Kubernetes Beyond YAML

Video modules

27 narrated modules, one per course unit. The pilot walks the whole request path end to end; each module then goes deeper on a single segment of it. They assume you have watched the pilot, and they teach only what their unit teaches.

01

Who Owns What

Module 01 — the control-plane map, and what an outage actually costs

Watch · 6:00 file

Spine segment: desired object · unit u1

02

Five Gates

Module 02 — the API request path, admission webhooks, and who owns a field

Watch · 5:25 file

Spine segment: admission / storage · unit u2

03

Events Are Hints

Module 03 — informers, level-based reconciliation, and loops that eat themselves

Watch · 4:54 file

Spine segment: watch / cache · unit u3

04

Four Different Promises

Module 04 — workload controllers, autoscaler conflict, and what a PDB really covers

Watch · 5:50 file

Spine segment: controller queue · unit u4

05

An API You Cannot Take Back

Module 05 — CRDs, operators, versioning, and finalizers

Watch · 5:37 file

Spine segment: controller queue · unit u5

06

Choose, Then Commit

Module 06 — the scheduling framework, why a Pod stays Pending, and what preemption costs

Watch · 4:40 file

Spine segment: scheduler queue + binding · unit u6

07

Running Is Not Ready

Module 07 — the kubelet's loop, the four boundaries, and what a Pod's status is really telling you

Watch · 4:33 file

Spine segment: kubelet · unit u7

08

A Permission Is Not A Path

Module 08 — Service identity, the two data planes, and how a Pod actually gets its address

Watch · 4:27 file

Spine segment: CNI · unit u8

09

Not The Name You Typed

Module 09 — resolver policy, the compiled plugin chain, and what Ready has not proven

Watch · 4:09 file

Spine segment: DNS · unit u9

10

Two Halves, One Volume

Module 10 — claim, class and volume, the CSI split, and why storage decides where a Pod can run

Watch · 3:43 file

Spine segment: CSI · unit u10

11

A Backup You Have Restored

Module 11 — two availability models, quorum arithmetic, and what a snapshot leaves out

Watch · 3:55 file

Spine segment: admission / storage · unit u11

12

Which Signal Proves What

Module 12 — API Priority and Fairness, the evidence hierarchy, and the spine as a diagnostic tool

Watch · 4:23 file

Spine segment: desired object · unit u12

13

kubeadm Writes Files, Then Leaves

Module 13 — what kubeadm actually builds, skew boundaries, and what makes an upgrade safe

Watch · 3:19 file

Spine segment: desired object · unit u13

14

An Update Is Not A Reload

Module 14 — config delivery semantics, how QoS is derived, and eviction versus OOM

Watch · 3:04 file

Spine segment: kubelet · unit u14

15

Objects Describe, Controllers Forward

Module 15 — Ingress and Gateway API, ownership boundaries, and why an accepted route can serve nothing

Watch · 2:58 file

Spine segment: service · unit u15

16

Feasible Is Not Local

Module 16 — topology hints, node admission, and why a CPU limit is not isolation

Watch · 3:20 file

Spine segment: kubelet · unit u16

17

From Scalar Counts To Claims

Module 17 — device plugins versus DRA, the allocation handshake, and where a device Pod stalls

Watch · 3:15 file

Spine segment: scheduler queue + binding · unit u17

18

Not Every API Is Stored Here

Module 18 — the aggregation layer, watch expiry, and policy without a network call

Watch · 3:07 file

Spine segment: desired object · unit u18

19

Four Gates, Four Transitions

Module 19 — leader election as optimistic concurrency, and what each gate actually delays

Watch · 3:06 file

Spine segment: controller queue · unit u19

20

Start At The Nearest Authority

Module 20 — the CKA troubleshooting spine, from control plane to Service

Watch · 3:15 file

Spine segment: desired object · unit u20

21

Scope Is Part Of The Permission

Module 21 — how RBAC actually composes, and how a node earns its identity

Watch · 2:39 file

Spine segment: admission / storage · unit u21

22

The Metrics API Is Not Monitoring

Module 22 — what kubectl top actually reads, and preserving evidence before restart

Watch · 2:30 file

Spine segment: kubelet · unit u22

23

Render First, Then Reconcile

Module 23 — what a successful Helm release proves, and who owns each field

Watch · 2:55 file

Spine segment: desired object · unit u23

24

Rejected, Not Pending

Module 24 — LimitRange and quota at admission, and proving a live resize took effect

Watch · 2:53 file

Spine segment: admission / storage · unit u24

25

Membership Is Not Eligibility

Module 25 — Service types as layers, and what EndpointSlice conditions actually encode

Watch · 2:41 file

Spine segment: service · unit u25

26

Ask Which Object Restarted

Module 26 — three restart owners, native sidecars, and the Job result protocol

Watch · 2:47 file

Spine segment: kubelet · unit u26

27

Admission Checks The Spec

Module 27 — Pod Security Admission versus runtime enforcement, and choosing an isolation boundary

Watch · 2:54 file

Spine segment: admission / storage · unit u27