Skip to content

Kubernetes and Docker

flowchart TD
    A[Kubernetes Docker] --> B[Key Concepts]
    A --> C[Core Principles]
    A --> D[Practical Applications]
    B --> E[Fundamental definitions]
    C --> F[Design patterns]
    D --> G[Real-world usage]
  • What are containers?
  • Benefits of containers
  • Container vs VM
  • Docker overview
  • Docker installation
  • Docker images
  • Docker containers
  • Dockerfile
  • Docker Compose
  • Kubernetes architecture
  • Pods
  • Services
  • Deployments
  • Namespaces
  • Service types
  • Ingress
  • Network policies
  • DNS
  • Volumes
  • Persistent volumes
  • Storage classes
  • ConfigMaps
  • Secrets
  • RBAC
  • Network policies
  • Pod security
  • Image security
  • Monitoring
  • Logging
  • Scaling
  • Rolling updates
  • Helm charts

Example 1: Dockerfile for a Python Application

Section titled “Example 1: Dockerfile for a Python Application”
FROM python:3.11-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
EXPOSE 8000
CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]

Key principles: use slim base images, copy requirements before source (better layer caching), run as non-root in production, use multi-stage builds for compiled languages.

Example 2: Kubernetes Deployment with Health Checks

Section titled “Example 2: Kubernetes Deployment with Health Checks”
apiVersion: apps/v1
kind: Deployment
metadata:
name: web-app
spec:
replicas: 3
selector:
matchLabels:
app: web-app
template:
spec:
containers:
- name: app
image: myapp:1.0
ports:
- containerPort: 8000
readinessProbe:
httpGet:
path: /health
port: 8000
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 8000
initialDelaySeconds: 15
periodSeconds: 20
resources:
requests:
memory: "128Mi"
cpu: "250m"
limits:
memory: "256Mi"
cpu: "500m"

Health probes ensure Kubernetes restarts unhealthy pods and only routes traffic to ready ones. Resource requests enable scheduling; limits prevent OOM kills.

  1. Using latest tag in production: Always pin specific versions. latest makes deployments non-reproducible and rollbacks impossible.
  2. Running as root in containers: Use USER directive in Dockerfile. Root containers can escape to the host if a vulnerability is exploited.
  3. Ignoring resource limits: Without limits, a single pod can consume all node resources, starving other workloads. Always set requests and limits.

Docker packages applications with their dependencies into portable containers. Kubernetes orchestrates containers at scale with automated scheduling, scaling, and self-healing. Together they form the foundation of modern cloud-native architecture. Docker handles the build/package stage; Kubernetes handles the deploy/run stage.