Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to Self-Managed Kubernetes for Government
- Kubernetes architecture and essential components
- Comparative analysis of managed versus self-managed Kubernetes environments
- Assessment of vendor dependency risks and sovereign control advantages
- Deployment methodologies: kubeadm, kOps, and manual installation
Infrastructure Planning for Government Operations
- Resource sizing strategies for control plane and worker nodes
- High availability mandates and topology designs
- Operating system selection and preparation (Ubuntu, RHEL, Rocky Linux)
- Network prerequisites and firewall configuration standards
Installation of Container Runtimes
- Evaluation of container runtime options: containerd vs. CRI-O
- Procedure for installing and configuring containerd
- Procedure for installing and configuring CRI-O
- Runtime security protocols and considerations
Cluster Bootstrapping with kubeadm
- Installation of kubeadm, kubelet, and kubectl utilities
- Initialization of the primary control plane node
- Configuration of kubeconfig for secure cluster access
- Integration of additional control plane nodes for high availability
- Provisioning and joining of worker nodes to the cluster
High Availability Configuration
- Architectural comparison: stacked versus external etcd topologies
- Implementation of HAProxy or Keepalived for API server load distribution
- Certificate lifecycle management and renewal processes
- etcd backup and recovery protocols for data integrity
Container Networking
- CNI plugin selection: Calico, Cilium, Flannel, and Weave
- Installation and configuration of Calico
- Establishment of network policies for enhanced security
- Node-to-node communication and pod network architecture
- Service exposure strategies independent of cloud load balancers
Service Load Balancing
- Utilization of MetalLB for bare-metal load balancing
- Configuration of Layer 2 and BGP operating modes
- Implementation of Keepalived and HAProxy alternatives
- Deployment of ingress controllers (nginx, Traefik)
Storage Solutions
- Concepts of storage classes and CSI drivers
- Implementation of local persistent volumes
- Setup of NFS provisioners
- Distributed storage options: Ceph RBD and OpenEBS
- Enabling snapshot and cloning capabilities
Cluster Security
- Management of certificate authorities and PKI infrastructure
- RBAC configuration and service account governance
- Application of pod security standards and admission controllers
- Hardening of API server and etcd instances
- Implementation of image signing and verification mechanisms
Self-Hosted Container Registry
- Deployment of the Harbor registry
- Configuration of the Docker Registry
- Processes for image replication and vulnerability scanning
- Registry authentication and system integration
Monitoring and Observability
- Deployment of the Prometheus and Grafana stack
- Implementation of VictoriaMetrics as a lightweight alternative
- Collection of node and pod metrics
- Development of custom alerting rules and dashboards
- Log aggregation using Loki or Fluentd
Cluster Maintenance
- Execution of Kubernetes version upgrades via kubeadm
- Management of rolling updates for control plane components
- Standard procedures for certificate rotation
- Node maintenance protocols and cordoning strategies
Backup and Disaster Recovery
- Procedures for etcd backup and restoration
- Utilization of Velero for cluster resource and PV backup
- Development of cross-site replication strategies
- Validation of recovery procedures through testing
Multi-Cluster Management
- Management of clusters using Rancher or Portainer
- Fundamental concepts of cluster federation
- Strategies for workload distribution and optimization
Requirements
- Demonstrated understanding of containers and containerization principles
- Practical experience with Linux system administration
- Foundational knowledge of networking concepts
- Proficiency with command-line tools and SSH protocols
Audience
- DevOps/SRE engineers
- System administrators
- Technical architects
- Infrastructure engineers seeking vendor independence for government operations
21 Hours
Testimonials (1)
The knowledge and the patience from the trainer to answer to our questions.