Kubernetes and Docker
flowchart TD
A[Kubernetes Docker] --> B[Key Concepts]
A --> C[Core Principles]
A --> D[Practical Applications]
B --> E[Fundamental definitions]
C --> F[Design patterns]
D --> G[Real-world usage]Introduction to Containers
Section titled “Introduction to Containers”- What are containers?
- Benefits of containers
- Container vs VM
- Docker overview
Docker Fundamentals
Section titled “Docker Fundamentals”- Docker installation
- Docker images
- Docker containers
- Dockerfile
- Docker Compose
Kubernetes Basics
Section titled “Kubernetes Basics”- Kubernetes architecture
- Pods
- Services
- Deployments
- Namespaces
Kubernetes Networking
Section titled “Kubernetes Networking”- Service types
- Ingress
- Network policies
- DNS
Kubernetes Storage
Section titled “Kubernetes Storage”- Volumes
- Persistent volumes
- Storage classes
- ConfigMaps
- Secrets
Kubernetes Security
Section titled “Kubernetes Security”- RBAC
- Network policies
- Pod security
- Image security
Production Deployment
Section titled “Production Deployment”- Monitoring
- Logging
- Scaling
- Rolling updates
- Helm charts
See Also
Section titled “See Also”Worked Examples
Section titled “Worked Examples”Example 1: Dockerfile for a Python Application
Section titled “Example 1: Dockerfile for a Python Application”FROM python:3.11-slimWORKDIR /appCOPY requirements.txt .RUN pip install --no-cache-dir -r requirements.txtCOPY . .EXPOSE 8000CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]Key principles: use slim base images, copy requirements before source (better layer caching), run as non-root in production, use multi-stage builds for compiled languages.
Example 2: Kubernetes Deployment with Health Checks
Section titled “Example 2: Kubernetes Deployment with Health Checks”apiVersion: apps/v1kind: Deploymentmetadata: name: web-appspec: replicas: 3 selector: matchLabels: app: web-app template: spec: containers: - name: app image: myapp:1.0 ports: - containerPort: 8000 readinessProbe: httpGet: path: /health port: 8000 initialDelaySeconds: 5 periodSeconds: 10 livenessProbe: httpGet: path: /health port: 8000 initialDelaySeconds: 15 periodSeconds: 20 resources: requests: memory: "128Mi" cpu: "250m" limits: memory: "256Mi" cpu: "500m"Health probes ensure Kubernetes restarts unhealthy pods and only routes traffic to ready ones. Resource requests enable scheduling; limits prevent OOM kills.
Common Pitfalls
Section titled “Common Pitfalls”- Using
latesttag in production: Always pin specific versions.latestmakes deployments non-reproducible and rollbacks impossible. - Running as root in containers: Use
USERdirective in Dockerfile. Root containers can escape to the host if a vulnerability is exploited. - Ignoring resource limits: Without limits, a single pod can consume all node resources, starving other workloads. Always set requests and limits.
Summary
Section titled “Summary”Docker packages applications with their dependencies into portable containers. Kubernetes orchestrates containers at scale with automated scheduling, scaling, and self-healing. Together they form the foundation of modern cloud-native architecture. Docker handles the build/package stage; Kubernetes handles the deploy/run stage.