KBS-535

Kubernetes Administration & Security with CKS Exam Prep

Complete Kubernetes administration and security training with certification preparation.

Course Description

Kubernetes is the de-facto system for container orchestration, e.g. automating the deployment, scaling and management of microservices-based, containerized applications.

This training first introduces participants to the basic concepts and architecture of Kubernetes, its initial install, setup and access control, Kubernetes Pods and Workloads, Scheduling and node management, Accessing the applications, Persistent storage in Kubernetes as well as its Logging, Monitoring and Troubleshooting facilities.

The second part of this training covers Kubernetes' security features and the security hardening of Kubernetes clusters and applications. It introduces concepts, procedures, and best practices to harden Kubernetes based systems and container-based applications against security threats. It deals with the main areas of cloud-native security: Kubernetes cluster setup, Kubernetes cluster hardening, hardening the underlying operating system and networks, minimizing microservices vulnerabilities, obtaining supply chain security as well as monitoring, logging, and runtime security.

This course doesn't only deal with the daily and security administration of Kubernetes based systems but also prepares delegates for the official Certified Kubernetes Security Specialist (CKS) exam of the Cloud Native Computing Foundation (CNCF).

Training Objectives

At the end of the training participants:

  • Understand cloud computing and cloud-native concepts, container orchestration as well as the concepts, object categories and architecture of Kubernetes.
  • Access the Kubernetes cluster and control access to the API with authentication, RBAC roles and role bindings, and admission control.
  • Work with Kubernetes workloads: the Pod and its lifecycle, ReplicationControllers, ReplicaSets and Deployments.
  • Understand the Kubernetes scheduler and manage nodes with pod priorities and preemption, node and pod affinities as well as taints and tolerations.
  • Make applications accessible with Services, Ingress and Network Policies.
  • Provide persistent storage with Volumes, Persistent Volumes, dynamic PVC provisioning, Secrets and ConfigMaps, and use special workloads such as StatefulSets, Jobs, CronJobs and DaemonSets.
  • Log, monitor and troubleshoot Kubernetes clusters and install and upgrade Kubernetes with kubeadm.
  • Manage users, service accounts and authorizations and secure the software supply chain by scanning, validating and minimizing container images.
  • Validate the cluster setup against the CIS benchmark, perform penetration testing and harden the underlying operating system and networks.
  • Configure Kubernetes audit logs and audit policies and monitor the behaviour of applications at runtime with Falco.
  • Be prepared for the official Kubernetes certification exams of the Cloud Native Computing Foundation (CNCF): CKA, CKAD and CKS.

Target Audience

System administrators, developers and DevOps who want to understand and use Kubernetes in enterprise and cloud environments.

Prerequisites

Proficiency with the Linux CLI. A broad understanding of Linux system administration. Basic knowledge of Linux containers, e.g. Docker.

Duration

5 days total (3 days Kubernetes + 2 days Cloud-native security) - 50% theory, 50% hands-on lab exercises