Kubernetes learning track

Learn by building the cluster.

Eight focused lessons, editable commands, guided architecture tours, and quick checks—without touching a real cluster.

8Lessons
8Interactive labs
3h 11mEst. time

Course progress

Lesson 7 of 8

0%
0 completed
Lesson 07 30 minIntermediate

Production

Security essentials

Use namespaces, service accounts, RBAC, security contexts, and resource limits to reduce risk.

What you'll learn

  • Apply least privilege
  • Set workload constraints
  • Avoid common secret mistakes

Key idea

Start with least privilege.

RBAC should grant each user and workload only the actions and resources it truly needs.

Interactive command lab

Change the syntax. See what Kubernetes does.

Simulation only — no real cluster changes

Original syntax

kubectl auth can-i VERB [TYPE | TYPE/NAME] [flags]
$ kubectl auth can-i list pods --namespace=default

Execution path

Read from top to bottom. Every arrow explains the action and destination.

Outside the cluster · your computer

kubectl

Builds the API request from the command you entered

1

SEND HTTPS API REQUEST

kubectl sends the desired operation to the Kubernetes API server

KUBERNETES CLUSTER

The control plane manages one or more worker nodes

CONTROL PLANE

Makes cluster-wide decisions; it does not run your application container

API server

Authenticates, validates, and stores the desired state

2

WATCH FOR UNSCHEDULED PODS

The scheduler watches the API server for Pods without a node

Scheduler

Chooses the best worker node based on resources and constraints

3

RECONCILE DESIRED STATE

Controllers compare desired state with actual state through the API server

Controllers

Create, replace, or repair managed Kubernetes resources

4

BIND POD TO WORKER NODE

The scheduling decision is stored; the selected node's kubelet sees the PodSpec

WORKER NODE

A machine that runs application workloads

kubelet

The node agent reads the PodSpec and asks the container runtime to start it

5

CREATE POD SANDBOX

The node prepares networking, storage, and the shared Pod lifecycle

POD

The smallest deployable unit; containers share network and lifecycle

Container

The selected image runs inside the Pod

6

REPORT STATUS

The kubelet reports container and Pod readiness back to the API server

Service / ConfigMap

A Service selects Pods for traffic; a ConfigMap is mounted or injected. Both are cluster resources outside the Pod.

Ready for the guided tour

The tour opens as a fixed panel, so the diagram remains fully visible.

Quick knowledge check

Two-question quiz

Get both correct to pass
01What principle should RBAC permissions follow?
02Does kubectl auth can-i perform the requested action?

Choose one answer for each question

Feedback appears after you check your answers.

Lesson 7 of 8

Next

Quick reference

Words you'll use every day

Pod
One or more tightly coupled containers scheduled together.
Node
A worker machine that runs Pods.
Cluster
A control plane plus one or more worker nodes.
kubectl
The command-line client for the Kubernetes API.