Skip to content

Kubernetes Learning Paths

The Learn section has 35 reference pages plus 20 ecosystem tool deep dives. Not everyone needs all of it. Pick the track that matches your goal below, and treat everything outside it as optional reading, not something you're falling behind on by skipping.

Each track is a numbered sequence, not a menu. Read each track in order - every entry assumes the ones above it. Each track builds on the one before it too: Developer and Operator both start from the Beginner track, and Security Specialist starts from the Operator track, matching the real CKS prerequisite of an active CKA.

Track For Builds on New pages Time
Beginner / Generalist Anyone new to Kubernetes, or reading manifests without operating clusters - 12 ~4 hours
Developer → CKAD App developers deploying and debugging their own workloads Beginner +14 ~6 hours
Operator / Admin → CKA Platform engineers and cluster administrators Beginner +19 ~8 hours
Security Specialist → CKS Security engineers hardening clusters Operator / Admin +10 ~5 hours

Track 1: Beginner / Generalist

Goal: a correct mental model of Kubernetes, not exam readiness. Assumes: you have used a terminal and run a Docker container once. Nothing else. Time: about 3-4 hours of reading, or a weekend if you follow along on a local cluster.

Read these in order - each one assumes the ones above it, and the order is chosen so that no page uses a concept you have not met yet.

  1. Overview - Foundations. What Kubernetes is and the reconciliation model everything else rests on.
  2. Get a Cluster to Practice On - Foundations. kubectl plus a local kind cluster, so every command from here on is runnable.
  3. Pods & Deployments - Workloads. The first objects you actually run.
  4. Health Probes - Configuration. How Kubernetes decides a pod is alive and ready; needed before Services and rollouts make sense.
  5. Networking Concepts - Networking. The pod-IP model and where traffic goes.
  6. Services - Networking. Stable endpoints in front of changing pods.
  7. Namespaces - Foundations. How objects are partitioned, now that you know what the objects are.
  8. ConfigMaps & Secrets - Configuration. Getting configuration and credentials into a pod.
  9. Resource Limits & Requests - Configuration. Requests drive both scheduling and autoscaling, so this comes before HPA.
  10. Scaling & HPA - Workloads. Automatic replica scaling, measured against the requests you just learned.
  11. Kubernetes API - Foundations. The machinery under everything above, once you have seen the objects it manages.
  12. Security Primer - Security. The layered model and where to go next.

Stop here if you just need working fluency. Every page above links forward to the deep-dive pages in its section if you want to go further on any one topic.


Track 2: Developer → CKAD

Prerequisite: the Beginner / Generalist track. For: application developers, or anyone prepping for the CKAD exam. Time: about 6 hours of reading on top of Track 1.

Ordered by CKAD domain, heaviest-weighted domain first, so limited study hours land where the exam actually scores. Percentages are the published domain weights.

1. Application Environment, Configuration & Security (25%)

  1. Resource Limits & Requests (~15 min) - revisit at exam depth
  2. Quotas & Limits (~15 min)
  3. Storage (~25 min) - PV, PVC and StorageClass; read before StatefulSets
  4. Security Context (~20 min)
  5. RBAC (~25 min) - service accounts and role bindings are CKAD scope
  6. Pod Security (~15 min)

2. Application Design & Build (20%)

  1. Jobs & CronJobs (~20 min)
  2. Init Containers (~15 min)
  3. StatefulSets (~25 min) - builds directly on Storage above
  4. DaemonSets (~15 min) - context only, not a CKAD objective, but you will meet them

3. Application Deployment (20%)

  1. Helm (~30 min) - everyday packaging, and an explicit exam objective
  2. Kustomize (~25 min)

4. Services & Networking (20%)

  1. DNS & Service Discovery (~20 min)
  2. Ingress (~25 min)
  3. Network Policies (~25 min)

5. Application Observability & Maintenance (15%)

  1. Troubleshooting (~25 min)
  2. Kubectl Cheat Sheet (~15 min) - drill this until the imperative forms are muscle memory

Then: the CKAD Exam Guide.

Gateway API is not on the CKAD curriculum - it lives in Track 3.


Track 3: Operator / Admin → CKA

Prerequisite: the Beginner / Generalist track. For: platform engineers and cluster administrators, or anyone prepping for the CKA exam. Time: about 8 hours of reading on top of Track 1.

Read in order:

Section Pages, in reading order
Foundations 1. Control Plane & etcd, 2. Kubelet & Container Runtime
Configuration 3. Quotas & Limits
Workloads 4. Storage - CKA's thinnest-margin domain relative to its exam weight, don't skip it, and StatefulSets depend on it. 5. StatefulSets, 6. DaemonSets, 7. Jobs & CronJobs, 8. Init Containers, 9. Scheduling & Placement - scheduling decisions are made on requests, so it follows Limits & Requests from Track 1
Networking 10. DNS, 11. Ingress, 12. Gateway API, 13. Network Policies
Operations 14. Troubleshooting, 15. Maintenance, 16. Operators & CRDs, 17. Kubectl Cheat Sheet
Ecosystem essentials 18. Helm, 19. Kustomize - everyday tools. Then the control-plane internals behind the Foundations pages: etcd, CoreDNS, containerd. Argo CD and Prometheus are optional but common in real clusters you'll administer.

Then: the CKA Exam Guide.


Track 4: Security Specialist → CKS

Prerequisite: the Operator / Admin track - CKS assumes CKA-level cluster fluency and doesn't re-teach it, the same prerequisite the real exam enforces. For: security engineers hardening clusters, or anyone prepping for the CKS exam. Time: about 5 hours of reading on top of Track 3.

Read in order:

Section Pages, in reading order
Security Fundamentals 1. RBAC, 2. Pod Security, 3. Security Context, 4. AppArmor & seccomp, 5. Image Scanning, 6. Audit & Logging
Specialist ecosystem 7. Falco (runtime detection), 8. OPA & Gatekeeper and 9. Kyverno (policy enforcement), 10. Cilium (network-policy enforcement at the CNI layer)

Then: the CKS Exam Guide.


A note on Ecosystem Tools

The Ecosystem Tools section covers twenty tools at full production depth - written for people who need to operate the tool, not skim it. Two of them, Helm and Kustomize, are everyday tools already in every track above. The rest are genuinely specialist reading, worth picking up based on what you actually run rather than working through top to bottom:

Area Tools Read if...
Networking & mesh Istio, Cilium, Linkerd, Envoy You're evaluating or operating a service mesh / advanced CNI. Envoy is the data plane under Istio and most Gateway API implementations, so read it if you're debugging one
Observability Prometheus, OpenTelemetry, Jaeger You own monitoring (Prometheus) or distributed tracing (OpenTelemetry for instrumentation, Jaeger for storage and query)
GitOps & delivery Argo CD, Flux CD Your org deploys GitOps-style
TLS & certificates cert-manager You issue or rotate certificates in-cluster, including for Ingress and webhooks
Backup & DR Velero You are responsible for cluster backup, restore, or migration
Autoscaling KEDA You need event-driven or scale-to-zero autoscaling beyond HPA
Runtime security & policy Falco, OPA & Gatekeeper, Kyverno You're on the Security Specialist track, or run policy enforcement in production
Cluster internals etcd, CoreDNS, containerd You're on the CKA track and want the depth behind the control-plane pages, or you're debugging one of these components directly

None of these are prerequisites for each other.

Key Takeaways

  • Pick one track and read it top to bottom - the order is the point, not the page list.
  • The Beginner track is 12 pages and gives a correct mental model; it is not exam preparation.
  • CKAD and CKA both branch off the Beginner track; CKS branches off CKA, matching the real prerequisite.
  • Ecosystem deep dives are demand-driven reading, not a sequence - read the one you are about to operate.