Containers & Kubernetes
"It works on my machine" used to end conversations. Containers fixed that by shipping the machine — or at least everything the application needs above the kernel — as a single immutable image. The same image runs on a laptop, in CI, and in production.
Once you have more than a handful of containers, you need something to schedule them, restart them when they crash, route traffic to them, and roll out new versions without downtime. That's orchestration, and Kubernetes is the de facto standard. This hub goes from your first Dockerfile to operating clusters safely.
TL;DR
- An image is a build artifact; a container is a running instance of it.
- Keep images small and reproducible — multi-stage builds, pinned base images, no secrets baked in.
- Kubernetes is declarative. You describe desired state; controllers keep reality matching it.
- Package Kubernetes apps with Helm or Kustomize rather than copy-pasted YAML.
- Don't adopt a service mesh until you need one — mTLS and traffic shifting are powerful but add operational weight.
- Security is layered — image scanning, non-root users, network policies, and RBAC.
From Code to Cluster
Featured Topics
Containers
- Docker — Images, containers, volumes, networks, and Compose
- Podman — Daemonless, rootless-first containers
- Docker vs Kubernetes — Why they solve different problems
Orchestration
- Kubernetes — Pods, deployments, services, and the control loop
- Helm — Versioned, templated packages for Kubernetes
- Service Mesh — mTLS, retries, and traffic control between services
Security
- Container Security — Minimal images, scanning, and runtime hardening
Do You Need Kubernetes?
Kubernetes pays off when its standardization outweighs its complexity. For many teams that point comes later than they expect.
Common Mistakes
🚫 Running as root — The default for many images. Set a non-root USER and drop capabilities.
🚫 latest tags in production — You can't tell what's running or roll back reliably. Pin by version or digest.
🚫 No resource requests and limits — One noisy pod starves the node. Set both.
🚫 Missing health probes — Without readiness probes, traffic hits pods that aren't ready. Without liveness probes, stuck pods never restart.
🚫 Secrets in images or plain ConfigMaps — Use Kubernetes Secrets backed by a secrets manager.
Learning Path
Beginner
Containerize an app with Docker, write a multi-stage Dockerfile, and run a multi-container setup with Compose.
Intermediate
Deploy it to a local Kubernetes cluster (kind or minikube) with Deployments, Services, probes, and resource limits. Package it with Helm.
Advanced
Run production clusters with GitOps, network policies, container security scanning in CI, and evaluate a service mesh.
Related Topics
- DevOps — CI/CD and infrastructure as code that deliver containers
- Cloud Computing — Managed Kubernetes and container services
- Observability & SRE — Monitoring what runs in the cluster