Inside Kubernetes
Run resilient workloads across scheduling, networking, storage, and failures
This Deep Dive follows a workload from YAML manifest through the control plane, scheduler, kubelet, Service network, and persistent storage to a running container, then puts it under rollouts, preemption, node drains, and failed mounts. You learn to predict where a Pod lands, which Pods survive eviction, how traffic reaches an endpoint, and which cluster evidence points to the fix when a workload stays Pending or in CrashLoopBackOff. Only container image and runtime basics are assumed.
See the Invisible
Interactive simulators visualise what's hidden from view.
Hands-On Labs
Step through executions tick by tick. Manipulate state.
Why, Not Just What
Understand the reasoning behind every design decision.
Quizzes & Cheatsheets
Verify your understanding and keep a quick reference handy.
Get Certified
Earn a shareable certificate to prove your deep expertise.
What's Covered
A manifest you apply is a declaration, not a command. The API server persists it in etcd, controllers reconcile observed state toward it through level-based control loops, the scheduler binds the Pod to a node, and the kubelet asks the container runtime to start it. Seeing each handoff explains why a cluster keeps converging after a controller or node fails, and where that convergence stops.
Startup, readiness, and liveness probes decide when a Pod receives traffic and when it is restarted, and preStop hooks with termination grace periods decide whether it drops requests on the way out. Deployments turn those single-Pod rules into rolling updates bounded by surge and unavailability budgets, while StatefulSets, DaemonSets, Jobs, and CronJobs each offer a different guarantee you choose on purpose.
Resource requests, node and pod affinity, topology spread constraints, and taints feed the scheduler filtering and scoring that place a Pod. Priority classes, QoS classes derived from requests and limits, and PodDisruptionBudgets then decide which Pods are preempted, evicted under node pressure, or drained during maintenance. The payoff is predicting both outcomes before the cluster acts.
East-west traffic resolves a name through cluster DNS to a Service virtual address, then to EndpointSlices that a kube-proxy or alternative data plane forwards to a Pod, subject to NetworkPolicy enforced by the CNI. North-south HTTP arrives through Ingress or Gateway API, where GatewayClass, Gateway, listeners, and routes split ownership between infrastructure and application teams.
PersistentVolumeClaims bind to CSI-backed volumes through StorageClass provisioning, access modes, reclaim policies, and volume topology, giving StatefulSet replicas stable storage identity. ServiceAccounts, RBAC bindings, security contexts, and admission policies scope what workloads and operators may do. Events, conditions, logs, and metrics tie it together as the evidence behind autoscaling, cordon and drain, and every diagnosis of a workload, traffic, or mount failure.
The Curriculum
Comprehensive Lessons! Each with theory, interactive simulation, and quiz.
What Kubernetes Is: Clusters, Pods, and kubectl
Reconciliation and the Control Plane
Pod Runtime, Configuration, and Health
Workload Controllers and Rollouts
Scheduling and Placement
Priority, Eviction, and Disruption
Service Networking and Policy
Ingress and Gateway API Traffic
Persistent Storage and Stateful Workloads
Workload Identity, RBAC, and Admission
Scaling and Operational Troubleshooting
This course in one line
Stop guessing why a Pod is Pending, unready, or unreachable
Ready to see what's really happening?
All courses included with your subscription. Cancel anytime.