Get in Touch

Course Outline

Overview of Self-Managed Kubernetes Deployments

  • Kubernetes architecture and fundamental components
  • Evaluating trade-offs between managed services and self-hosted environments for government applications
  • Implications for data sovereignty and avoidance of vendor lock-in
  • Implementation methodologies: kubeadm, kOps, and manual provisioning

Infrastructure Planning and Resource Allocation

  • Determining hardware specifications for control plane and worker nodes
  • Establishing high availability requirements and architectural topologies
  • Operating system selection and hardening (Ubuntu, RHEL, Rocky Linux)
  • Network prerequisites and firewall policy configuration

Installation of Container Runtimes

  • Comparison of container runtime options: containerd versus CRI-O
  • Installation and configuration procedures for containerd
  • Installation and configuration procedures for CRI-O
  • Security considerations regarding runtime integrity

Cluster Initialization via kubeadm

  • Deployment of kubeadm, kubelet, and kubectl components
  • Initialization of the primary control plane node
  • Configuration of kubeconfig files for administrative access
  • Addition of secondary control plane nodes to ensure high availability
  • Integration of worker nodes into the cluster infrastructure for government workloads

High Availability Architecture

  • Differentiating between stacked and external etcd topologies
  • Implementation of HAProxy or Keepalived for API server load balancing
  • Certificate lifecycle management and renewal protocols
  • Disaster recovery strategies for etcd data persistence

Container Network Interface (CNI) Configuration

  • Selection of CNI plugins: Calico, Cilium, Flannel, or Weave
  • Deployment and configuration of the Calico network plugin
  • Implementation of network policies for security enforcement
  • Configuration of pod-to-pod and node-to-node communication paths
  • Service exposure mechanisms in environments without cloud-based load balancers

Network Load Balancing Services

  • Deployment of MetalLB for bare-metal network load balancing
  • Configuration of Layer 2 and BGP operational modes
  • Alternative solutions using Keepalived and HAProxy
  • Deployment of ingress controllers (nginx, Traefik) for traffic management

Storage Infrastructure Solutions

  • Understanding storage classes and Container Storage Interface (CSI) drivers
  • Implementation of local persistent volumes
  • Configuration of NFS provisioners
  • Evaluation of distributed storage systems: Ceph RBD and OpenEBS
  • Utilization of snapshot and cloning capabilities for data management

Security Framework Implementation

  • Management of certificate authorities and Public Key Infrastructure (PKI)
  • Configuration of Role-Based Access Control (RBAC) and service accounts
  • Enforcement of pod security standards and admission controllers
  • Hardening of the API server and etcd storage layer
  • Implementation of image signing and verification protocols

Internal Container Registry Deployment

  • Deployment of Harbor registry infrastructure
  • Configuration of Docker Registry instances
  • Establishment of image replication and vulnerability scanning procedures
  • Authentication mechanisms and integration with cluster workflows for government compliance

Monitoring, Logging, and Observability

  • Deployment of the Prometheus and Grafana monitoring stack
  • Evaluation of VictoriaMetrics as a resource-efficient alternative
  • Collection of metrics from nodes and pods
  • Development of custom alerting rules and operational dashboards
  • Implementation of log aggregation using Loki or Fluentd

Operational Maintenance Procedures

  • Execution of Kubernetes version upgrades via kubeadm
  • Management of rolling updates for control plane components
  • Procedures for certificate rotation
  • Node maintenance protocols including cordon and drain operations

Backup and Disaster Recovery Planning

  • Procedures for etcd backup and restoration
  • Utilization of Velero for cluster resource and persistent volume backup
  • Strategies for cross-site data replication
  • Regular testing and validation of recovery procedures for government continuity

Multi-Cluster Governance

  • Use of Rancher or Portainer for centralized cluster management
  • Concepts and implementation of cluster federation
  • Strategies for workload distribution across multiple environments

Requirements

**Prerequisites** * Proficiency in containerization technologies and underlying concepts. * Demonstrated experience performing Linux system administration tasks. * Foundational knowledge of network architecture and protocols. * Competency with command-line interfaces and Secure Shell (SSH) connectivity. **Intended Audience** This material is designed for professionals requiring robust, vendor-neutral infrastructure solutions **for government** agencies and public sector entities, including: * DevOps and Site Reliability Engineering practitioners. * System administrators managing core IT resources. * Technical architects designing scalable environments. * Infrastructure engineers focused on achieving vendor independence.
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories