Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Overview of Self-Managed Kubernetes Deployments
- Kubernetes architecture and fundamental components
- Evaluating trade-offs between managed services and self-hosted environments for government applications
- Implications for data sovereignty and avoidance of vendor lock-in
- Implementation methodologies: kubeadm, kOps, and manual provisioning
Infrastructure Planning and Resource Allocation
- Determining hardware specifications for control plane and worker nodes
- Establishing high availability requirements and architectural topologies
- Operating system selection and hardening (Ubuntu, RHEL, Rocky Linux)
- Network prerequisites and firewall policy configuration
Installation of Container Runtimes
- Comparison of container runtime options: containerd versus CRI-O
- Installation and configuration procedures for containerd
- Installation and configuration procedures for CRI-O
- Security considerations regarding runtime integrity
Cluster Initialization via kubeadm
- Deployment of kubeadm, kubelet, and kubectl components
- Initialization of the primary control plane node
- Configuration of kubeconfig files for administrative access
- Addition of secondary control plane nodes to ensure high availability
- Integration of worker nodes into the cluster infrastructure for government workloads
High Availability Architecture
- Differentiating between stacked and external etcd topologies
- Implementation of HAProxy or Keepalived for API server load balancing
- Certificate lifecycle management and renewal protocols
- Disaster recovery strategies for etcd data persistence
Container Network Interface (CNI) Configuration
- Selection of CNI plugins: Calico, Cilium, Flannel, or Weave
- Deployment and configuration of the Calico network plugin
- Implementation of network policies for security enforcement
- Configuration of pod-to-pod and node-to-node communication paths
- Service exposure mechanisms in environments without cloud-based load balancers
Network Load Balancing Services
- Deployment of MetalLB for bare-metal network load balancing
- Configuration of Layer 2 and BGP operational modes
- Alternative solutions using Keepalived and HAProxy
- Deployment of ingress controllers (nginx, Traefik) for traffic management
Storage Infrastructure Solutions
- Understanding storage classes and Container Storage Interface (CSI) drivers
- Implementation of local persistent volumes
- Configuration of NFS provisioners
- Evaluation of distributed storage systems: Ceph RBD and OpenEBS
- Utilization of snapshot and cloning capabilities for data management
Security Framework Implementation
- Management of certificate authorities and Public Key Infrastructure (PKI)
- Configuration of Role-Based Access Control (RBAC) and service accounts
- Enforcement of pod security standards and admission controllers
- Hardening of the API server and etcd storage layer
- Implementation of image signing and verification protocols
Internal Container Registry Deployment
- Deployment of Harbor registry infrastructure
- Configuration of Docker Registry instances
- Establishment of image replication and vulnerability scanning procedures
- Authentication mechanisms and integration with cluster workflows for government compliance
Monitoring, Logging, and Observability
- Deployment of the Prometheus and Grafana monitoring stack
- Evaluation of VictoriaMetrics as a resource-efficient alternative
- Collection of metrics from nodes and pods
- Development of custom alerting rules and operational dashboards
- Implementation of log aggregation using Loki or Fluentd
Operational Maintenance Procedures
- Execution of Kubernetes version upgrades via kubeadm
- Management of rolling updates for control plane components
- Procedures for certificate rotation
- Node maintenance protocols including cordon and drain operations
Backup and Disaster Recovery Planning
- Procedures for etcd backup and restoration
- Utilization of Velero for cluster resource and persistent volume backup
- Strategies for cross-site data replication
- Regular testing and validation of recovery procedures for government continuity
Multi-Cluster Governance
- Use of Rancher or Portainer for centralized cluster management
- Concepts and implementation of cluster federation
- Strategies for workload distribution across multiple environments
Requirements
**Prerequisites**
* Proficiency in containerization technologies and underlying concepts.
* Demonstrated experience performing Linux system administration tasks.
* Foundational knowledge of network architecture and protocols.
* Competency with command-line interfaces and Secure Shell (SSH) connectivity.
**Intended Audience**
This material is designed for professionals requiring robust, vendor-neutral infrastructure solutions **for government** agencies and public sector entities, including:
* DevOps and Site Reliability Engineering practitioners.
* System administrators managing core IT resources.
* Technical architects designing scalable environments.
* Infrastructure engineers focused on achieving vendor independence.
21 Hours
Testimonials (1)
The knowledge and the patience from the trainer to answer to our questions.