Series · 18 parts
Docker, Compose & Kubernetes
Lộ trình tiếng Việt theo hai chặng: 10 phần nền tảng giúp bạn làm chủ container, image, Dockerfile, storage, networking, Compose, hardening và debug; nhánh chuyên sâu đi xuống OCI runtime, namespace/cgroup, BuildKit và supply chain, Compose cho team/CI, rồi vào Kubernetes networking, scheduling, autoscaling, stateful storage, security, observability và incident response. Mỗi phần ưu tiên mental model, trade-off, failure mode, lab có thể tự phá–sửa và tài liệu chính thức để biến kiến thức thành năng lực vận hành production.
-
Hiểu đúng container, image, layer và vòng đời docker run; so sánh với VM, thực hành container đầu tiên và các lệnh cốt lõi.
-
Tự build image với Dockerfile: instruction, layer/cache, multi-stage, .dockerignore, CMD/ENTRYPOINT và chiến lược tag.
-
Làm chủ dữ liệu container với named volume, bind mount, tmpfs; thực hành PostgreSQL bền vững và quản lý cấu hình an toàn.
-
Theo dõi đường đi mạng Docker: bridge, DNS theo tên service, publish/expose port và kết nối ứng dụng với database.
-
Dựng ứng dụng nhiều container bằng compose.yaml: service, image/build, network, volume, dependency và workflow hằng ngày.
-
Đào sâu Compose với interpolation, healthcheck, profiles, override files, scale và restart policy qua các lab có thể chạy.
-
Tối ưu và harden image với base nhỏ, cache, multi-stage, non-root, secret mount, .dockerignore và quét lỗ hổng.
-
Playbook debug Docker theo evidence: status, logs, inspect, events, stats; xử lý exit code, OOM, port, cache, network và disk.
-
Từ một host tới cluster: kiến trúc Kubernetes, Pod, Deployment, Service, kubectl, kind và lần deploy ứng dụng đầu tiên.
-
Đưa workload Kubernetes tới mức production-shaped với config, probes, resources, rollout và playbook debug sự cố bằng kubectl.
-
Đi từ docker run xuống OCI, containerd, runc, namespaces, cgroups v2, copy-on-write, PID 1 và rootless bằng các lab quan sát trực tiếp.
-
Hiểu BuildKit như DAG, dùng cache/secret/SSH mounts, build amd64+arm64, xuất cache CI và gắn SBOM/provenance vào image.
-
Thiết kế workflow Compose lặp lại được với config đã resolve, merge/include, Watch, secrets/configs, CI validation và ranh giới production.
-
Theo một packet qua Pod, CNI, Service, EndpointSlice, CoreDNS và Gateway API; khóa traffic bằng NetworkPolicy và debug theo từng lớp.
-
Hiểu scheduler, requests/limits, QoS, placement, topology spread, PDB và HPA v2; thực hành lỗi Pending, eviction và autoscaling.
-
Làm chủ Kubernetes storage: PV/PVC/StorageClass/CSI, StatefulSet, topology-aware provisioning, backup, restore và failure drill.
-
Harden workload Kubernetes bằng RBAC tối thiểu, Pod Security Restricted, Secret an toàn, NetworkPolicy, image bất biến và audit drill.
-
Từ alert tới nguyên nhân: logs, metrics, traces, events, kubectl debug, SLO và quy trình incident có evidence, rollback và postmortem.