Learning track 08
DevOps — From Git to Production
Twelve modules from culture and Linux basics to Kubernetes, GitOps, and SRE. One BookStore API grows with every chapter — the same app you built in Spring Boot, now shipped and operated at scale.
- Articles
- 48
- Modules
- 12
- Total read
- 8 hr 27 min
- Streak
- 0 days
Start here
DevOps Culture, CALMS, and Team Topologies
DevOps Foundations
Culture, delivery lifecycle, toolchain, and environment strategy
- DevOps Culture, CALMS, and Team TopologiesWhy DevOps is a practice, not a job title — culture, collaboration, and team shapes that ship faster.
- From Commit to Customer: The Delivery LifecyclePlan, code, build, test, release, deploy, operate, monitor — the loop every team runs.
- The Modern DevOps ToolchainSource control, build, artefact, CI/CD, registry, orchestration, and observability — how tools connect.
- Dev, Staging, Prod: Environment StrategyParity, promotion gates, configuration drift, and why staging must mirror production.
Linux & Shell for DevOps
Commands, scripting, processes, and SSH hardening
- Linux Commands Every DevOps Engineer NeedsNavigate, inspect, search, and manage files and processes on the servers your pipelines deploy to.
- Shell Scripting for Repeatable TasksWrite bash scripts for health checks, backups, and pipeline glue with proper error handling.
- Processes, Services, and systemdPID management, signals, systemd units, and why containers changed how we think about services.
- Users, Permissions, and SSH Hardeningchmod, chown, sudo, SSH keys, and least-privilege access for production servers.
Git & Version Control
Commits, branching, PRs, hooks, and signed releases
- Git Fundamentals: Commits, Branches, RemotesThe object model, staging area, branches, remotes, and the daily commands every engineer uses.
- Trunk-Based vs GitFlow vs GitHub FlowChoose a branching model that matches your release cadence and team size.
- PRs, Code Review, and Protected BranchesPull request workflow, review checklists, branch protection, and merge strategies.
- Hooks, Signed Commits, and Release TagsPre-commit hooks, GPG signing, semantic versioning tags, and release automation.
Build Tools: Maven & Packaging
POM structure, lifecycle, dependencies, and CI-friendly builds
- Maven Coordinates, POM, and Directory LayoutgroupId, artifactId, version, standard directory layout, and the BookStore POM explained.
- Lifecycle Phases, Plugins, and Goalsvalidate through deploy, compiler plugin, surefire, and how phases bind to goals.
- Dependency Management, BOMs, and ExclusionsTransitive dependencies, dependencyManagement, Spring Boot BOM, and conflict resolution.
- Profiles, Properties, and CI-Friendly VersionsEnvironment-specific profiles, -D properties, flatten plugin, and reproducible CI builds.
Docker Fundamentals
Containers, images, Dockerfiles, and Compose for local dev
- Containers vs VMs: Isolation and EfficiencyKernel namespaces, cgroups, image immutability, and when each abstraction fits.
- Images, Layers, and the Container RuntimeImage layers, union filesystem, containerd, and how Docker caches builds.
- Writing Your First Production-Ready DockerfileFROM, COPY, RUN, EXPOSE, CMD — containerise the BookStore API step by step.
- Docker Compose for Local Multi-Service StacksRun BookStore + PostgreSQL + Redis locally with one compose file and health checks.
Docker in Production
Multi-stage builds, registries, security, and networking
- Multi-Stage Builds for Slim Java ImagesSeparate build and runtime stages, shrink images from 800 MB to under 200 MB.
- Registries, Tagging Strategy, and Image PromotionECR, GHCR, semantic tags, digest pinning, and promoting images across environments.
- Non-Root Users, Scanning, and SBOMsRun as non-root, read-only filesystems, Trivy scans, and software bill of materials.
- Networking Modes, Volumes, and Bind MountsBridge, host, overlay networks, named volumes, and when to use each storage type.
CI/CD Foundations
Pipeline anatomy, artefacts, deployment strategies, and quality gates
- Continuous Integration vs Continuous Delivery vs DeploymentCI, CD, and CD (deployment) defined — what changes when you automate each step.
- Build, Test, Package, Publish: Pipeline AnatomyStage design, artefact storage, caching, and the BookStore pipeline blueprint.
- Rolling, Blue/Green, Canary, and Feature FlagsCompare deployment strategies by risk, rollback speed, and infrastructure cost.
- Tests, Linting, Coverage, and Approval GatesFail fast in CI with unit tests, static analysis, coverage thresholds, and manual gates.
Jenkins Pipeline Automation
Controller, agents, Jenkinsfile, shared libraries, and scaling
- Jenkins Architecture: Controller, Agents, PluginsController-agent model, plugin ecosystem, and setting up Jenkins for BookStore.
- Declarative Jenkinsfile for BookStoreWrite a declarative pipeline that builds, tests, and pushes the BookStore Docker image.
- Shared Libraries and Reusable Pipeline StepsExtract common steps into a shared library for consistent pipelines across teams.
- Agent Pools, Kubernetes Agents, and CachingScale Jenkins agents dynamically on Kubernetes with layer caching for faster builds.
Modern CI/CD
GitHub Actions, GitLab CI, secrets, and container pipelines
- GitHub Actions: Workflows, Jobs, and Matrix BuildsYAML workflows, reusable actions, matrix strategy, and caching for BookStore CI.
- GitLab CI: Stages, Runners, and Environments.gitlab-ci.yml structure, runner tags, environment tracking, and deployment jobs.
- Secrets, OIDC, and Least-Privilege in PipelinesVault integration, OIDC federation to cloud, and never hardcoding credentials.
- Build, Scan, Push, and Deploy Containers in CIEnd-to-end container pipeline: build image, scan with Trivy, push to registry, deploy.
Kubernetes Fundamentals
Control plane, workloads, config, ingress, and Helm
- Control Plane, Nodes, and the Declarative ModelAPI server, etcd, scheduler, kubelet, and why you declare desired state.
- Pods, Deployments, and Services for BookStoreDeploy BookStore as a Deployment, expose via Service, and understand pod lifecycle.
- ConfigMaps, Secrets, and Ingress RoutingExternalise config, inject secrets, and route HTTP traffic with Ingress.
- Helm Charts: Packaging and VersioningChart structure, values.yaml, releases, and packaging BookStore for repeatable deploys.
Kubernetes Operations
Rollouts, scaling, security, and GitOps with ArgoCD
- Rolling Updates, Rollbacks, and ProbesmaxSurge, maxUnavailable, readiness/liveness probes, and instant rollback.
- HPA, Resource Requests/Limits, and QoSHorizontal Pod Autoscaler, CPU/memory limits, and Quality of Service classes.
- RBAC, Network Policies, and Pod SecurityRoles, RoleBindings, NetworkPolicy, and Pod Security Standards for least privilege.
- GitOps Principles and ArgoCD WorkflowsGit as source of truth, ArgoCD reconcile loop, and automated cluster sync.
Production Platform & SRE
Observability, SLOs, Terraform, and incident response
- Logs, Metrics, and Distributed TracingThe three pillars, Prometheus/Grafana stack, structured logging, and OpenTelemetry.
- SLOs, SLIs, and Error BudgetsDefine reliability targets, measure SLIs, and balance feature velocity with stability.
- Terraform: State, Modules, and EnvironmentsHCL basics, state management, modules, workspaces, and provisioning BookStore infra.
- On-Call, Runbooks, and PostmortemsIncident lifecycle, blameless postmortems, runbook templates, and on-call best practices.