Course

Inside Kubernetes

Run resilient workloads across scheduling, networking, storage, and failures

This Deep Dive follows a workload from YAML manifest through the control plane, scheduler, kubelet, Service network, and persistent storage to a running container, then puts it under rollouts, preemption, node drains, and failed mounts. You learn to predict where a Pod lands, which Pods survive eviction, how traffic reaches an endpoint, and which cluster evidence points to the fix when a workload stays Pending or in CrashLoopBackOff. Only container image and runtime basics are assumed.

Latest Updates 2026

See the Invisible

Interactive simulators visualise what's hidden from view.

Hands-On Labs

Step through executions tick by tick. Manipulate state.

Why, Not Just What

Understand the reasoning behind every design decision.

Quizzes & Cheatsheets

Verify your understanding and keep a quick reference handy.

Get Certified

Earn a shareable certificate to prove your deep expertise.

What's Covered

Desired State and the Control Plane

A manifest you apply is a declaration, not a command. The API server persists it in etcd, controllers reconcile observed state toward it through level-based control loops, the scheduler binds the Pod to a node, and the kubelet asks the container runtime to start it. Seeing each handoff explains why a cluster keeps converging after a controller or node fails, and where that convergence stops.

Pod Lifecycle and Workload Controllers

Startup, readiness, and liveness probes decide when a Pod receives traffic and when it is restarted, and preStop hooks with termination grace periods decide whether it drops requests on the way out. Deployments turn those single-Pod rules into rolling updates bounded by surge and unavailability budgets, while StatefulSets, DaemonSets, Jobs, and CronJobs each offer a different guarantee you choose on purpose.

Scheduling, Priority, and Disruption

Resource requests, node and pod affinity, topology spread constraints, and taints feed the scheduler filtering and scoring that place a Pod. Priority classes, QoS classes derived from requests and limits, and PodDisruptionBudgets then decide which Pods are preempted, evicted under node pressure, or drained during maintenance. The payoff is predicting both outcomes before the cluster acts.

Traffic from Cluster DNS to Gateway API

East-west traffic resolves a name through cluster DNS to a Service virtual address, then to EndpointSlices that a kube-proxy or alternative data plane forwards to a Pod, subject to NetworkPolicy enforced by the CNI. North-south HTTP arrives through Ingress or Gateway API, where GatewayClass, Gateway, listeners, and routes split ownership between infrastructure and application teams.

Storage, Identity, and Operational Evidence

PersistentVolumeClaims bind to CSI-backed volumes through StorageClass provisioning, access modes, reclaim policies, and volume topology, giving StatefulSet replicas stable storage identity. ServiceAccounts, RBAC bindings, security contexts, and admission policies scope what workloads and operators may do. Events, conditions, logs, and metrics tie it together as the evidence behind autoscaling, cordon and drain, and every diagnosis of a workload, traffic, or mount failure.

The Curriculum

Comprehensive Lessons! Each with theory, interactive simulation, and quiz.

What Kubernetes Is: Clusters, Pods, and kubectl

Reconciliation and the Control Plane

Pod Runtime, Configuration, and Health

Workload Controllers and Rollouts

Scheduling and Placement

Priority, Eviction, and Disruption

Service Networking and Policy

Ingress and Gateway API Traffic

Persistent Storage and Stateful Workloads

Workload Identity, RBAC, and Admission

Scaling and Operational Troubleshooting

This course in one line

Stop guessing why a Pod is Pending, unready, or unreachable

Ready to see what's really happening?

All courses included with your subscription. Cancel anytime.