Who Owns What
Module 01 — the control-plane map, and what an outage actually costs
Spine segment: desired object · unit u1
- Five actors
- One contract
- What etcd holds
- Controllers, plural
- One decision
- The node's agent
- Four loops, one Deployment
27 narrated modules, one per course unit. The pilot walks the whole request path end to end; each module then goes deeper on a single segment of it. They assume you have watched the pilot, and they teach only what their unit teaches.
Module 01 — the control-plane map, and what an outage actually costs
Spine segment: desired object · unit u1
Module 02 — the API request path, admission webhooks, and who owns a field
Spine segment: admission / storage · unit u2
Module 03 — informers, level-based reconciliation, and loops that eat themselves
Spine segment: watch / cache · unit u3
Module 04 — workload controllers, autoscaler conflict, and what a PDB really covers
Spine segment: controller queue · unit u4
Module 05 — CRDs, operators, versioning, and finalizers
Spine segment: controller queue · unit u5
Module 06 — the scheduling framework, why a Pod stays Pending, and what preemption costs
Spine segment: scheduler queue + binding · unit u6
Module 07 — the kubelet's loop, the four boundaries, and what a Pod's status is really telling you
Spine segment: kubelet · unit u7
Module 08 — Service identity, the two data planes, and how a Pod actually gets its address
Spine segment: CNI · unit u8
Module 09 — resolver policy, the compiled plugin chain, and what Ready has not proven
Spine segment: DNS · unit u9
Module 10 — claim, class and volume, the CSI split, and why storage decides where a Pod can run
Spine segment: CSI · unit u10
Module 11 — two availability models, quorum arithmetic, and what a snapshot leaves out
Spine segment: admission / storage · unit u11
Module 12 — API Priority and Fairness, the evidence hierarchy, and the spine as a diagnostic tool
Spine segment: desired object · unit u12
Module 13 — what kubeadm actually builds, skew boundaries, and what makes an upgrade safe
Spine segment: desired object · unit u13
Module 14 — config delivery semantics, how QoS is derived, and eviction versus OOM
Spine segment: kubelet · unit u14
Module 15 — Ingress and Gateway API, ownership boundaries, and why an accepted route can serve nothing
Spine segment: service · unit u15
Module 16 — topology hints, node admission, and why a CPU limit is not isolation
Spine segment: kubelet · unit u16
Module 17 — device plugins versus DRA, the allocation handshake, and where a device Pod stalls
Spine segment: scheduler queue + binding · unit u17
Module 18 — the aggregation layer, watch expiry, and policy without a network call
Spine segment: desired object · unit u18
Module 19 — leader election as optimistic concurrency, and what each gate actually delays
Spine segment: controller queue · unit u19
Module 20 — the CKA troubleshooting spine, from control plane to Service
Spine segment: desired object · unit u20
Module 21 — how RBAC actually composes, and how a node earns its identity
Spine segment: admission / storage · unit u21
Module 22 — what kubectl top actually reads, and preserving evidence before restart
Spine segment: kubelet · unit u22
Module 23 — what a successful Helm release proves, and who owns each field
Spine segment: desired object · unit u23
Module 24 — LimitRange and quota at admission, and proving a live resize took effect
Spine segment: admission / storage · unit u24
Module 25 — Service types as layers, and what EndpointSlice conditions actually encode
Spine segment: service · unit u25
Module 26 — three restart owners, native sidecars, and the Job result protocol
Spine segment: kubelet · unit u26
Module 27 — Pod Security Admission versus runtime enforcement, and choosing an isolation boundary
Spine segment: admission / storage · unit u27