Cloud & DevOps: from a local app to a reliable service
A free 24-lesson practical course covering Linux, networking, Docker, CI/CD, a cloud server, HTTPS, OpenTofu, Ansible, Kubernetes, observability, backup, and recovery through one project.
·
Every lesson is open: reading needs no account.
-
Before you begin: why Cloud & DevOps now
A detailed introduction to this free practical course: why infrastructure skills are growing with cloud, AI, and data centres, what Kazakhstan is building, and what you will learn without a promise of an instant career.
-
Why Cloud & DevOps now: infrastructure, roles, and boundaries
Separate data-centre growth from job-title growth and map the skills of cloud engineering, DevOps, platform engineering, and SRE.
-
Terminal and Git: a reproducible working point
Navigate the workspace, review a change before committing, and return to a known version without deleting history.
-
Linux: users, files, and least privilege
Understand owners, groups, permission modes, and why a service should not run permanently as root.
-
Processes, signals, services, and logs
Observe a PID, graceful shutdown, and structured logs, then read a systemd unit as a startup contract.
-
Networking without magic: IP, port, DNS, HTTP, and TLS
Trace a request from a domain name to a process socket and localize failures layer by layer.
-
CloudLab: service, environment, and readiness criteria
Run the course service, inspect its endpoints, and turn a vague “works” into a testable contract.
-
A container: a bounded process, not a tiny VM
Run a first container, observe namespaces and an immutable image, and distinguish a process from a virtual machine.
-
Image layers, tags, and the container lifecycle
Inspect image history, pin a digest, and distinguish stop, start, remove, and pull.
-
Dockerfile: small, tested, and unprivileged
Build CloudLab as a multi-stage image, test during the build, and verify its unprivileged user.
-
Volumes, bind mounts, and proof of persistence
Move state out of the container, recreate it, and prove a note survives process replacement.
-
Docker Compose: services, networking, and declarative startup
Start the application and reverse proxy from one declaration and reach a service by DNS name inside the network.
-
Health checks, limits, and graceful shutdown
Distinguish liveness from readiness, set resource boundaries, and test shutdown behaviour.
-
Registry, immutable tags, SBOM, and supply-chain checks
Tie an image to a commit SHA, produce an SBOM, and scan its contents before publishing.
-
CI/CD as a feedback system
Design a pipeline from independent checks and separate continuous integration, delivery, and deployment.
-
GitHub Actions: verify every change
Move local checks into a workflow, pin permissions, and use caching without storing secrets.
-
Build and publish one verified image
Publish to a registry only after tests and promote one digest across environments.
-
Secrets, configuration, and environments without leaks
Separate public configuration from secrets, scope tokens narrowly, and prevent values from reaching logs.
-
Deployment, smoke testing, and a verified rollback
Deploy by version, test from outside, and restore the previous digest with a prewritten procedure.
-
Cloud: IaaS, cost, IAM, and shared responsibility
Design minimal virtual infrastructure, a budget, and access before creating a billable resource.
-
Ubuntu server: SSH keys, updates, and a firewall
Connect as an unprivileged user, close unnecessary ports, and verify access from a second session.
-
Domain, reverse proxy, and automatic HTTPS
Point DNS at the server, serve CloudLab through Caddy, and verify the TLS chain externally.
-
OpenTofu and Ansible: infrastructure and configuration as code
Validate a resource description, produce inventory, and apply idempotent host configuration.
-
Kubernetes: Deployment, Service, probes, and rollout
Read the CloudLab manifests, build them with Kustomize, and observe a safe update and rollback.
-
Observability, backups, and a recovery drill
Define service indicators, create a verifiable backup, restore data, and write a blameless final report.