- 容器技术基础
- 镜像文件
- Dockerfile
- Namespace
- CGroup
- 网络
- containerd & Runc
-
k8s架构和设计原则
-
k8s API
-
kubectl
-
etcd
-
Api-Server
-
Scheduler-Server
-
Controller-Server
- Deployment, ReplicatSet, Pod, StatefulSet, DamonSet
- Service
- Configmap, Secret,Service Account
- RBAC
- NetworkPolicy
- SecurtiyContext
- kubelet
- CRI & CNI & CSI
- CoreDNS
- Ingress & Service
- kube-proxy & Iptables
- Ipvs
- Calico
- Cilium
-
GRPC
- protobuf基础
- 通信模式
- 拦截器
- metadata
- 超时控制
- 认证
- 安全
-
K8s Api
-
Client-Go
-
Controller-Runtime
-
KubeBuilder
- 日志
- 监控
- Trace
- harbor
- helm
- kustomize
- ArgoCD
- 运维最佳实践
- 排查
-
envoy
-
istio
- iptables
- istio 架构
- 流量劫持原理分析
- 流量管理
- [API Gateway]
- [安全与零信任网络]
- [可观察性]
- 扩展 & EnvoyFilter & Wasmplugin
- [Pilot 源码分析]
- [Ambient 模式原理分析]
- FinOps
- Crane