Kubernetes Learning Paths¶
The Learn section has 38 reference pages plus 10 ecosystem tool deep dives. Not everyone needs all of it. Pick the track that matches your goal below, and treat everything outside it as optional reading, not something you're falling behind on by skipping.
Each track builds on the one before it: Developer and Operator both start from the Beginner track, and Security Specialist starts from the Operator track, matching the real CKS prerequisite of an active CKA.
| Track | For | Builds on | New pages |
|---|---|---|---|
| Beginner / Generalist | Anyone new to Kubernetes, or reading manifests without operating clusters | -- | ~10 |
| Developer → CKAD | App developers deploying and debugging their own workloads | Beginner | +14 |
| Operator / Admin → CKA | Platform engineers and cluster administrators | Beginner | +18 |
| Security Specialist → CKS | Security engineers hardening clusters | Operator / Admin | +10 |
Track 1: Beginner / Generalist¶
Goal: a correct mental model of Kubernetes, not exam readiness.
| Section | Pages |
|---|---|
| Foundations | Overview, Kubernetes API, Namespaces |
| Workloads | Pods & Deployments, Scaling & HPA |
| Networking | Overview, Services |
| Configuration | ConfigMaps & Secrets, Health Probes |
| Security | Security Primer |
Stop here if you just need working fluency. Every page above links forward to the deep-dive pages in its section if you want to go further on any one topic.
Track 2: Developer → CKAD¶
Prerequisite: the Beginner / Generalist track. For: application developers, or anyone prepping for the CKAD exam.
| Section | Pages |
|---|---|
| Workloads | StatefulSets, DaemonSets, Jobs & CronJobs, Init Containers |
| Networking | DNS & Service Discovery, Ingress, Gateway API, Network Policies |
| Configuration | Resource Limits & Requests, Quotas & Limits, Storage |
| Security | Pod Security |
| Operations | Troubleshooting, Kubectl Cheat Sheet |
| Ecosystem essentials | Helm, Kustomize - everyday packaging tools, not optional deep dives |
Then: the CKAD Exam Guide.
Track 3: Operator / Admin → CKA¶
Prerequisite: the Beginner / Generalist track. For: platform engineers and cluster administrators, or anyone prepping for the CKA exam.
| Section | Pages |
|---|---|
| Foundations | Control Plane & etcd, Kubelet & Container Runtime |
| Workloads | StatefulSets, DaemonSets, Jobs & CronJobs, Init Containers, Scheduling & Placement |
| Networking | DNS, Ingress, Gateway API, Network Policies |
| Configuration | Limits & Requests, Quotas & Limits, Storage -- CKA's thinnest-margin domain relative to its exam weight, don't skip it |
| Operations | Troubleshooting, Operators & CRDs, Maintenance, Kubectl Cheat Sheet |
| Ecosystem essentials | Helm, Kustomize - everyday tools. Argo CD and Prometheus are optional but common in real clusters you'll administer. |
Then: the CKA Exam Guide.
Track 4: Security Specialist → CKS¶
Prerequisite: the Operator / Admin track -- CKS assumes CKA-level cluster fluency and doesn't re-teach it, the same prerequisite the real exam enforces. For: security engineers hardening clusters, or anyone prepping for the CKS exam.
| Section | Pages |
|---|---|
| Security Fundamentals | RBAC, Pod Security, Security Context, AppArmor & seccomp, Image Scanning, Audit & Logging |
| Specialist ecosystem | Falco (runtime detection), OPA & Gatekeeper and Kyverno (policy enforcement), Cilium (network-policy enforcement at the CNI layer) |
Then: the CKS Exam Guide.
A note on Ecosystem Tools¶
The Ecosystem Tools section covers ten tools at full production depth - written for people who need to operate the tool, not skim it. Two of them, Helm and Kustomize, are everyday tools already in every track above. The rest are genuinely specialist reading, worth picking up based on what you actually run rather than working through top to bottom:
| Area | Tools | Read if... |
|---|---|---|
| Networking & mesh | Istio, Cilium | You're evaluating or operating a service mesh / advanced CNI |
| Observability | Prometheus | You own monitoring |
| GitOps & delivery | Argo CD | Your org deploys GitOps-style |
| Autoscaling | KEDA | You need event-driven or scale-to-zero autoscaling beyond HPA |
| Runtime security & policy | Falco, OPA & Gatekeeper, Kyverno | You're on the Security Specialist track, or run policy enforcement in production |
None of these are prerequisites for each other.