Get in Touch

Course Outline

Introduction to Self-Managed Kubernetes for Government

  • Kubernetes architecture and essential components
  • Comparative analysis of managed versus self-managed Kubernetes environments
  • Assessment of vendor dependency risks and sovereign control advantages
  • Deployment methodologies: kubeadm, kOps, and manual installation

Infrastructure Planning for Government Operations

  • Resource sizing strategies for control plane and worker nodes
  • High availability mandates and topology designs
  • Operating system selection and preparation (Ubuntu, RHEL, Rocky Linux)
  • Network prerequisites and firewall configuration standards

Installation of Container Runtimes

  • Evaluation of container runtime options: containerd vs. CRI-O
  • Procedure for installing and configuring containerd
  • Procedure for installing and configuring CRI-O
  • Runtime security protocols and considerations

Cluster Bootstrapping with kubeadm

  • Installation of kubeadm, kubelet, and kubectl utilities
  • Initialization of the primary control plane node
  • Configuration of kubeconfig for secure cluster access
  • Integration of additional control plane nodes for high availability
  • Provisioning and joining of worker nodes to the cluster

High Availability Configuration

  • Architectural comparison: stacked versus external etcd topologies
  • Implementation of HAProxy or Keepalived for API server load distribution
  • Certificate lifecycle management and renewal processes
  • etcd backup and recovery protocols for data integrity

Container Networking

  • CNI plugin selection: Calico, Cilium, Flannel, and Weave
  • Installation and configuration of Calico
  • Establishment of network policies for enhanced security
  • Node-to-node communication and pod network architecture
  • Service exposure strategies independent of cloud load balancers

Service Load Balancing

  • Utilization of MetalLB for bare-metal load balancing
  • Configuration of Layer 2 and BGP operating modes
  • Implementation of Keepalived and HAProxy alternatives
  • Deployment of ingress controllers (nginx, Traefik)

Storage Solutions

  • Concepts of storage classes and CSI drivers
  • Implementation of local persistent volumes
  • Setup of NFS provisioners
  • Distributed storage options: Ceph RBD and OpenEBS
  • Enabling snapshot and cloning capabilities

Cluster Security

  • Management of certificate authorities and PKI infrastructure
  • RBAC configuration and service account governance
  • Application of pod security standards and admission controllers
  • Hardening of API server and etcd instances
  • Implementation of image signing and verification mechanisms

Self-Hosted Container Registry

  • Deployment of the Harbor registry
  • Configuration of the Docker Registry
  • Processes for image replication and vulnerability scanning
  • Registry authentication and system integration

Monitoring and Observability

  • Deployment of the Prometheus and Grafana stack
  • Implementation of VictoriaMetrics as a lightweight alternative
  • Collection of node and pod metrics
  • Development of custom alerting rules and dashboards
  • Log aggregation using Loki or Fluentd

Cluster Maintenance

  • Execution of Kubernetes version upgrades via kubeadm
  • Management of rolling updates for control plane components
  • Standard procedures for certificate rotation
  • Node maintenance protocols and cordoning strategies

Backup and Disaster Recovery

  • Procedures for etcd backup and restoration
  • Utilization of Velero for cluster resource and PV backup
  • Development of cross-site replication strategies
  • Validation of recovery procedures through testing

Multi-Cluster Management

  • Management of clusters using Rancher or Portainer
  • Fundamental concepts of cluster federation
  • Strategies for workload distribution and optimization

Requirements

  • Demonstrated understanding of containers and containerization principles
  • Practical experience with Linux system administration
  • Foundational knowledge of networking concepts
  • Proficiency with command-line tools and SSH protocols

Audience

  • DevOps/SRE engineers
  • System administrators
  • Technical architects
  • Infrastructure engineers seeking vendor independence for government operations
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories