LEARN / BUILD / VERIFY2026 edition · checked 06 Oct
THE CRAFT OF OPERATING DECLARATIVE SYSTEMS
Declare the intent.
Observe the system.
Explain the difference.
Thirty practical lessons connecting Kubernetes control loops to workloads, traffic, identity, troubleshooting and evidence.

ONE SYSTEM, FOUR QUESTIONS
An accepted object is the beginning of the story.
01 · Declare
A versioned API object describes desired state, identity and configuration.
02 · Reconcile
Controllers compare observations with intent and request bounded changes.
03 · Run
The scheduler, node agent and runtime turn an eligible Pod into running containers.
04 · Verify
Readiness, endpoints, policy and application evidence determine whether users can rely on the result.
Open a stage to inspect the mechanism. This is an explanatory diagram; it executes nothing.
30connected chapters
68interview questions
5learning stages
1offline capstone
Practice with a clear boundary.All manifests are offline teaching examples. The handbook creates no cluster, applies no policy and provisions no paid resource. Optional live observations require an approved disposable environment.
Kubernetes 1.37.1Official release baseline checked 6 October 2026. Verify your cluster version, distribution and feature prerequisites before adapting any example.
One system, built in stagesThe fictional ParcelOps API connects selectors, scheduling, readiness and policy. Learn to trace each transition before changing a system.
Build understanding, one mechanism at a time.
Each chapter includes a worked example, a safe exercise, expected observations, troubleshooting and two interview questions.
BEFORE YOU START
Bring curiosity.
Keep the boundary clear.
Bring basic containers, YAML and networking knowledge. The main path uses saved synthetic objects and a Python 3 offline lab. kubectl examples are optional and use an explicit disposable context.
Keep these distinctions close
- Desired state and observed state are different.
- Running is not the same as ready.
- A namespace is not a complete isolation boundary.
- Persistence is not backup.
- Local checks do not prove cluster behavior.
BUILD WITH EVIDENCE
The ParcelOps workload lab
Standard-library checks for synthetic selectors, ports, resource arithmetic and selected privilege settings. No kubectl or cluster access.
Download the lab ↓ CONNECT THE MECHANISMS
The scenario interview
Eight cases that ask you to explain the failure, choose a bounded check and defend the limits.
Open the interview → Sources, evidence and limits
Start with the Official Kubernetes release baseline. Each chapter links to relevant primary documentation. Examples are original teaching fixtures; expected observations are distinguished from executed evidence.
The benchmark and article chapters supply methods and blank templates. They make no invented measurements, deployment claims or completed-lab claims. Reading progress stays in this browser, separately for each book. Every public visitor starts fresh.
Download the blank benchmark template · Download the evidence record