedures for pending updates
  • Development of rollback plans for update failures
  • Fundamental concepts of disaster recovery planning

Final Practical Workshop

Participants execute a comprehensive operational scenario encompassing the following tasks:

  • Construction and tagging of a container image.
  • Publishing the image to a designated registry repository.
  • Deployment of the application within a Kubernetes or OpenShift environment for government use.
  • Configuration of application settings and secure credential injection.
  • Exposure of the application via appropriate network services.
  • Attachment of persistent storage volumes to the workload.
  • Implementation of access permission controls.
  • Deployment of health check mechanisms.
  • Scaling and updating the running application.
  • Diagnosis and resolution of an intentionally introduced failure scenario.

Course Format

  • Interactive lectures supplemented by technical discussions relevant to public sector operations.
  • Instructor-led demonstrations of administrative procedures.
  • Extensive hands-on exercises to reinforce technical skills.
  • Scenario-based workshops focused on administration and troubleshooting methodologies.
  • Practical application within container, Kubernetes, and OpenShift environments.

Course Customization Options

  • The curriculum can be adapted to align with the participant's existing infrastructure, cloud provider capabilities, and container tooling stacks.
  • The instructional balance among Docker, Kubernetes, and OpenShift topics can be adjusted based on the team's prior experience and operational needs.
  • Practical exercises can be tailored to reflect the organization's specific applications, deployment pipelines, and operational requirements for government systems.

Trademark Notice

OpenShift is a trademark of Red Hat, Inc. This independently developed training is not affiliated with, endorsed by or authorized by Red Hat.

Requirements

Attendees are expected to possess the following qualifications:

  • Proficiency in operating the Linux command-line interface.
  • Foundational knowledge of system administration or DevOps practices.
  • A working understanding of core networking principles.
  • Familiarity with standard software deployment methodologies.

While prior exposure to Docker, Kubernetes, or OpenShift is advantageous, it is not mandatory for this initiative designed for government audiences.

 35 Hours

Number of participants


Price per participant

Testimonials (7)

Upcoming Courses

Related Categories