Learning Kubernetes
50 chapters
1. Configuration and Secrets Management
[Verse 1]
When your app needs settings that can change and grow
ConfigMaps hold the data that your pods need to know
Environment variables, config files, and more
Kubernetes native storage for the values you adore
No hardcoded secrets buried in your code
ConfigMaps make it clean, follow the right road
[Chorus]
Config separate, secrets locked away
Mount them as volumes or env vars today
ConfigMaps for settings, Secrets for the keys
Keep your data flowing with such graceful ease
Separate your concerns, make your systems bright
Configuration management done exactly right
[Verse 2]
But when you've got passwords, tokens, and certificates too
Secrets are encrypted, base64 won't do
Store them in etcd with protection intact
Volume mounts or env vars, that's how you extract
Never put sensitive data where eyes can see
Secrets keep it hidden, that's security
[Chorus]
Config separate, secrets locked away
Mount them as volumes or env vars today
ConfigMaps for settings, Secrets for the keys
Keep your data flowing with such graceful ease
Separate your concerns, make your systems bright
Configuration management done exactly right
[Bridge]
Volume mounting gives you files inside your container space
Environment injection puts the values in their place
Projected volumes combine them, powerful and neat
Immutable settings when consistency's complete
ConfigMap updates rolling, pods restart with care
Secrets rotation policies keep your data secure and fair
[Verse 3]
Label your resources, organize with style
Version your configs, test them for a while
Namespace isolation keeps your data clean
Best practices matter in the container scene
From development to production, scale with confidence high
Configuration mastery reaching for the sky
[Chorus]
Config separate, secrets locked away
Mount them as volumes or env vars today
ConfigMaps for settings, Secrets for the keys
Keep your data flowing with such graceful ease
Separate your concerns, make your systems bright
Configuration management done exactly right
[Outro]
ConfigMaps and Secrets, mounting strategies true
Full-stack engineering, this knowledge carries you
Keep your data organized, security in mind
Configuration excellence, perfectly designed
2. Health Probes and Observability
[Verse 1]
In the world of Kubernetes where containers run free
Three guardians watch over what we cannot see
Liveness checks if your app's still alive and well
Readiness says when traffic it can tell
Startup gives you time when you're just getting born
Before the other probes sound their warning horn
[Chorus]
Live, Ready, Start - that's the trinity
Live, Ready, Start - keeping systems free
When your pods are failing, these probes will know
Live, Ready, Start - watch your traffic flow
Health checks running, status they report
Live, Ready, Start - Kubernetes support
[Verse 2]
Liveness probe will restart you when you're stuck in a loop
HTTP get or TCP check, it's part of the group
If you fail too many times, the kubelet takes control
Kills your container, starts fresh, that's its role
Every ten seconds it knocks upon your door
"Are you still breathing?" - that's what it's checking for
[Chorus]
Live, Ready, Start - that's the trinity
Live, Ready, Start - keeping systems free
When your pods are failing, these probes will know
Live, Ready, Start - watch your traffic flow
Health checks running, status they report
Live, Ready, Start - Kubernetes support
[Verse 3]
Readiness is different, it won't restart your pod
Just removes you from service when things get odd
Load balancer stops sending requests your way
Until you're healthy and ready for another day
Database connecting or cache warming up
Readiness waits till you're ready to fill the cup
[Bridge]
Startup probe runs first when your container wakes
Gives you time to initialize, whatever time it takes
Once it passes successfully, it steps aside with grace
Lets liveness and readiness take over in its place
Failure threshold, success count, timeout and delay
Configure them wisely for a smooth deployment day
[Chorus]
Live, Ready, Start - that's the trinity
Live, Ready, Start - keeping systems free
When your pods are failing, these probes will know
Live, Ready, Start - watch your traffic flow
Health checks running, status they report
Live, Ready, Start - Kubernetes support
[Outro]
Three probes working together in harmony
Observability built into your infrastructure free
Live, Ready, Start - remember these three
The guardians of your containerized destiny
3. Helm Charts and Templating
[Verse 1]
Start with templates directory, that's where magic lives
Values dot yaml holds the keys, configuration it gives
Chart dot yaml is metadata, defines what you deploy
Helpers dot tpl functions there, for logic you employ
[Chorus]
Helm Charts Template, Values interpolate
Double curly braces, variables translate
Package and release, versions orchestrate
Kubernetes made simple, applications we create
[Verse 2]
Values files cascade down, defaults at the base
Override with dash dash set, environment-specific space
Dot notation paths the way, to nested config trees
Required function validates, ensures no missing keys
[Chorus]
Helm Charts Template, Values interpolate
Double curly braces, variables translate
Package and release, versions orchestrate
Kubernetes made simple, applications we create
[Bridge]
Range loops through arrays clean
If statements guard the scene
Include brings templates in
Named templates share and win
With blocks scope the flow
Pipe functions data flow
[Verse 3]
Dependencies in Chart yaml, sub-charts you define
Hooks run at lifecycle points, pre-install by design
Release object gives you context, namespace name and more
Capabilities tell you features, what your cluster has in store
[Chorus]
Helm Charts Template, Values interpolate
Double curly braces, variables translate
Package and release, versions orchestrate
Kubernetes made simple, applications we create
[Outro]
Template render test it first
Dry run shows what's parsed
Helm the package manager
For Kubernetes deployment star
4. Kubernetes Scheduling Deep Dive
[Verse 1]
When a pod needs a home in the cluster tonight
The scheduler steps up to make everything right
It scans every node for resources free
CPU and memory, what do we need
Filters out the bad, scores what remains
Picks the highest number, that's where pod stays
[Chorus]
Schedule, filter, score and bind
That's how Kubernetes makes up its mind
Node selector says where you can go
Affinity pulls you close you know
Taints push away, tolerations let you stay
Resource limits guide the scheduling way
[Verse 2]
Node selector is simple, just key-value pairs
Match the label exactly, scheduler declares
But affinity gives you so much more control
Required or preferred, soft goals or hard goals
Pod affinity groups your workloads tight
Anti-affinity spreads them left and right
[Chorus]
Schedule, filter, score and bind
That's how Kubernetes makes up its mind
Node selector says where you can go
Affinity pulls you close you know
Taints push away, tolerations let you stay
Resource limits guide the scheduling way
[Bridge]
Taints are like warnings on nodes that say
"Don't place your pods here unless they're okay"
But tolerations are keys that unlock the door
Let pods run on tainted nodes and so much more
No schedule, prefer no schedule, no execute too
Different effects for what you want to do
[Verse 3]
Resource requests tell the scheduler true
How much CPU and memory you'll use
Quality of service classes three
Guaranteed, burstable, best effort you see
Priority classes can jump the line
Higher numbers scheduled first every time
[Chorus]
Schedule, filter, score and bind
That's how Kubernetes makes up its mind
Node selector says where you can go
Affinity pulls you close you know
Taints push away, tolerations let you stay
Resource limits guide the scheduling way
[Outro]
From pending to running, the journey complete
The scheduler's magic makes everything neat
Your pods find their home in the cluster so wide
Thanks to the rules and the scheduling guide
5. Service Mesh Fundamentals
[Verse 1]
In distributed systems where services collide
We need a layer to be our faithful guide
Service mesh sits between each call and response
Handling communication with elegant finesse
When microservices need to talk and share
The mesh provides the infrastructure there
[Chorus]
Discover, Balance, Break the Chain
Service mesh handles all the pain
Proxies routing every call
Sidecar pattern connects them all
Discover, Balance, Break the Chain
Inter-service communication's gain
[Verse 2]
Service discovery finds what you need
No hardcoded addresses to impede
Registry holds the map of every node
Dynamic routing down the network road
Health checks verify what's alive
Keep the service catalog up to thrive
[Chorus]
Discover, Balance, Break the Chain
Service mesh handles all the pain
Proxies routing every call
Sidecar pattern connects them all
Discover, Balance, Break the Chain
Inter-service communication's gain
[Verse 3]
Load balancing spreads the weight around
Round robin, random, weighted and sound
Least connections finds the lighter load
While consistent hashing stays on the road
Traffic shaping keeps the flow in line
Performance metrics help you optimize
[Bridge]
When services fail and systems break down
Circuit breakers stop the cascade around
Open circuit blocks the failing calls
Closed circuit lets the traffic through the halls
Half-open testing if the service heals
Timeout and retry with exponential wheels
[Chorus]
Discover, Balance, Break the Chain
Service mesh handles all the pain
Proxies routing every call
Sidecar pattern connects them all
Discover, Balance, Break the Chain
Inter-service communication's gain
[Verse 4]
Observability shows you what's inside
Distributed tracing follows every ride
Metrics flowing through the telemetry stream
Security policies fulfill the dream
Mutual TLS encrypts every connection
Service mesh provides the full protection
[Outro]
From Istio to Linkerd they pave the way
Envoy proxies processing night and day
Service mesh architecture standing tall
Managing microservices one and all
6. 2 Networking Deep Dive
[Verse 1]
In defense networks where secrets flow
CNI plugins are what you need to know
Calico brings security first in line
With policy enforcement by design
Cilium runs eBPF so fast and clean
Best performance that you've ever seen
While Multus lets you bridge multiple nets
Multi-homing without regrets
[Chorus]
Lock it down with policies tight
Ingress egress done just right
Default deny keeps threats outside
Service mesh for encrypted rides
DNS resolves both near and far
Load balancing where you are
Network deep dive, security pride
Defense infrastructure as your guide
[Verse 2]
Network policies set the rules
Ingress traffic through controlled pools
Egress filtering what goes out
Default deny removes all doubt
Start with nothing, add what's needed
Security boundaries well-heeded
Label selectors make it precise
Network segments rolled like dice
[Chorus]
Lock it down with policies tight
Ingress egress done just right
Default deny keeps threats outside
Service mesh for encrypted rides
DNS resolves both near and far
Load balancing where you are
Network deep dive, security pride
Defense infrastructure as your guide
[Verse 3]
Service mesh decides your fate
Istio's feature-rich and great
Linkerd keeps it simple, light
Both give mTLS done right
Mutual authentication flows
Observability that glows
Traffic management in between
Routing policies crystal clean
[Bridge]
CoreDNS resolves the names
Cluster zones and custom domains
Cross-cluster service discovery
Network paths for all to see
Layer four or layer seven
Load balancing straight from heaven
External facing, internal too
Traffic flows the way you choose
[Outro]
From CNI to service mesh
Network policies keep it fresh
DNS resolution, load balancing art
Defense networking, every part
Deep dive complete, security tight
Network infrastructure done right
7. 1 Architecture and Core Concepts
[Verse 1]
In the control plane where the magic starts
API server is the beating heart
Taking requests from every part
While etcd stores the cluster's art
Scheduler finds the perfect home
For every pod that needs to roam
Controller manager keeps the tone
Making sure nothing's left alone
[Chorus]
Architecture flows from control to node
API, etcd, scheduler's code
Kubelet, proxy, runtime's load
Pods and services on the road
Remember the pattern, remember the way
Control plane leads, workers obey
Container orchestration every day
Kubernetes architecture at play
[Verse 2]
Down on the worker nodes you'll find
Kubelet keeping pods aligned
Kube-proxy routes with traffic kind
Container runtime intertwined
Containerd handles all the rest
Running containers at their best
While kubelet keeps them all in check
Making sure they pass every test
[Chorus]
Architecture flows from control to node
API, etcd, scheduler's code
Kubelet, proxy, runtime's load
Pods and services on the road
Remember the pattern, remember the way
Control plane leads, workers obey
Container orchestration every day
Kubernetes architecture at play
[Verse 3]
Pods are the smallest unit we deploy
ReplicaSets keep copies they employ
Deployments roll updates with such joy
StatefulSets keep order they won't destroy
DaemonSets run on every node
Choosing wisely helps your code
Each workload type has its own mode
Following the Kubernetes road
[Bridge]
Services connect with ClusterIP inside
NodePort opens to the outside
LoadBalancer distributes the ride
Ingress routes with rules as guide
Namespaces divide the space
Resource quotas set the pace
Limit ranges keep things in place
Multi-tenancy finds its grace
[Verse 4]
ConfigMaps hold your settings clear
Secrets keep passwords away from fear
External secrets management's here
For enterprise security we hold dear
Gateway API's the future way
Modern routing starts today
While the old Ingress still holds sway
Both will guide you on your way
[Chorus]
Architecture flows from control to node
API, etcd, scheduler's code
Kubelet, proxy, runtime's load
Pods and services on the road
Remember the pattern, remember the way
Control plane leads, workers obey
Container orchestration every day
Kubernetes architecture at play
[Outro]
From control plane to worker ground
Kubernetes patterns can be found
Master these concepts, safe and sound
Defense infrastructure's battleground
8. 4 Cluster Lifecycle and Operations
[Verse 1]
Starting with a cluster plan in mind
EKS for AWS, Azure's got AKS
GKE on Google Cloud you'll find
RKE2 when air-gapped networks last
Kubeadm builds from scratch with care
Choose your platform, environment aware
[Chorus]
Provision, deploy, monitor, upgrade
GitOps keeps your state in line
Terraform builds, Helm manages the stage
ArgoCD makes your clusters shine
Control plane up, then worker nodes
Infrastructure as Code flows
[Verse 2]
RKE2 stands for government grade
Air-gapped networks, DoD compliant
Security hardened, not afraid
Kubernetes distro, self-reliant
OpenTofu scripts the infrastructure
Helm charts wrap your workload mixture
[Chorus]
Provision, deploy, monitor, upgrade
GitOps keeps your state in line
Terraform builds, Helm manages the stage
ArgoCD makes your clusters shine
Control plane up, then worker nodes
Infrastructure as Code flows
[Verse 3]
GitOps brings declarative state
ArgoCD pulls from your repo
Flux detects when configs deviate
Reconciliation keeps the flow
Drift detection catches the changes
Declarative truth rearranges
[Bridge]
Prometheus scrapes the metrics true
Grafana paints the dashboard view
Alerting pipelines notify you
When something breaks or needs review
Version skew policies define
How far apart your versions align
[Verse 4]
Upgrade strategies take their turn
Control plane first, then worker fleet
Rolling updates help systems learn
Blue-green deployments can't be beat
Monitor health through every phase
Infrastructure as Code always pays
[Chorus]
Provision, deploy, monitor, upgrade
GitOps keeps your state in line
Terraform builds, Helm manages the stage
ArgoCD makes your clusters shine
Control plane up, then worker nodes
Infrastructure as Code flows
[Outro]
From provisioning to operation
Kubernetes lifecycle complete
Defense infrastructure automation
Makes your deployment process neat
9. 3 Storage and State
[Verse 1]
When containers need their data to survive
Past the pod's ephemeral lifecycle
Persistent Volumes keep your storage alive
Claims connect them like a bridge so logical
Storage Classes define the quality of service
EBS for AWS, Azure Disk for Microsoft's purpose
[Chorus]
PV, PVC, Storage Class - the trinity of state
CSI drivers bridge the gap between cloud and on-premise fate
Stateful Sets deploy in order, networks stay the same
Velero backs it up, encryption keeps data safe from shame
[Verse 2]
CSI drivers are the interface that we need
Container Storage plugs into any backend
EFS for files, Ceph clusters that feed
Portworx and Longhorn for on-prem extend
Driver talks to Kubernetes API calls
Storage abstraction breaks down all the walls
[Chorus]
PV, PVC, Storage Class - the trinity of state
CSI drivers bridge the gap between cloud and on-premise fate
Stateful Sets deploy in order, networks stay the same
Velero backs it up, encryption keeps data safe from shame
[Verse 3]
StatefulSets bring order to deployment time
Each pod gets a number, network ID that's stable
Databases and clusters work in paradigm
Ordered startup, shutdown - predictable and able
Pod zero starts first, then one, then two
Headless service gives each pod a hostname true
[Bridge]
When disaster strikes, you need a backup plan
Velero snapshots volumes across the span
Etcd holds the state of everything you know
Application backups let your data flow
Provider-managed keys or app-level control
Encryption at rest protects your data's soul
[Chorus]
PV, PVC, Storage Class - the trinity of state
CSI drivers bridge the gap between cloud and on-premise fate
Stateful Sets deploy in order, networks stay the same
Velero backs it up, encryption keeps data safe from shame
[Outro]
Storage and state management, the foundation of your stack
Persistent data flowing, never looking back
From volumes to encryption, from drivers to restore
Kubernetes storage mastery - this is what we're fighting for
10. List pods (current namespace)
[Verse 1]
When you need to see what's running in your space
Kubectl get pods will show you every trace
Simple list appears with names and status clear
Running, pending, failed - the state will all be here
[Chorus]
Get pods, get pods, see what's alive
Dash o wide for details that help you thrive
Get pods, get pods, yaml shows it all
Show labels flag reveals what you might call
[Verse 2]
Add dash o wide and watch the view expand
Node locations, IP addresses in your hand
Internal addresses and the age of every pod
External IPs too when you need to debug hard
[Chorus]
Get pods, get pods, see what's alive
Dash o wide for details that help you thrive
Get pods, get pods, yaml shows it all
Show labels flag reveals what you might call
[Verse 3]
When yaml format gives you everything inside
Full configuration with nothing left to hide
Specifications, status, metadata complete
Every detail exposed from your head to your feet
[Chorus]
Get pods, get pods, see what's alive
Dash o wide for details that help you thrive
Get pods, get pods, yaml shows it all
Show labels flag reveals what you might call
[Bridge]
Show labels brings the tags into the light
App versions, environments, all in sight
Current namespace is where these commands will look
Your kubectl pods become an open book
[Final Chorus]
Get pods, get pods, four ways to see
Basic, wide, yaml, labels - your kubectl key
Get pods, get pods, master them all
List your audiobook pods standing tall
[Outro]
From simple names to full configuration
Kubectl get pods serves every situation
11. 1 Kubernetes Refresher
[Verse 1]
In the cluster where containers run free
Pods are the smallest units you'll see
One or more containers sharing the space
Network and storage in the same place
Deployments manage replicas with care
Rolling updates happen everywhere
But when you need persistence that won't fade
StatefulSets keep your data trade
[Chorus]
Kube-er-netes, building blocks so strong
Pods and Services singing along
Storage Classes, ConfigMaps too
RBAC keeps it safe for me and you
Remember the pattern, CRDs define
Custom resources in perfect line
[Verse 2]
Services expose your pods to connect
ClusterIP, NodePort, what you'd expect
Load balancing traffic with a stable name
Even when pod IPs aren't the same
Persistent Volumes claim the space you need
Storage Classes provision at full speed
Dynamic provisioning takes the lead
Your data survives when pods concede
[Chorus]
Kube-er-netes, building blocks so strong
Pods and Services singing along
Storage Classes, ConfigMaps too
RBAC keeps it safe for me and you
Remember the pattern, CRDs define
Custom resources in perfect line
[Bridge]
ConfigMaps hold your config data clean
Secrets encrypt what shouldn't be seen
ServiceAccounts authenticate with grace
RBAC controls who can access what space
NetworkPolicies filter the flow
Keeping your cluster secure as you go
[Verse 3]
Helm charts package apps complete
Templates and values make deploys neat
Kustomize patches without the mess
Declarative changes bring success
Operators extend the API way
Custom Resource Definitions hold sway
They watch and reconcile night and day
Making complex workloads child's play
[Chorus]
Kube-er-netes, building blocks so strong
Pods and Services singing along
Storage Classes, ConfigMaps too
RBAC keeps it safe for me and you
Remember the pattern, CRDs define
Custom resources in perfect line
[Outro]
From Pods to Operators, now you know
The foundation where Kafka will grow
Strimzi builds upon this solid ground
Kubernetes mastery, safe and sound
12. Get pod logs
[Verse 1]
When your pod is running but something's going wrong
You need to peek inside to see what's going on
Kubectl logs with your pod name in tow
Will show you all the messages your container needs you to know
[Chorus]
Get pod logs, see what's there
Kubectl logs shows you what's happening where
Dash f to follow, dash dash tail for the end
Previous crashed instance, logs are your friend
Get pod logs, make it clear
Debug your pods when errors appear
[Verse 2]
Multi-container pods need a little more care
Add dash c with container name to get exactly where
The messages are coming from, which service is the source
When multiple containers run, you'll need to stay on course
[Chorus]
Get pod logs, see what's there
Kubectl logs shows you what's happening where
Dash f to follow, dash dash tail for the end
Previous crashed instance, logs are your friend
Get pod logs, make it clear
Debug your pods when errors appear
[Bridge]
Dash dash previous when your pod has crashed
Shows the logs from before when everything was smashed
Dash dash tail one hundred gives you just the last
Skip the older messages, get current info fast
[Verse 3]
Stream the logs in real time with dash f flag
Watch them scroll before your eyes, no need to lag
Following live output as your application runs
Debugging gets much easier when live logging's begun
[Chorus]
Get pod logs, see what's there
Kubectl logs shows you what's happening where
Dash f to follow, dash dash tail for the end
Previous crashed instance, logs are your friend
Get pod logs, make it clear
Debug your pods when errors appear
[Outro]
Pod name first, then your flags
Container name when needed, no more debug snags
Kubectl logs will guide your way
To healthier pods every day
13. Execute into a running pod
[Verse 1]
When your pod is running strong and free
But you need to peek inside and see
There's a command that opens up the door
kubectl exec will give you so much more
Type dash i and dash t together tight
Interactive terminal shining bright
Then the pod name that you want to reach
Shell access is within your teach
[Chorus]
Execute into the running pod
Dash i dash t, remember the code
Kubectl exec will take you there
Inside the container, commands to share
Execute into the running pod
Double dash bin slash sh, break the facade
When you need to troubleshoot and debug
Step inside with the terminal hug
[Verse 2]
Sometimes you've got multiple containers inside
Need to specify which one to ride
Add dash c and then the container name
Before the double dash, play the game
Bin slash bash if you want more power
Advanced shell for that coding hour
But bin slash sh works most of the time
Simple shell that works just fine
[Chorus]
Execute into the running pod
Dash i dash t, remember the code
Kubectl exec will take you there
Inside the container, commands to share
Execute into the running pod
Double dash bin slash sh, break the facade
When you need to troubleshoot and debug
Step inside with the terminal hug
[Bridge]
Interactive mode with dash i flag
Terminal session, never lag
Dash t gives you that TTY
Pretty output for your eye
When things go wrong and logs aren't clear
Jump inside, the truth appears
File systems, processes running wild
Debugging made simple, error reconciled
[Chorus]
Execute into the running pod
Dash i dash t, remember the code
Kubectl exec will take you there
Inside the container, commands to share
Execute into the running pod
Double dash separates, don't be awed
When you need to troubleshoot and debug
Step inside with the terminal hug
[Outro]
From the outside looking in
To the inside where you win
Execute and investigate
Kubectl exec is truly great
14. Describe a pod (events, conditions, container status)
[Verse 1]
When your pod is acting strange and you don't know why
There's a command that shows the truth, no need to cry
Kubectl describe pod, just type the name
It tells the story of what's happening in the game
[Chorus]
Describe describe, show me what's inside
Events and conditions, container's ride
Status and phases, all laid out clear
Kubectl describe pod makes problems disappear
[Verse 2]
First it shows the metadata, name and namespace too
Labels and annotations, all the tags on you
Then the spec section tells us what should be
The image and the ports and resources we need
[Chorus]
Describe describe, show me what's inside
Events and conditions, container's ride
Status and phases, all laid out clear
Kubectl describe pod makes problems disappear
[Verse 3]
Container status tells us if it's running fine
Ready, waiting, terminated - check the line
Restart count and reason why it failed before
Image pull status tells us so much more
[Bridge]
Events at the bottom, chronological flow
Shows you the journey, how your pod did grow
Scheduled and pulling, started and crashed
All the important moments, nothing gets trashed
[Chorus]
Describe describe, show me what's inside
Events and conditions, container's ride
Status and phases, all laid out clear
Kubectl describe pod makes problems disappear
[Outro]
So when debugging gets you down
Describe your pod and turn it around
The answer's there in black and white
Kubectl describe makes everything right
15. Port-forward to a pod (local debugging)
[Verse 1]
When your pod is running but you can't connect
There's a bridge you need to build, let me direct
Your local machine to the cluster inside
Port-forward is the tunnel where data can ride
[Chorus]
kubectl port-forward pod, that's the way
Eight oh eight oh colon eight oh, every day
Local port to pod port, make the connection
Debugging made easy with this direction
[Verse 2]
First you need the pod name, get it just right
Use kubectl get pods to bring it to light
Copy paste that name, don't make a mistake
One typo will cause the whole tunnel to break
[Chorus]
kubectl port-forward pod, that's the way
Eight oh eight oh colon eight oh, every day
Local port to pod port, make the connection
Debugging made easy with this direction
[Verse 3]
The format is simple, just follow the rule
Pod name after pod slash, it's the perfect tool
Then your local port first, colon in between
Target pod port last, cleanest you've seen
[Bridge]
Eight oh eight oh on your machine
Maps to port eighty where the app is seen
Traffic flows through like a secret door
From localhost straight to the cluster core
[Chorus]
kubectl port-forward pod, that's the way
Eight oh eight oh colon eight oh, every day
Local port to pod port, make the connection
Debugging made easy with this direction
[Verse 4]
Now open your browser, type localhost
Eight oh eight oh takes you coast to coast
From your development box to the pod inside
The Kubernetes bridge is your debugging guide
[Outro]
Port-forward pod name, ports aligned
kubectl makes the connection, peace of mind
Eight oh eight oh colon eight oh, remember the flow
Local debugging, now you know
16. shorthand:
[Verse 1]
Don't create pods directly, that's not the way
Use controllers instead to make them stay
Atomic units of deployment, smallest thing you'll find
But higher-level tools will ease your mind
[Chorus]
Kubectl get pods dash A
Shows you everything today
Never use the default space
Namespaces keep things in their place
Team dash environment dash app
That's the naming convention map
[Verse 2]
Pods are great for debugging when things go wrong
But for deployment they won't last too long
Understand the basics but don't deploy alone
Let controllers manage what you own
[Chorus]
Kubectl get pods dash A
Shows you everything today
Never use the default space
Namespaces keep things in their place
Team dash environment dash app
That's the naming convention map
[Bridge]
Resource quotas set the limit
Limit ranges keep you in it
Best practices from the start
Will set your cluster apart
[Verse 3]
Establish naming early on
Before your workloads have grown
Every namespace needs its rules
These are your essential tools
[Chorus]
Kubectl get pods dash A
Shows you everything today
Never use the default space
Namespaces keep things in their place
Team dash environment dash app
That's the naming convention map
[Outro]
Pods are atomic, controllers deploy
Namespaces organized, that's how we enjoy
Kubernetes management done the proper way
17. Create a deployment
[Verse 1]
When you need to scale your application high
Multiple pods running in the sky
Kubernetes helps you manage the load
With deployments on this container road
Take your image from the registry shelf
Docker Hub or built it yourself
Tag it right so you know the version
No mistakes in your code conversion
[Chorus]
kubectl create deployment name
Image tag and replicas the same
Three copies running strong and free
That's how we scale efficiently
Create deploy, name your app
Image colon tag no gap
Replicas three is what we need
Kubernetes plants the scaling seed
[Verse 2]
First you choose a deployment name
Something clear to stake your claim
Then the image that you've prepared
With the tag version that you've declared
The replicas flag sets the count
Three instances is the right amount
High availability is the goal
Keep your service on a roll
[Chorus]
kubectl create deployment name
Image tag and replicas the same
Three copies running strong and free
That's how we scale efficiently
Create deploy, name your app
Image colon tag no gap
Replicas three is what we need
Kubernetes plants the scaling seed
[Bridge]
When one pod fails another stands
Kubernetes has it in its hands
Load balancing across the three
Your users won't feel the debris
The scheduler finds the perfect node
To run your containerized code
Health checks keep them running right
Monitoring day and night
[Chorus]
kubectl create deployment name
Image tag and replicas the same
Three copies running strong and free
That's how we scale efficiently
Create deploy, name your app
Image colon tag no gap
Replicas three is what we need
Kubernetes plants the scaling seed
[Outro]
Now you know the deployment way
Scale your apps throughout the day
Three replicas standing tall
Kubernetes manages them all
18. Update image (triggers rolling update)
[Verse 1]
Your pods are running yesterday's code
The new version's ready to deploy
But you don't want downtime on the road
Rolling updates are what you'll employ
kubectl set image is the way
Point to your deployment by name
Container equals image tag today
And watch the magic rearrange
[Chorus]
Set image deployment, container name
Image colon tag, it's all the same
Rolling smooth, no downtime pain
New pods up, old ones fade away
kubectl set image saves the day
Rolling updates all the way
[Verse 2]
First you specify deployment slash name
The resource that you want to change
Then the container in the game
Followed by the image you'll exchange
The old tag's "v1" but now it's "v2"
Kubernetes does the heavy lift
Creates new pods with something new
While traffic makes a seamless shift
[Chorus]
Set image deployment, container name
Image colon tag, it's all the same
Rolling smooth, no downtime pain
New pods up, old ones fade away
kubectl set image saves the day
Rolling updates all the way
[Bridge]
Watch the rollout status flow
Old replicas decreasing slow
New ones coming up to show
Zero downtime as you go
Deployment slash your-app-name
Container equals nginx-web
Image colon v-two-dot-ten
Rolling forward, never dread
[Chorus]
Set image deployment, container name
Image colon tag, it's all the same
Rolling smooth, no downtime pain
New pods up, old ones fade away
kubectl set image saves the day
Rolling updates all the way
[Outro]
When your code needs to update
Rolling deployments seal your fate
kubectl set image, don't be late
Your users never have to wait
19. View rollout status
[Verse 1]
You've deployed your audiobook app to the cluster
But you're wondering if it's running right
Kubernetes is working behind the scenes
Rolling out your pods into the light
When you need to know the current state
There's a command that shows you straight
[Chorus]
Kubectl rollout status, check your deployment's way
See if pods are ready or still updating today
Deployment slash the name, that's the pattern you need
Rollout status tells you when your changes succeed
Watch it roll, watch it go, see your progress flow
Kubectl rollout status, now you're in the know
[Verse 2]
Your audiobook containers need time to start
Each replica has to come online
The rolling update happens one by one
Making sure your service works just fine
Old pods fade as new ones take their place
Status shows you the deployment race
[Chorus]
Kubectl rollout status, check your deployment's way
See if pods are ready or still updating today
Deployment slash the name, that's the pattern you need
Rollout status tells you when your changes succeed
Watch it roll, watch it go, see your progress flow
Kubectl rollout status, now you're in the know
[Bridge]
Successfully rolled out means you're done
All replicas are running as one
If it's progressing, give it time
Your audiobook deployment will shine
From pending state to running free
That's the status you want to see
[Chorus]
Kubectl rollout status, check your deployment's way
See if pods are ready or still updating today
Deployment slash the name, that's the pattern you need
Rollout status tells you when your changes succeed
Watch it roll, watch it go, see your progress flow
Kubectl rollout status, now you're in the know
[Outro]
Monitor your rollouts, keep your apps in sight
Kubectl rollout status makes deployment bright
20. Autoscale (HPA)
[Verse 1]
When your pods are running slow and traffic starts to grow
Your deployment needs some help to handle all the flow
CPU is climbing high, users start to cry
Time to scale it up and down, let Kubernetes try
[Chorus]
H-P-A, scaling pods all day
Min of two, max of ten, keeping load at bay
Seventy percent CPU, that's the magic line
Auto-scale will save the day, working every time
Kubectl auto-scale, never gonna fail
Horizontal pods will rise when metrics tell the tale
[Verse 2]
Start with your deployment name, specify the range
Minimum replicas two, maximum can change
Up to ten pods running when the pressure's really on
Back to two when traffic's light, resources never gone
[Chorus]
H-P-A, scaling pods all day
Min of two, max of ten, keeping load at bay
Seventy percent CPU, that's the magic line
Auto-scale will save the day, working every time
Kubectl auto-scale, never gonna fail
Horizontal pods will rise when metrics tell the tale
[Bridge]
CPU percent seventy is the threshold we define
Above this line we scale up high, below we scale down fine
Deployment slash your app name, then the flags you'll need
Min and max and CPU percent, that's the scaling creed
[Verse 3]
No more manual scaling wars, no more sleepless nights
HPA will watch your load and adjust to traffic spikes
From audiobooks to any app, the pattern stays the same
Horizontal Pod Autoscaler is the scaling game
[Chorus]
H-P-A, scaling pods all day
Min of two, max of ten, keeping load at bay
Seventy percent CPU, that's the magic line
Auto-scale will save the day, working every time
Kubectl auto-scale, never gonna fail
Horizontal pods will rise when metrics tell the tale
[Outro]
Set it once and let it run
Auto-scaling's never done
Min two, max ten, seventy CPU
HPA will see you through
21. Copy files to/from a pod
[Verse 1]
When your pod is running in the cluster space
And you need to move some files to another place
Kubectl copy is the command you'll use
To transfer data without any blues
From your local machine to the container's home
Or pull files back when you need to roam
[Chorus]
Copy in, copy out, kubectl see pee
Pod name colon path is all you need
Local file to remote, or remote to your drive
Moving audiobooks to keep your pod alive
Copy in, copy out, the transfer is clean
Best file management that you've ever seen
[Verse 2]
First the source location, then the destination
Dot slash for your local file creation
Pod name followed by a colon mark
Then the path inside, hitting the target mark
Your imported audiobook needs to flow
From local storage to where containers go
[Chorus]
Copy in, copy out, kubectl see pee
Pod name colon path is all you need
Local file to remote, or remote to your drive
Moving audiobooks to keep your pod alive
Copy in, copy out, the transfer is clean
Best file management that you've ever seen
[Bridge]
Set your resource limits, don't forget the probes
Readiness and liveness as your container loads
Run as non-root user for security's sake
Startup probe for apps that time they take
Deployments manage pods through replica sets
Declarative updates, the best practice you get
[Verse 3]
When you need to debug or grab a log file
Copy from the pod, it's worth your while
Dot slash local file saves it to your machine
Now you can examine what the errors mean
Bidirectional transfer, both ways it flows
Kubectl copy, that's how the data goes
[Chorus]
Copy in, copy out, kubectl see pee
Pod name colon path is all you need
Local file to remote, or remote to your drive
Moving audiobooks to keep your pod alive
Copy in, copy out, the transfer is clean
Best file management that you've ever seen
[Outro]
From workstation to pod and back again
File transfer magic at your command
Kubectl copy makes it simple and true
Container file management for me and you
22. Pause/resume a rollout (batch multiple changes)
[Verse 1]
When your deployment's rolling out across the cluster wide
Sometimes you need to stop and check before you let it ride
Maybe there's an issue or you want to batch some more
Pause command will freeze it right there at your current score
[Chorus]
Pause it, resume it, control your deploy flow
Kubectl rollout pause when you need to take it slow
Resume it, complete it, when you're ready to go
Batch your changes together, let your updates flow
[Verse 2]
Type kubectl rollout pause deployment slash your app name
The rollout stops in place, no pods will change their game
Now you can make more edits, update configs as you need
Stack up all your changes before you let them feed
[Chorus]
Pause it, resume it, control your deploy flow
Kubectl rollout pause when you need to take it slow
Resume it, complete it, when you're ready to go
Batch your changes together, let your updates flow
[Bridge]
Multiple changes waiting in the queue
Instead of rolling one by one, here's what smart admins do
Pause the first deployment, make your other changes too
Then resume rolls everything in one clean breakthrough
[Verse 3]
When you're ready to continue, type resume instead of pause
Kubectl rollout resume deployment, honor all the laws
All your batched up changes will deploy in one smooth wave
No more rolling back and forth, time and resources saved
[Chorus]
Pause it, resume it, control your deploy flow
Kubectl rollout pause when you need to take it slow
Resume it, complete it, when you're ready to go
Batch your changes together, let your updates flow
[Outro]
Pause deployment slash name
Resume deployment slash name
Control your rollout game
Kubernetes deployment mastery claimed
23. Restart all pods in a deployment (rolling restart)
[Verse 1]
When your pods are feeling tired and old
And updates just won't take hold
There's a magic command that works so well
Rolling restart, I'll tell you how to tell
Type kubectl rollout restart
Then deployment slash the name
Every pod will cycle through
Zero downtime in this game
[Chorus]
Rolling restart, rolling restart
Keep your service running smart
One by one they'll cycle through
Rolling restart will see you through
Max surge up and max unavailable
Keep your limits reasonable
Rolling restart, that's the way
To refresh without delay
[Verse 2]
Don't forget the record flag
For history you can track and tag
Revision history limit set
Ten old sets you'll keep, don't fret
Rolling update strategy
Max surge and max unavailable
Control the flow of pods that go
Keep your service always reachable
[Chorus]
Rolling restart, rolling restart
Keep your service running smart
One by one they'll cycle through
Rolling restart will see you through
Max surge up and max unavailable
Keep your limits reasonable
Rolling restart, that's the way
To refresh without delay
[Bridge]
StatefulSets and DaemonSets
Jobs and pods, no regrets
Rolling restarts work for all
Kubernetes will heed your call
Annotate for better tracking
Never leave your history lacking
Rollout restart is the command
That keeps your cluster running grand
[Chorus]
Rolling restart, rolling restart
Keep your service running smart
One by one they'll cycle through
Rolling restart will see you through
Max surge up and max unavailable
Keep your limits reasonable
Rolling restart, that's the way
To refresh without delay
[Outro]
Kubectl rollout restart deployment
That's your faithful friend
Zero downtime, pods refreshed
On this you can depend
24. StatefulSets (databases, stateful apps — ordered, stable identity)
[Verse 1]
When your apps need steady ground
StatefulSets keep data sound
Not like pods that come and go
These maintain what they should know
Ordered startup, shutdown clean
Stable names you've ever seen
Database clusters need this way
Persistent storage here to stay
[Chorus]
StatefulSet, ordered and stable
Every pod gets its own label
Zero one two three four five
Identity that stays alive
Get describe and scale with care
StatefulSets handle data there
Ordered stable identity
That's the StatefulSet guarantee
[Verse 2]
kubectl get statefulsets shows
All the ordered apps that grow
Each one numbered, never random
MySQL or Mongo standing
Pod zero starts before pod one
Sequential startup till it's done
Shutdown happens in reverse
Keeping order, nothing worse
[Chorus]
StatefulSet, ordered and stable
Every pod gets its own label
Zero one two three four five
Identity that stays alive
Get describe and scale with care
StatefulSets handle data there
Ordered stable identity
That's the StatefulSet guarantee
[Bridge]
Scale them up with replicas flag
Five instead of three you had
kubectl scale statefulset name
Each new pod joins the game
Persistent volumes stick around
Even when pods hit the ground
Stateful apps need this design
Data safety by design
[Final Chorus]
StatefulSet, ordered and stable
Every pod gets its own label
Zero one two three four five
Identity that stays alive
Describe shows the current state
Scaling up you cannot wait
Ordered stable identity
StatefulSets for you and me
[Outro]
When you need your data stored
StatefulSets are your reward
Ordered stable here to stay
The Kubernetes stateful way
25. CronJobs (scheduled jobs)
[Verse 1]
When you need a task to run on schedule time
Kubernetes has the tool to make your workload shine
CronJobs are the answer when you want control
Over when your containers play their scripted role
[Chorus]
kubectl create cronjob with a name you choose
Image and a schedule that you cannot lose
Zero star-slash-six star star star means every six hours
kubectl get cronjobs shows you all their powers
[Verse 2]
Schedule syntax follows the old cron way
Five fields tell the system when to start the day
Minutes hours day-of-month and month and weekday too
Star means every value, numbers make it true
[Chorus]
kubectl create cronjob with a name you choose
Image and a schedule that you cannot lose
Zero star-slash-six star star star means every six hours
kubectl get cronjobs shows you all their powers
[Bridge]
StatefulSets need stable names and storage that persists
DaemonSets run everywhere with toleration twists
Set your deadline seconds so your jobs don't run too long
Backoff limit saves you when something goes wrong
[Verse 3]
Best practices matter when you're setting up your flow
Active deadline seconds keeps your runtime under control
Backoff limit stops the chaos when your task goes wrong
Scheduled automation keeps your cluster running strong
[Chorus]
kubectl create cronjob with a name you choose
Image and a schedule that you cannot lose
Zero star-slash-six star star star means every six hours
kubectl get cronjobs shows you all their powers
[Outro]
From batch jobs to scheduled runs your cluster's got the beat
CronJobs make automation simple and complete
26. Jobs (run-to-completion tasks)
[Verse 1]
When you need a task to run just once and then be done
Kubernetes has jobs that get the work complete
Unlike pods that keep on running till their time has come
Jobs will finish up and mark success so neat
Create a job with kubectl, give it name and image too
Add a dash dash for the command you want to run
The container starts up working on the task for you
When it's finished, job is marked as done
[Chorus]
Jobs run to completion, that's their special way
Create, get, and logs - remember these three
Kubectl create job with image every day
Get jobs shows the status, logs show what you see
Run to completion, then they're done hooray
Jobs make sure your one-time tasks run perfectly
[Verse 2]
Once you've got your job created, how do you check its state?
Kubectl get jobs will show you what's going on
See if it's still running or if it had to wait
Completed column tells you when the work is done
But what if something goes wrong and you need to see inside?
Kubectl logs job slash name will show the way
All the output from your container, nothing left to hide
Debug problems from your job throughout the day
[Chorus]
Jobs run to completion, that's their special way
Create, get, and logs - remember these three
Kubectl create job with image every day
Get jobs shows the status, logs show what you see
Run to completion, then they're done hooray
Jobs make sure your one-time tasks run perfectly
[Bridge]
Different from deployments that keep pods alive
Jobs are meant for one-time tasks that finish and survive
Database migrations, batch processing too
Any task that runs once, jobs are perfect for you
[Chorus]
Jobs run to completion, that's their special way
Create, get, and logs - remember these three
Kubectl create job with image every day
Get jobs shows the status, logs show what you see
Run to completion, then they're done hooray
Jobs make sure your one-time tasks run perfectly
[Outro]
So when you need a task to run and finish clean
Jobs in Kubernetes are the way to go
Create, get, and logs - the best commands you've seen
For one-time tasks that complete and show
27. View rollout history
[Verse 1]
When your deployment's running wild
And changes aren't going as planned
You need to see what happened when
Each rollout took command
There's a simple way to trace
Every version that's been deployed
Just use kubectl with the right grace
And your history won't be destroyed
[Chorus]
Rollout history, rollout history
Shows you every change that's been made
Kubectl rollout history deployment name
That's the command that won't fade
From revision one to the latest run
You can see them all in line
Rollout history, rollout history
Makes debugging shine
[Verse 2]
Type kubectl rollout history first
Then deployment slash your name
Watch the revisions appear in order
Like a timeline of your game
Each number tells a story
Of when changes were applied
From the first deployment glory
To the current running pride
[Chorus]
Rollout history, rollout history
Shows you every change that's been made
Kubectl rollout history deployment name
That's the command that won't fade
From revision one to the latest run
You can see them all in line
Rollout history, rollout history
Makes debugging shine
[Bridge]
But wait there's more to see
When you need specific details
Add revision equals two
And watch as knowledge never fails
The dash dash revision flag
Will show you what you need
Deep dive into any change
At debugging speed
[Verse 3]
Sometimes you need the full story
Of one particular deploy
Add dash dash revision number
And details you'll enjoy
See exactly what was changed
In that specific run
Compare it to the others
Till your debugging's done
[Chorus]
Rollout history, rollout history
Shows you every change that's been made
Kubectl rollout history deployment name
That's the command that won't fade
From revision one to the latest run
You can see them all in line
Rollout history, rollout history
Makes debugging shine
[Outro]
So when your pods aren't working right
And you need to trace the past
Rollout history is your friend
It'll help you find answers fast
28. Expose a deployment as a service
[Verse 1]
Your deployment's running fine, containers are alive
But they're hidden from the world, trapped inside their hive
Time to open up the door, let the traffic flow
With kubectl expose, here's what you need to know
[Chorus]
Expose deployment, make it shine
Port eighty to eight zero eight zero, that's the line
ClusterIP keeps it internal, LoadBalancer goes wide
Target port and service port, connected side by side
[Verse 2]
First decide your service type, where will traffic go
ClusterIP for inner talk, keeps it nice and closed
But when you need the outside world to reach your app today
LoadBalancer is the key to open up the way
[Chorus]
Expose deployment, make it shine
Port eighty to eight zero eight zero, that's the line
ClusterIP keeps it internal, LoadBalancer goes wide
Target port and service port, connected side by side
[Bridge]
kubectl is your magic wand
expose deployment takes command
name your service, set the ports
traffic flows where it reports
Target port is where pods listen
Service port is what clients visit
Type decides the traffic route
Inside cluster or all about
[Verse 3]
When you run the expose command, magic starts to flow
Service wraps around your pods, makes them ready to go
Port mapping bridges the gap between the world and your code
Now your audiobook service is ready for the load
[Final Chorus]
Expose deployment, make it shine
Port eighty to eight zero eight zero, that's the line
ClusterIP keeps it internal, LoadBalancer goes wide
Target port and service port, connected side by side
[Outro]
From deployment to service
Your app is now alive
kubectl expose made it work
Your containers now thrive
29. Run a temporary debug pod
[Verse 1]
When your cluster's acting strange and you need to peek inside
There's a pod that comes to help you, like a debugger by your side
Kubectl run debug with an image that's called busybox
Interactive terminal, temporary as the clock ticks
[Chorus]
Run it temp, run it clean, debug pod upon the scene
Interactive flag and remove when done, restart never is the theme
Shell access to your cluster, troubleshoot what you can't see
Temporary debug pod, sets your applications free
[Verse 2]
Sometimes you need to test a curl, reach out across the net
Kubectl run curl-test, with the curl image all set
Interactive and remove it, restart never once again
Pass the URL you're testing, watch the network traffic begin
[Chorus]
Run it temp, run it clean, debug pod upon the scene
Interactive flag and remove when done, restart never is the theme
Shell access to your cluster, troubleshoot what you can't see
Temporary debug pod, sets your applications free
[Bridge]
No persistent storage needed, just a moment in the light
Check your services and endpoints, make sure everything's all right
When you exit from the session, pod will vanish from the node
Kubectl run with dash dash rm, temporary debug mode
[Chorus]
Run it temp, run it clean, debug pod upon the scene
Interactive flag and remove when done, restart never is the theme
Shell access to your cluster, troubleshoot what you can't see
Temporary debug pod, sets your applications free
[Outro]
Debug and curl-test waiting, whenever you're in need
Temporary pods for testing, kubernetes guaranteed
30. Create a headless service (for StatefulSets)
[Verse 1]
When your pods need steady names and storage that will stay
StatefulSets are calling but there's something in the way
Regular services won't work, they balance all around
But your database replicas need identity that's sound
[Chorus]
Headless service, no cluster IP
Point to pods individually
ClusterIP set to None you see
Headless service sets pods free
DNS names that never change
StatefulSet's perfect range
[Verse 2]
Create your YAML file, kind Service at the top
Set the clusterIP to None, let the load balancing stop
Match your StatefulSet selector, ports defined with care
Now each pod gets its own DNS, stable everywhere
[Chorus]
Headless service, no cluster IP
Point to pods individually
ClusterIP set to None you see
Headless service sets pods free
DNS names that never change
StatefulSet's perfect range
[Bridge]
Pod zero dot service dot namespace dot cluster dot local
Pod one follows the pattern, addresses never fall
Direct connections possible, no proxy in between
Persistent volumes mounting, the cleanest setup seen
[Verse 3]
Apply your configuration, watch the magic start
Each pod gets an endpoint, playing its own part
Database clustering working, leader election smooth
Headless service architecture, watch your apps improve
[Final Chorus]
Headless service, no cluster IP
Point to pods individually
ClusterIP set to None you see
Headless service sets pods free
DNS names that never change
StatefulSet's perfect range
Perfect for your StatefulSet range
[Outro]
When you need identity
Choose headless, you'll be free
31. Describe a service (endpoints, selector)
[Verse 1]
When you need to see what's running in your cluster space
There's a command that shows you every service face
Type kubectl describe and add svc right after
Then the service name you're chasing after
[Chorus]
Describe the service, see what it connects
Endpoints showing where the traffic directs
Selector matching pods that qualify
Port mappings tell you how the data flies
K-U-B-E-C-T-L describe
Shows you the service blueprint inside
[Verse 2]
Endpoints are the addresses where requests will go
Each pod IP that matches what you need to know
When selectors find the pods with matching tags
The service routes the traffic without any lags
[Chorus]
Describe the service, see what it connects
Endpoints showing where the traffic directs
Selector matching pods that qualify
Port mappings tell you how the data flies
K-U-B-E-C-T-L describe
Shows you the service blueprint inside
[Bridge]
Target port is where your app receives
Service port is what the client believes
Session affinity keeps connections true
Load balancing spreads the work for you
[Verse 3]
Name and namespace tell you where it lives
Type and cluster IP show what it gives
Creation timestamp marks when it was born
Labels and annotations keep it well-adorned
[Chorus]
Describe the service, see what it connects
Endpoints showing where the traffic directs
Selector matching pods that qualify
Port mappings tell you how the data flies
K-U-B-E-C-T-L describe
Shows you the service blueprint inside
[Outro]
When your audiobook pods need to be found
Describe the service keeps your traffic sound
Endpoints, selectors working in harmony
That's how Kubernetes serves your poetry
32. DaemonSets (one pod per node — logging agents, monitoring)
[Verse 1]
In every cluster there's a special way
To run one pod on every single node
DaemonSets ensure they never stray
Logging agents following this code
When nodes join up, pods appear like magic
When nodes go down, pods disappear
This pattern's not random, it's systematic
One per node, the rule is crystal clear
[Chorus]
DaemonSet, one pod per node
Logging and monitoring, that's the code
Get them all with kubectl dash A
Describe the details, watch them display
DaemonSet, they spread around
Every worker node, they can be found
Agents running everywhere
System services beyond compare
[Verse 2]
Logging agents need to see it all
Fluent-d or Filebeat on every machine
Monitoring daemons answer the call
Node Exporter keeping metrics clean
They don't need scheduling like other pods
They bypass the scheduler's careful plan
Directly placed by Kubernetes gods
One per node is their master plan
[Chorus]
DaemonSet, one pod per node
Logging and monitoring, that's the code
Get them all with kubectl dash A
Describe the details, watch them display
DaemonSet, they spread around
Every worker node, they can be found
Agents running everywhere
System services beyond compare
[Bridge]
Kubectl get daemonsets across all namespaces
Shows you every agent running wide
Describe command reveals all the places
Namespace flags help you peek inside
Rolling updates happen one by one
Node by node they upgrade with care
System services are never done
DaemonSets keep them running everywhere
[Chorus]
DaemonSet, one pod per node
Logging and monitoring, that's the code
Get them all with kubectl dash A
Describe the details, watch them display
DaemonSet, they spread around
Every worker node, they can be found
Agents running everywhere
System services beyond compare
[Outro]
When you need that system-wide embrace
DaemonSets put pods in every place
One per node, the golden rule
DaemonSets are the perfect tool
33. Set clusterIP: None in YAML
[Verse 1]
When your pods need to discover each other's names
But you don't want a virtual IP in the game
Set your cluster IP to none in the YAML line
Create a headless service, everything's fine
[Chorus]
Headless service, no virtual address
ClusterIP none, direct access
Pods talk directly, DNS resolves the way
Set clusterIP none in your YAML today
[Verse 2]
Each pod gets its own DNS entry clear
No load balancing, connections direct here
Perfect for databases that need to know
Which specific pod instance they should go
[Chorus]
Headless service, no virtual address
ClusterIP none, direct access
Pods talk directly, DNS resolves the way
Set clusterIP none in your YAML today
[Bridge]
In your spec section, type it out clean
Service type ClusterIP, set to none you'll see
The kube-proxy won't create any virtual IP
Direct pod-to-pod communication is the key
[Verse 3]
StatefulSets love this pattern the most
Each pod gets a stable network host
Master-slave setups, peer-to-peer too
Headless services know just what to do
[Chorus]
Headless service, no virtual address
ClusterIP none, direct access
Pods talk directly, DNS resolves the way
Set clusterIP none in your YAML today
[Outro]
Remember the rule when you need direct connection
ClusterIP none gives perfect direction
No proxy in between, just pod-to-pod flow
Headless services, now you know
34. List deployments
[Verse 1]
When you need to see what's running in your cluster space
Applications deployed across your Kubernetes place
There's a simple command that will show you the way
List all deployments that are active today
[Chorus]
Kubectl get deployments, that's the way to go
Shows you all the apps and lets the details flow
Get deploy for short, it does the same thing too
Listing all deployments, that's what kubectl do
Kubectl get deployments, memorize this line
Check your running apps, working all the time
[Verse 2]
Every deployment has a name and ready count
Shows you how many pods are up and running now
Available replicas and the age they've been alive
Status information helps you keep your apps in stride
[Chorus]
Kubectl get deployments, that's the way to go
Shows you all the apps and lets the details flow
Get deploy for short, it does the same thing too
Listing all deployments, that's what kubectl do
Kubectl get deployments, memorize this line
Check your running apps, working all the time
[Bridge]
In your terminal window, type the magic phrase
See your applications running for days and days
Ready, available, updated all in view
Deployment status telling you what's running true
[Verse 3]
Whether troubleshooting problems or just checking health
This command gives you visibility and deployment wealth
Long form or shorthand, either way will work
Get deployments listed with a kubectl quirk
[Chorus]
Kubectl get deployments, that's the way to go
Shows you all the apps and lets the details flow
Get deploy for short, it does the same thing too
Listing all deployments, that's what kubectl do
Kubectl get deployments, memorize this line
Check your running apps, working all the time
[Outro]
When you need to see what's deployed today
Kubectl get deployments shows you the way
35. Check ingress controller pods
[Verse 1]
When your traffic isn't flowing through
And users can't get to your site
Time to check what's happening with
Your ingress controller tonight
Open up your terminal
Type the command that we all know
kubectl get pods will show you
Where your traffic's meant to go
[Chorus]
Check ingress controller pods
In the nginx namespace
See if they're running strong
Or if something's out of place
One controller per cluster
That's the rule we follow through
TLS at the ingress
That's the best practice too
[Verse 2]
kubectl get pods dash n
ingress dash nginx is the way
Look for Ready, Running status
Green lights mean you're okay
If you see Pending, Crashing
Something's wrong behind the scene
Check your resources and your configs
Keep your gateway running clean
[Chorus]
Check ingress controller pods
In the nginx namespace
See if they're running strong
Or if something's out of place
One controller per cluster
That's the rule we follow through
TLS at the ingress
That's the best practice too
[Bridge]
Nginx, Traefik, or cloud-native
Pick one and stick with it
Rate limiting, CORS, authentication
Use annotations to commit
Gateway API is coming
The future's looking bright
But for now keep checking pods
To keep your traffic right
[Chorus]
Check ingress controller pods
In the nginx namespace
See if they're running strong
Or if something's out of place
One controller per cluster
That's the rule we follow through
TLS at the ingress
That's the best practice too
[Outro]
When the pods are healthy running
Traffic flows without a doubt
Check ingress controller pods
That's what debugging's all about
36. Scale a deployment
[Verse 1]
Your audiobook app is running slow tonight
Users are complaining, nothing feels quite right
One pod is working but it's not enough
When traffic gets heavy, the going gets rough
Time to scale up, make your system strong
Kubernetes will help you get back on song
[Chorus]
Scale it up, scale it down
Kubectl is the best command around
Deployment name and replicas five
Keep your audiobook service alive
Scale it up, scale it down
Replicas spinning all around
[Verse 2]
Open your terminal, type the magic words
Kubectl scale deployment, let your voice be heard
Forward slash then name it, that's your target there
Add the replicas flag, show how much you care
Five pods working where there once was one
Horizontal scaling, now your work is done
[Chorus]
Scale it up, scale it down
Kubectl is the best command around
Deployment name and replicas five
Keep your audiobook service alive
Scale it up, scale it down
Replicas spinning all around
[Bridge]
When the load gets heavy and your app runs tight
Scaling is the answer, it'll be alright
More pods mean more power, spread across the nodes
Handling all the traffic, sharing all the loads
[Verse 3]
Watch your pods appearing, one by one they start
Each one serves your users, playing their part
Audiobook deployment, stronger than before
Ready for the traffic coming through your door
Kubernetes orchestrates this symphony
Of pods and deployments in perfect harmony
[Chorus]
Scale it up, scale it down
Kubectl is the best command around
Deployment name and replicas five
Keep your audiobook service alive
Scale it up, scale it down
Replicas spinning all around
[Outro]
Scale deployment audiobook, replicas equals five
That's the way to keep your service alive
37. Test connectivity
[Verse 1]
When your audiobook won't load or play
And the service seems so far away
There's a kubectl trick that works so well
To test connections and quickly tell
Time to run a pod that's temporary
With curl inside to check what's scary
Image curlimages slash curl will do
Interactive mode will help you too
[Chorus]
kubectl run curl-test now
Image curl and tell me how
Interactive temporary pod
Dash it dash rm restart never mod
Curl dash v http colon slash slash
Service name and port don't crash
Test connectivity right away
Debug your audiobook today
[Verse 2]
The dash it flag means interactive
Terminal session that's so active
Dash dash rm cleans up when you're done
No leftover pods when test is run
Restart never means don't try again
If the pod fails just let it end
Double dash separates the command
From kubectl options you understand
[Chorus]
kubectl run curl-test now
Image curl and tell me how
Interactive temporary pod
Dash it dash rm restart never mod
Curl dash v http colon slash slash
Service name and port don't crash
Test connectivity right away
Debug your audiobook today
[Bridge]
Verbose output shows the flow
Headers requests all you need to know
Connection timeouts or success
This simple test removes the guess
Service discovery made so clear
Is your audiobook service really here
Network policies blocking the way
This curl test saves you from dismay
[Chorus]
kubectl run curl-test now
Image curl and tell me how
Interactive temporary pod
Dash it dash rm restart never mod
Curl dash v http colon slash slash
Service name and port don't crash
Test connectivity right away
Debug your audiobook today
[Outro]
When audio streams just won't connect
This kubectl curl earns respect
Temporary testing pod so neat
Makes network debugging feel complete
38. Port-forward to a service
[Verse 1]
When your service sits inside the cluster wall
And you need to reach it from your local call
There's a bridge you build with just one command line
Port forward makes that distant service mine
[Chorus]
K-U-B-E-C-T-L port dash forward
Service name then ports you move toward
Eight zero eight zero colon eight zero
Local to remote, that's the way to go
Forward forward, bridge the gap between
Forward forward, localhost on your screen
[Verse 2]
Service slash the name you want to find
Eighty eighty is the port that's been assigned
But eight zero eight zero on your machine
Creates a tunnel to that Kubernetes scene
[Chorus]
K-U-B-E-C-T-L port dash forward
Service name then ports you move toward
Eight zero eight zero colon eight zero
Local to remote, that's the way to go
Forward forward, bridge the gap between
Forward forward, localhost on your screen
[Bridge]
No need for ingress, no need for load balancer tonight
Just a simple tunnel making everything right
Development testing, debugging with ease
Port forwarding gives you all the access you need
[Verse 3]
Left side local, right side is remote
Colon separates them, that's the magic quote
Eight zero eight zero maps to eighty clean
Your browser connects to the Kubernetes machine
[Final Chorus]
K-U-B-E-C-T-L port dash forward
Service name then ports you move toward
Eight zero eight zero colon eight zero
Local to remote, that's the way to go
Forward forward, bridge the gap between
Forward forward, localhost on your screen
[Outro]
When the cluster's calling and you need to see
Port forward's the key to accessibility
39. View bindings
[Verse 1]
In the cluster where permissions flow
There's a secret you should know
Bindings tie the roles to users tight
Making sure the access is just right
Cluster-wide or namespace bound
Different scopes can be found
[Chorus]
Get cluster role bindings first
See who has the widest burst
Get role bindings all around
Every namespace can be found
View the bindings, know the way
Who can do what every day
[Verse 2]
kubectl get with cluster role
Bindings show the access control
Dash A flag will show you more
All namespaces at your door
Role bindings scope is narrow
Like a targeted arrow
[Chorus]
Get cluster role bindings first
See who has the widest burst
Get role bindings all around
Every namespace can be found
View the bindings, know the way
Who can do what every day
[Bridge]
Cluster bindings cross all lines
Namespace bindings stay confined
Check them both to understand
Who holds power in your land
Security through clarity
Permissions shown so you can see
[Verse 3]
When you need to audit rights
These commands will shine the lights
Show the subjects and their roles
Administrative controls
Binding names and namespaces too
All the access granted through
[Chorus]
Get cluster role bindings first
See who has the widest burst
Get role bindings all around
Every namespace can be found
View the bindings, know the way
Who can do what every day
[Outro]
View the bindings, stay secure
Make your access control sure
kubectl shows you what you need
Binding knowledge helps you lead
40. Check your own permissions
[Verse 1]
Before you try to deploy your code
Or delete what's running in production mode
There's a question that you need to ask
Can I really do this task?
Kubernetes has a way to check
Your permissions before you wreck
The system with commands you can't run
Let's learn how it's properly done
[Chorus]
Can I, can I, check before you try
Auth can I will tell you why
Some commands might be denied
Can I, can I, verify your rights
Before you launch into the night
Permission checking keeps things right
[Verse 2]
Kubectl auth can I create
Deployments in this cluster state
The system checks your role and scope
Gives you yes or no, don't just hope
Maybe you can read the pods
But writing needs the admin gods
Each namespace has its own rules
Don't be caught without the tools
[Chorus]
Can I, can I, check before you try
Auth can I will tell you why
Some commands might be denied
Can I, can I, verify your rights
Before you launch into the night
Permission checking keeps things right
[Bridge]
In production be extra careful
Deletion can be truly harmful
Check your permissions with the flag
Dash dash namespace in the bag
Kubectl auth can I delete
Pods in production's elite
Better safe than sorry later
Permission checking makes you greater
[Chorus]
Can I, can I, check before you try
Auth can I will tell you why
Some commands might be denied
Can I, can I, verify your rights
Before you launch into the night
Permission checking keeps things right
[Outro]
Before you act, before you deploy
Use can I, it's not a toy
Check your permissions, stay secure
That's how professionals endure
41. Check another user's permissions
[Verse 1]
When you need to check what someone else can do
In your cluster there's a way to see it through
Use kubectl auth can-i with their name in line
Add dash dash as equals and their username fine
[Chorus]
Can they create pods, can they delete files
Check another user's permissions for a while
Auth can-i tells you yes or no today
What they're allowed to do and what's kept away
[Verse 2]
Create pods question mark, add dash dash as user
Type their name right there, now you're not a loser
The command will answer if they have the right
To make new pods or if it's out of sight
[Chorus]
Can they create pods, can they delete files
Check another user's permissions for a while
Auth can-i tells you yes or no today
What they're allowed to do and what's kept away
[Bridge]
Want to check if someone's got the master key
Use star star for everything they might see
Cluster admin powers, do they have them all
Auth can-i star star tells you if they'll fall
[Verse 3]
Single quotes around each star will make it right
Check for cluster admin with this powerful sight
If they get a yes back then they rule the land
Every resource, every verb is in their hand
[Chorus]
Can they create pods, can they delete files
Check another user's permissions for a while
Auth can-i tells you yes or no today
What they're allowed to do and what's kept away
[Outro]
Before you grant access, check what they can do
Auth can-i keeps your cluster safe and true
42. List storage classes
[Verse 1]
When you need to check what storage is available
In your Kubernetes cluster running stable
There's a command that shows you all the classes
No more guessing what your storage passes
kubectl get storageclasses reveals the list
Every option that your cluster can't resist
From fast SSDs to slower spinning drives
See what storage keeps your data alive
[Chorus]
Get storage classes, see what's there
Fast or slow, what does your cluster share
Provisioners and policies too
Storage classes tell you what they can do
Get storage classes, type the command
kubectl shows you what's at your command
[Verse 2]
Each storage class has a provisioner name
AWS EBS or Azure, not quite the same
Google persistent disk or local storage
Every class defines its own coverage
Parameters tell you how volumes are made
Replication and zones where data's laid
Default classes marked with special signs
Making storage choices easier to find
[Chorus]
Get storage classes, see what's there
Fast or slow, what does your cluster share
Provisioners and policies too
Storage classes tell you what they can do
Get storage classes, type the command
kubectl shows you what's at your command
[Bridge]
Volume binding modes immediate or wait
Reclaim policies seal your data's fate
Retain or delete when pods are done
Storage classes make the choice for everyone
Allow volume expansion true or false
Understanding classes helps your cause
[Verse 3]
Before you create that persistent claim
Check your storage classes, learn each name
Some are faster, some store data long
Pick the right class and you can't go wrong
From standard drives to premium speed
Storage classes match your every need
[Chorus]
Get storage classes, see what's there
Fast or slow, what does your cluster share
Provisioners and policies too
Storage classes tell you what they can do
Get storage classes, type the command
kubectl shows you what's at your command
[Outro]
kubectl get storageclasses
Shows you all your storage passes
Before you claim persistent space
Know your options, know your place
43. Create a role
[Verse 1]
In Kubernetes land where pods need care
Permissions matter everywhere
We need a role to grant access right
Let's build one up and see the light
When you want to watch and list and get
Create a role, don't you forget
The kubectl command will pave the way
To secure resources every day
[Chorus]
Create a role, name it well
Verb dash dash verb, can you tell?
Get and list and watch them all
Resource pods will heed the call
Namespace flag to set the place
Role-based access, steady pace
Create a role, make it right
Kubernetes security shining bright
[Verse 2]
Start with kubectl, that's your tool
Create a role, follow the rule
Give it a name that makes sense clear
Something admins will hold dear
The verbs you choose define the power
Get means read in any hour
List shows all the pods in sight
Watch sees changes day and night
[Chorus]
Create a role, name it well
Verb dash dash verb, can you tell?
Get and list and watch them all
Resource pods will heed the call
Namespace flag to set the place
Role-based access, steady pace
Create a role, make it right
Kubernetes security shining bright
[Bridge]
Resource flag points to pods
That's the target for your mods
Namespace flag sets the boundary
Where this role will have authority
Double dash before each flag
Makes the syntax never lag
Commas separate every verb
Clean and simple, don't disturb
[Chorus]
Create a role, name it well
Verb dash dash verb, can you tell?
Get and list and watch them all
Resource pods will heed the call
Namespace flag to set the place
Role-based access, steady pace
Create a role, make it right
Kubernetes security shining bright
[Outro]
Now you know the role creation way
Practice this command every day
Kubectl create role in hand
Security across the land
44. View cluster roles and roles
[Verse 1]
When you need to see the power that's spread across your cluster wide
There's a command that shows you everything, no secrets left to hide
Kubectl get clusterroles will list them all for you
Global permissions that affect the whole system through and through
[Chorus]
Get cluster get roles, that's the way to go
Clusterroles are global, roles are local though
Dash capital A shows all namespaces clear
View your RBAC structure, make your access appear
[Verse 2]
But when you want the namespaced roles, the ones that stay confined
You'll need a different approach to see what's been designed
Kubectl get roles will show you just one space
Add dash capital A to see them every place
[Chorus]
Get cluster get roles, that's the way to go
Clusterroles are global, roles are local though
Dash capital A shows all namespaces clear
View your RBAC structure, make your access appear
[Bridge]
Cluster roles reach everywhere, no boundaries they know
Regular roles stay put inside their namespace home
Security and access rights, now you can see them all
From the smallest local scope to cluster-wide install
[Verse 3]
Now you've got the power to inspect your access tree
Clusterroles and roles displayed for all your eyes to see
Management just got easier when you know where to look
These kubectl commands are pages in your admin book
[Chorus]
Get cluster get roles, that's the way to go
Clusterroles are global, roles are local though
Dash capital A shows all namespaces clear
View your RBAC structure, make your access appear
[Outro]
From cluster-wide to namespace tight
Your roles are now in sight
Kubectl shows the way to go
Now your access rights you know
45. Bind a role to a user or service account
[Verse 1]
When you need to grant access in your cluster space
Bind a role to users with kubectl's embrace
Create role binding with a name you choose
Specify the role and the user you'll use
[Chorus]
Bind it up, bind it tight
Role binding makes permissions right
Namespace scope or cluster wide
Give your users access with pride
Kubectl create, don't hesitate
Role bindings seal your security fate
[Verse 2]
Add the namespace flag to keep it contained
Local permissions properly maintained
But when you need cluster-wide control
Cluster role binding is your goal
[Chorus]
Bind it up, bind it tight
Role binding makes permissions right
Namespace scope or cluster wide
Give your users access with pride
Kubectl create, don't hesitate
Role bindings seal your security fate
[Verse 3]
Service accounts need permissions too
Cluster role binding will see you through
Namespace colon service account name
Cluster-wide access is the game
[Bridge]
Role binding for namespace scope
Cluster role binding gives wider hope
Users and service accounts align
With kubectl your permissions shine
[Chorus]
Bind it up, bind it tight
Role binding makes permissions right
Namespace scope or cluster wide
Give your users access with pride
Kubectl create, don't hesitate
Role bindings seal your security fate
[Outro]
From user to role the binding flows
Security granted as your knowledge grows
Role bindings keep your cluster secure
Access controlled and permissions pure
46. List service accounts
[Verse 1]
When you're working with your cluster every day
Service accounts help applications find their way
They're the identities that pods can use
To access resources without getting the blues
But finding them scattered can be quite a maze
Let me teach you the command that always pays
[Chorus]
Get service accounts dash A
That's the flag that shows the way
Every namespace will display
All the accounts in array
kubectl get serviceaccounts
Add the A to check all routes
Never miss a single one
List them all until you're done
[Verse 2]
In the default namespace you might see some
But other namespaces have accounts that run
The kube-system holds the system's core
And your applications might be using more
Without the dash A flag you'll only see
The current namespace identity
[Chorus]
Get service accounts dash A
That's the flag that shows the way
Every namespace will display
All the accounts in array
kubectl get serviceaccounts
Add the A to check all routes
Never miss a single one
List them all until you're done
[Bridge]
Each account has secrets bound
Tokens that can be found
Age and namespace clearly shown
Every service account known
From system pods to your apps too
This command reveals them all to you
[Verse 3]
When debugging access issues late at night
This command brings service accounts to light
See which ones exist across your cloud
Makes troubleshooting clear and loud
Remember dash A for all namespaces wide
Your cluster's service accounts can't hide
[Chorus]
Get service accounts dash A
That's the flag that shows the way
Every namespace will display
All the accounts in array
kubectl get serviceaccounts
Add the A to check all routes
Never miss a single one
List them all until you're done
[Outro]
kubectl get serviceaccounts dash A
Shows them all in grand display
47. Create a service account
[Verse 1]
In the world of Kubernetes where pods need to play
There's a special kind of user that works a different way
Not a human with a password, not a person at the door
It's a service account waiting to unlock so much more
[Chorus]
kubectl create serviceaccount
That's the magic phrase you need
Give it any name you want
Plant that authentication seed
Service accounts are the key
For your pods to run so free
kubectl create serviceaccount
That's how services succeed
[Verse 2]
When your audiobook importer needs to access and read
It can't use your credentials, no that's not what you need
Create a service identity that pods can safely use
With tokens and permissions that you carefully can choose
[Chorus]
kubectl create serviceaccount
That's the magic phrase you need
Give it any name you want
Plant that authentication seed
Service accounts are the key
For your pods to run so free
kubectl create serviceaccount
That's how services succeed
[Bridge]
No more hardcoded secrets
No more passwords in your code
Service accounts are the answer
For a secure and proper load
Name it well and bind it tight
To the roles that feel just right
[Verse 3]
In your namespace it will live
With a token it can give
To the pods that need to call
Other services through it all
Authentication made clean
Best security you've seen
[Chorus]
kubectl create serviceaccount
That's the magic phrase you need
Give it any name you want
Plant that authentication seed
Service accounts are the key
For your pods to run so free
kubectl create serviceaccount
That's how services succeed
[Outro]
So remember when you're building
And your apps need to connect
Service accounts are the pathway
To the security you expect
48. Delete a PVC (check reclaim policy first!)
[Verse 1]
Before you delete that storage claim
There's something you must check first
The reclaim policy holds the key
To avoid data loss at worst
Production volumes need retain
Development can use delete
Always verify the setting
Before you make the change complete
[Chorus]
Check the policy first, then kubectl delete
P-V-C by name, make it clean and neat
Retain for prod data, delete for test
Always check reclaim before you make a mess
Delete P-V-C, delete P-V-C
But check that policy first, that's the key
[Verse 2]
Storage classes are the way to go
Dynamic provisioning is best
Avoid creating volumes by hand
Let automation do the rest
Wait for first consumer mode
Ensures your pods and volumes align
Same zone deployment every time
Performance tuned and running fine
[Chorus]
Check the policy first, then kubectl delete
P-V-C by name, make it clean and neat
Retain for prod data, delete for test
Always check reclaim before you make a mess
Delete P-V-C, delete P-V-C
But check that policy first, that's the key
[Bridge]
Test your backups, test restore
For stateful workloads you depend
Recovery procedures must be known
Before disaster strikes again
Persistent volumes hold your state
So handle them with proper care
[Chorus]
Check the policy first, then kubectl delete
P-V-C by name, make it clean and neat
Retain for prod data, delete for test
Always check reclaim before you make a mess
Delete P-V-C, delete P-V-C
But check that policy first, that's the key
[Outro]
Storage management done right
Keeps your data safe and sound
Check reclaim, then delete clean
Best practices all around
49. View token (K8s 1.24+ uses projected tokens)
[Verse 1]
In Kubernetes one point twenty four and beyond
The token game has changed, old ways are gone
No more secrets mounted automatically there
Projected tokens are the new way we declare
Service accounts need tokens to authenticate
But the old static method we must eliminate
Create token command is what we use today
Dynamic tokens that expire and fade away
[Chorus]
kubectl create token with the service account name
Projected tokens playing a security game
No more static secrets hanging around
Least privilege principle keeping systems sound
View the token but don't let it stay
Projected security is the Kubernetes way
Short-lived access with expiration time
Keeping your clusters secure by design
[Verse 2]
Never use cluster-admin for your workloads
Create dedicated accounts as security unfolds
One service account per application you deploy
Separation of concerns that nothing can destroy
automountServiceAccountToken set to false
Unless you really need it, give mounting a pause
Only mount the tokens when apps really require
Keep the attack surface small, that's what we desire
[Chorus]
kubectl create token with the service account name
Projected tokens playing a security game
No more static secrets hanging around
Least privilege principle keeping systems sound
View the token but don't let it stay
Projected security is the Kubernetes way
Short-lived access with expiration time
Keeping your clusters secure by design
[Bridge]
Pod Security Standards are your friend
Restricted, Baseline, Privileged to defend
Pod Security Admission controls the gate
Define your policies before it's too late
The token you create has a time to live
More secure than static secrets that we give
Project the identity, scope it down tight
Security contexts shining bright
[Chorus]
kubectl create token with the service account name
Projected tokens playing a security game
No more static secrets hanging around
Least privilege principle keeping systems sound
View the token but don't let it stay
Projected security is the Kubernetes way
Short-lived access with expiration time
Keeping your clusters secure by design
[Outro]
From static to projected, evolution's here
Service account tokens crystal clear
Create, view, and use them with care
Kubernetes security beyond compare
50. Example security context (apply in your pod specs)
[Verse 1]
When you're setting up your pod today
Security context shows the way
Run as non-root, that's the rule
User ID one thousand is your tool
Read-only root filesystem's the key
No privilege escalation, you see
[Chorus]
Lock it down, lock it down
Security context all around
Drop all caps and add back what you need
Read-only roots will make you succeed
Lock it down, lock it down
Keep your pods safe and sound
[Verse 2]
Allow privilege escalation false
That's the setting that never faults
Capabilities drop them all
Then add back just what you call
SecComp profile runtime default mode
That's the safest way to code
[Chorus]
Lock it down, lock it down
Security context all around
Drop all caps and add back what you need
Read-only roots will make you succeed
Lock it down, lock it down
Keep your pods safe and sound
[Bridge]
Best practices tell us what to do
Pod security standards guide you through
Scan your images in CI CD flow
Before they reach your cluster, you know
Namespace level standards are the way
Keep vulnerabilities at bay
[Verse 3]
Run as non-root true is set
Read-only filesystem's your best bet
User one thousand runs your code
Security context shares the load
Drop all capabilities clean
Add back only what you need
[Chorus]
Lock it down, lock it down
Security context all around
Drop all caps and add back what you need
Read-only roots will make you succeed
Lock it down, lock it down
Keep your pods safe and sound
[Outro]
Security context in your spec
Keeps your cluster systems in check
Lock it down and sleep at night
Your pods are running safe and right
Back to Home