KBS-615

Kubernetes Networking deep dive and Troubleshooting

Detailed Course Outline

Course Length

2 days Kubernetes networking deep dive + 3 days Kubernetes Troubleshooting, 5 days altogether

Course Overview

Kubernetes is the de-facto system for container orchestration, e.g. automating the deployment, scaling and management of microservices-based, containerized applications. And as Kubernetes is becoming the most widely used platform for deploying applications, it is of paramount importance to know how to address problems that may occur in these systems.

This course will present from the generic methodologies applicable in the troubleshooting to the domain specific instructions that will address the various aspects of Kubernetes and the deployed applications.

This training builds on the knowledge gained by students on one of our Kubernetes administration trainings and teaches advanced topics about Kubernetes networking and troubleshooting practices for them.

The first part of the training deals with the different types of networking resources that facilitates the connectivity for containers, the Container Network Interface (CNI) as well as CNI plugins.

In the second part of this training participants learn about a wide range of IT troubleshooting concepts and technics starting with the generic methodologies applicable in troubleshooting to the domain specific instructions that will address the various aspects of Kubernetes clusters and applications deployed in them.

Besides in-depth theoretical coverage, students also do hands-on exercises in their own Kubernetes lab system throughout the training.

Training Objectives

At the end of the training participants:

  • • Understand how network resources are isolated for containers and how network namespaces are connected with veth pairs, Linux bridges, Open vSwitch and routing.
  • • Know the role of iptables and IPVS in container networking and understand the macvlan, ipvlan and SR-IOV connection options.
  • • Understand the Container Network Interface (CNI) specification and be familiar with the reference plugins as well as popular third party plugins such as Calico, Multus CNI, Whereabouts, sriov-cni and ovs-cni.
  • • Understand in depth how Kubernetes services are implemented with iptables and with IPVS and how dual stack services work.
  • • Apply a systematic fault analysis and diagnosis methodology and use the system, container and Kubernetes level diagnosis tools.
  • • Troubleshoot the Kubernetes control plane and worker node components, their configuration and logging, request processing, RBAC and node issues.
  • • Troubleshoot workload errors in Pods, Deployments and StatefulSets.
  • • Troubleshoot Kubernetes networking, including the network architecture, the CNI, services and network policies.
  • • Troubleshoot storage issues in Kubernetes, including the Container Storage Interface (CSI).

Structure

50% theory, 50% hands-on lab exercises

Target Audience

System administrators, developers and DevOps who participated on one of our Kubernetes administration trainings or have a Certified Kubernetes Administrator (CKA) certification and want to learn more about Kubernetes networking as well as general IT systems troubleshooting technics and their implementation at Kubernetes clusters.

Prerequisites

Linux container (e.g. Docker) and Kubernetes admin. skills, for instance by participating on our Docker and Kubernetes administration courses.

Course Modules

PART I. Container and Kubernetes networking deep dive (2 days)

Module 1: Network connectivity for containers

  • Isolating network resources
  • Connecting network namespaces – veth pairs
  • Connecting network namespaces – linux bridge
  • Connecting network namespaces – Open vSwitch
  • Connecting network namespaces – routing
  • Iptables introduction
  • IPVS introduction
  • Connecting network namespaces – macvlan
  • Connecting network namespaces – ipvlan
  • Connecting network namespaces – SR-IOV
  • Lab 1

Module 2: CNI - Container network interface

  • CNI Specification - Concepts
  • CNI – Network configuration format
  • CNI – Execution protocol
  • CNI – Operations
  • CNI – Plugin delegation
  • CNI – Conventions
  • Lab 2

Module 3: CNI plugins

  • CNI – Reference Plugins
  • Third Party Plugins – Calico
  • Third Party Plugins – Multus CNI
  • Third Party Plugins – Whereabouts
  • Third Party Plugins – sriov-cni
  • Third Party Plugins – ovs-cni
  • Lab 3

Module 4: Services deep dive

  • Kubernetes service implementation with iptables
  • Kubernetes service implementation with ipvs
  • Dual stack services

PART II. Kubernetes Troubleshooting (3 days)

Module 5: Troubleshooting methodology and tools

  • Fault analysis methodology
  • Diagnosis methodology
  • Diagnosis tools
    • • System
    • • Container
    • • Kubernetes

Module 6: Kubernetes architecture

  • Control plane components, configuration, logging
  • Worker components, configurations, logging
  • Request processing
  • RBAC
  • Troubleshooting node issues

Module 7: Handling workload errors

  • Troubleshooting pod errors
  • Troubleshooting Deployments
  • Troubleshooting StatefulSets

Module 8: Troubleshooting the Networking

  • Network architecture
  • CNI
  • Troubleshooting services
  • Troubleshooting network policies

Module 9: Storage issues

  • Storage in Kubernetes
  • CSI
  • Troubleshooting storage issues