Kubernetes Hands-On Labs

The Kubernetes labs give you a real cluster to work on, not a diagram. From a first cluster and a first Pod, to writing the manifests yourself, exposing an application with Ingress, and resolving an RBAC incident in a production-style scenario.

What you will practice in the Kubernetes labs

  • Pods and lifecycle
  • Deployments
  • YAML manifests
  • ConfigMaps and Secrets
  • Probes and resource limits
  • Jobs and CronJobs
  • Services and DNS
  • Ingress
  • Network Policies
  • RBAC and ServiceAccounts
  • Namespaces
  • Troubleshooting
  1. 01
    Your First Cluster

    Read a running control plane, carve out a namespace, and put your first workload on it.

    Beginner · 20 min

  2. 02
    Pods and the Lifecycle

    Watch what Kubernetes does when a container finishes, when it fails, and when something has to run before it.

    Beginner · 25 min

  3. 03
    Deployments and Reconciliation

    Hand the cluster a desired state and let the controllers keep it true — through scaling, deletion, and a rolling release.

    Beginner · 30 min

  4. 04
    Write the Manifests Yourself

    Move from imperative kubectl to a directory of YAML that is the source of truth for a running application.

    Beginner · 40 min

  5. 05
    Deploy and Reach a Web Application

    Put a real web application on the cluster, give it a stable address, and prove another Pod can reach it by name.

    Beginner · 40 min

  6. 06
    ConfigMaps and Secrets

    Separate configuration from the image, deliver it as files and environment variables, and rotate it on a running Pod.

    Intermediate · 30 min

  7. 07
    Probes and Resource Limits

    Tell the cluster what healthy means and what your workload costs, then watch a readiness probe pull a Pod out of service.

    Intermediate · 30 min

  8. 08
    Jobs and CronJobs

    Run work that is meant to finish, decide how many times it should retry, and put it on a schedule.

    Intermediate · 25 min

  9. 09
    Services, DNS, and NodePort

    Work through the Service types from the inside out: ClusterIP, headless, and a port punched through the node.

    Intermediate · 30 min

  10. 10
    Ingress and HTTP Routing

    Put one HTTP entry point in front of several services and route by path and by hostname.

    Intermediate · 30 min

  11. 11
    Network Policies

    Close a namespace down to default-deny, then open exactly one path — and prove both halves.

    Intermediate · 30 min

  12. 12
    Expose and Harden the Stack

    Build a configured, replicated web application, publish it through Ingress, and lock its network down without taking it offline.

    Intermediate · 45 min

  13. 13
    Your First ServiceAccount

    Give a workload an identity of its own, find the token inside the running container, then take it away entirely.

    Beginner · 20 min

  14. 14
    Give a ServiceAccount Limited Access

    Write a Role, bind it, and then prove the boundary by showing everything the identity still cannot do.

    Beginner · 25 min

  15. 15
    Role or ClusterRole?

    Three ways to combine a role and a binding, and the question that tells you which one you need.

    Intermediate · 25 min

  16. 16
    Namespace Isolation

    Two teams, one ClusterRole definition, and a boundary you have to prove in both directions.

    Intermediate · 25 min

  17. 17
    Debug the Forbidden Error

    Three identities that cannot do their jobs, three different root causes, and no error message that tells you which.

    Intermediate · 25 min

  18. 18
    Production RBAC Incident

    A workload was given cluster-admin to fix an outage. Take it back without taking the service down.

    Advanced · 35 min

View the full course

Why practice Kubernetes hands-on?

  • Kubernetes has concepts that look simple in a talk and fall apart the first time you write the YAML yourself. The lab shows the difference.
  • Every module closes with a scenario lab: expose and harden a full stack, or resolve a permissions incident.
  • The cluster is real, so what you learn is what you will do on your team's cluster.

Frequently asked questions

Is the cluster real?

Yes. Each lab creates a Kubernetes cluster of your own, and you work on it with kubectl from a terminal in the browser.

Do I need Docker first?

Preferably. Kubernetes runs containers, so understanding images and containers makes you faster. The Docker labs are there if you need to start with them.

Do the labs cover RBAC and networking?

Yes. There is a full networking module (Services, DNS, Ingress, Network Policies) and a full RBAC module that ends with an incident scenario.