todo.academy Try a free chapter

Application Core, true zero to capable practitioner

Kubernetes Application Operations

Deploy and troubleshoot Kubernetes applications from real state and evidence.

Start from zero, operate an application on an existing cluster, and prove each change through Kubernetes state.

No credit card for the free chapter. Preview what the chapter covers.

By the end

Observable skills you will practice.

  • Explain desired state, observed state, API objects, and controller reconciliation
  • Confirm context and namespace, discover resources, inspect schema, and apply changes safely
  • Read Pod conditions, Events, logs, and failure reasons before editing
  • Operate Deployments and ReplicaSets through rollout, failure, rollback, and recovery
  • Expose applications through Services, ready EndpointSlices, DNS, and basic Ingress
  • Configure workloads with ConfigMaps and Secrets without leaking sensitive values
  • Operate ordinary Jobs, CronJobs, PVCs, mounts, and StatefulSet identity boundaries
  • Build and verify least-privilege ServiceAccount and RBAC access with expected allow and deny checks
  • Troubleshoot and hand off an application incident with bounded, redacted evidence

Syllabus

25 chapters from the published course structure.

The focused path contains 84 required lessons. The advanced library remains available when your role needs more depth.

Focused path chapters14 chapters contain the required 84-lesson path.
Chapter 00Free

Free Kubernetes first contact

Build the first mental model: cluster, object, manifest, Deployment, Pod, Service, Event, EndpointSlice, and proof.

12 focused lessons
Chapter 01Full course

Objects, manifests, and desired state

Turn YAML into an API contract with metadata, spec, status, namespaces, labels, annotations, validation, diff, and repair.

7 focused lessons + 3 advanced lessons
Chapter 02Full course

kubectl and API discovery

Use context, namespace, API discovery, schema, tables, structured output, Events, logs, dry-run, and diff as deliberate evidence lenses.

5 focused lessons + 6 advanced lessons
Chapter 03Full course

Pods as scheduling contracts

Understand the Pod boundary, container process intent, ports, shared storage, initialization, multi-container roles, restart behavior, and temporary identity.

3 focused lessons + 8 advanced lessons
Chapter 04Full course

Pod lifecycle, conditions, Events, and logs

Read phases, conditions, container states, scheduling failures, image pull failures, crash loops, termination outcomes, Events, and current versus previous logs.

5 focused lessons + 6 advanced lessons
Chapter 05Full course

Deployments, ReplicaSets, and rollout mechanics

Follow the Deployment, ReplicaSet, and Pod ownership chain. Trigger a revision, watch rollout convergence, interpret strategy budgets, and inspect history.

5 focused lessons + 7 advanced lessons
Chapter 06Full course

Rollout failure, undo, restart, and image drift

Reproduce a broken rollout, correlate conditions with Events, read ProgressDeadlineExceeded, undo to a pinned revision, and prove recovery.

4 focused lessons + 8 advanced lessons
Chapter 07Full course

Labels, selectors, Services, and EndpointSlices

Trace labels and selectors through Service ports to ready EndpointSlices. Diagnose selector or readiness failures and prove repair with a connection result.

7 focused lessons + 5 advanced lessons
Chapter 08Full course

DNS, Ingress, and north-south entry

Resolve Service DNS, route HTTP by host and path through an IngressClass, inspect TLS intent, and repair a wrong backend port with before and after evidence.

3 focused lessons + 8 advanced lessons
Chapter 09Full course

ConfigMaps, Secrets, env, and mounted config

Inject ConfigMap and Secret data as environment values or files. Prove update timing and repair a missing-key failure without exposing credentials.

4 focused lessons + 7 advanced lessons
Chapter 10Full course

Jobs, CronJobs, retries, and completion

Run one-shot and scheduled work, control retries and deadlines, inspect history and concurrency policy, and diagnose a mixed Job and CronJob incident.

5 focused lessons + 6 advanced lessons
Chapter 11Full course

Volumes, PersistentVolumes, PVCs, and StatefulSets

Separate temporary volumes from durable claims, diagnose PVC binding, prove mounted data, and use StatefulSet identity with headless DNS and stable storage.

9 focused lessons + 3 advanced lessons
Chapter 12Full course

Namespaces, ServiceAccounts, and RBAC

Assign workload identities, build least-privilege Roles and bindings, prove allowed and denied actions with auth can-i, and repair an overbroad grant.

7 focused lessons + 5 advanced lessons
Chapter 13Full course

Final professional capstone

Build, expose, configure, authorize, protect, observe, break, repair, and hand off a production-shaped Kubernetes application.

8 focused lessons + 4 advanced lessons
Explore 11 advanced library chapters

These chapters provide optional drills and reference depth. They are not required to complete the focused path.

Library 11Full course

Resource requests, limits, QoS, and node pressure

Read CPU and memory requests and limits, predict scheduler fit from allocatable capacity, diagnose throttling and OOMKilled, classify QoS, explain Pending, read node pressure, reason about eviction, and repair a resource incident with evidence.

12 advanced lessons
Library 12Full course

Scheduler fit, affinity, taints, tolerations, and spread

Read scheduler filter, score, and bind decisions, use node labels and affinity, diagnose taint rejection, add tolerations, spread replicas across topology, reason about priority and preemption, and repair a multi-constraint Pending Pod.

11 advanced lessons
Library 13Full course

Probes, readiness, liveness, startup, and disruption

Separate alive, ready, and started, tune probe budgets, read readiness gates, protect voluntary disruption with PodDisruptionBudgets, trace graceful termination, and repair a mixed health incident.

13 advanced lessons
Library 14Full course

Debugging Pods, exec, copy, and ephemeral containers

Choose the smallest useful debug lens, preserve logs and artifacts, inspect files and processes safely, use port-forward deliberately, debug distroless images with ephemeral containers, and solve a Pod forensics incident.

12 advanced lessons
Library 15Full course

Debugging Services and network policy

Diagnose traffic in order from DNS to Service selectors, EndpointSlices, readiness, ports, NetworkPolicy, and application response, then repair layered incidents with evidence.

12 advanced lessons
Library 19Full course

Container and Pod security posture

Read securityContext identity, privilege boundaries, Pod Security Standards, capabilities, read-only filesystems, seccomp, image pull policy, imagePullSecrets, namespace admission labels, and a mixed security incident repair.

12 advanced lessons
Library 20Full course

Observability, metrics, HPA, Events, and audit thinking

Connect Metrics API availability, kubectl top, resource requests, HPA decisions, conditions, short-lived Events, audit boundaries, and a durable incident timeline.

12 advanced lessons
Library 21Full course

Cluster operations, nodes, drain, and upgrade safety

Operate nodes with condition evidence, cordon, drain, disruption budgets, DaemonSet boundaries, static Pod awareness, component responsibility, etcd safety, and maintenance incident repair.

12 advanced lessons
Library 22Full course

Helm, Kustomize, and release packaging

Treat packaging as manifest generation: build Kustomize bases and overlays, patch narrowly, render Helm values, diff concrete YAML, manage revisions, roll back deliberately, and repair a packaging incident.

11 advanced lessons
Library 23Full course

Custom resources, controllers, and operator pattern

Extend the Kubernetes API with a CRD, create custom resources, follow reconciliation through status and child objects, interpret conditions and generations, trace ownership, handle finalizers, and repair an operator incident.

12 advanced lessons
Library 24Full course

Incident gauntlet and production readiness

Diagnose mixed Kubernetes failures by evidence, choose bounded repairs, verify customer-facing recovery, and write an operator-ready handoff.

16 advanced lessons

Full access

Choose access for Kubernetes Application Operations

Every available offer is shown with its exact CAD price and billing model. Checkout opens only after you choose an offer and enter the receipt email.

Available access options

The selected offer and exact total remain visible before payment.

Already purchased? Restore access

Payments are processed by Lemon Squeezy for Phoenix Soft Inc. Paid access can be restored after secure sign-in.

Questions

Know what to expect before you start.

What can I try for free?

Free Kubernetes first contact is free and contains 12 lessons. No credit card is requested before the free workspace opens.

What experience do I need?

No Kubernetes experience is required. Basic command-line familiarity is helpful.

What does the focused path include?

84 required lessons, with 12 free and 72 included in paid access.

Is there material beyond the focused path?

Yes. The course also includes 211 advanced practice and reference resources. They are available when you need more depth, but they do not lengthen the required path.

Which paid options are available?

Academy Founder Annual: CA$139 per year. Founder Vault: CA$279 one-time.

How is paid access billed?

Academy Founder Annual: Access continues while the annual subscription remains active. Founder Vault: No recurring charge. Coverage includes courses launched during the first 24 months.

How long does it take?

The published estimate is 18 to 24 active hours for the Core Path. Your pace will depend on how much you repeat the practice.

Do I need to install anything?

No installation is required to start the guided free chapter. Later lessons explain the real tools, files, and operating boundaries relevant to the skill.

What technology is covered?

The syllabus and these stated outcomes are the source of truth: Explain desired state, observed state, API objects, and controller reconciliation; Confirm context and namespace, discover resources, inspect schema, and apply changes safely; Read Pod conditions, Events, logs, and failure reasons before editing; Operate Deployments and ReplicaSets through rollout, failure, rollback, and recovery; Expose applications through Services, ready EndpointSlices, DNS, and basic Ingress; Configure workloads with ConfigMaps and Secrets without leaking sensitive values; Operate ordinary Jobs, CronJobs, PVCs, mounts, and StatefulSet identity boundaries; Build and verify least-privilege ServiceAccount and RBAC access with expected allow and deny checks; Troubleshoot and hand off an application incident with bounded, redacted evidence.

Which browsers are supported?

Use a current browser with JavaScript enabled. The free chapter is the quickest compatibility check for your device.

Does the workspace work on mobile?

The reading pages reflow for small screens. Command-heavy practice is more comfortable with a physical keyboard and a larger display.

What happens when I make a mistake?

The practice state is isolated from production systems. Read the resulting evidence, revise the action, and try again.

How do I restore access?

Use the receipt email on the restore-access page. The sign-in link verifies the account before paid entitlements are loaded.