jvinhit//lab

Search posts

Type to search across journal entries.

navigate open esc close

Series · 18 parts

Docker, Compose & Kubernetes

Lộ trình tiếng Việt theo hai chặng: 10 phần nền tảng giúp bạn làm chủ container, image, Dockerfile, storage, networking, Compose, hardening và debug; nhánh chuyên sâu đi xuống OCI runtime, namespace/cgroup, BuildKit và supply chain, Compose cho team/CI, rồi vào Kubernetes networking, scheduling, autoscaling, stateful storage, security, observability và incident response. Mỗi phần ưu tiên mental model, trade-off, failure mode, lab có thể tự phá–sửa và tài liệu chính thức để biến kiến thức thành năng lực vận hành production.

  1. Hiểu đúng container, image, layer và vòng đời docker run; so sánh với VM, thực hành container đầu tiên và các lệnh cốt lõi.

  2. Tự build image với Dockerfile: instruction, layer/cache, multi-stage, .dockerignore, CMD/ENTRYPOINT và chiến lược tag.

  3. Làm chủ dữ liệu container với named volume, bind mount, tmpfs; thực hành PostgreSQL bền vững và quản lý cấu hình an toàn.

  4. Theo dõi đường đi mạng Docker: bridge, DNS theo tên service, publish/expose port và kết nối ứng dụng với database.

  5. Dựng ứng dụng nhiều container bằng compose.yaml: service, image/build, network, volume, dependency và workflow hằng ngày.

  6. Đào sâu Compose với interpolation, healthcheck, profiles, override files, scale và restart policy qua các lab có thể chạy.

  7. Tối ưu và harden image với base nhỏ, cache, multi-stage, non-root, secret mount, .dockerignore và quét lỗ hổng.

  8. Playbook debug Docker theo evidence: status, logs, inspect, events, stats; xử lý exit code, OOM, port, cache, network và disk.

  9. Từ một host tới cluster: kiến trúc Kubernetes, Pod, Deployment, Service, kubectl, kind và lần deploy ứng dụng đầu tiên.

  10. Đưa workload Kubernetes tới mức production-shaped với config, probes, resources, rollout và playbook debug sự cố bằng kubectl.

  11. Đi từ docker run xuống OCI, containerd, runc, namespaces, cgroups v2, copy-on-write, PID 1 và rootless bằng các lab quan sát trực tiếp.

  12. Hiểu BuildKit như DAG, dùng cache/secret/SSH mounts, build amd64+arm64, xuất cache CI và gắn SBOM/provenance vào image.

  13. Thiết kế workflow Compose lặp lại được với config đã resolve, merge/include, Watch, secrets/configs, CI validation và ranh giới production.

  14. Theo một packet qua Pod, CNI, Service, EndpointSlice, CoreDNS và Gateway API; khóa traffic bằng NetworkPolicy và debug theo từng lớp.

  15. Hiểu scheduler, requests/limits, QoS, placement, topology spread, PDB và HPA v2; thực hành lỗi Pending, eviction và autoscaling.

  16. Làm chủ Kubernetes storage: PV/PVC/StorageClass/CSI, StatefulSet, topology-aware provisioning, backup, restore và failure drill.

  17. Harden workload Kubernetes bằng RBAC tối thiểu, Pod Security Restricted, Secret an toàn, NetworkPolicy, image bất biến và audit drill.

  18. Từ alert tới nguyên nhân: logs, metrics, traces, events, kubectl debug, SLO và quy trình incident có evidence, rollback và postmortem.