From Containers to Production Kubernetes
What containers solved and what they did not, Kubernetes’ declarative control-loop model, and CloudShop’s first container architecture.
Designing, Deploying, Scaling, Securing, Troubleshooting, and Operating Kubernetes in the Cloud

Overview
A practitioner-focused book on designing, deploying, scaling, securing, troubleshooting, and operating Kubernetes in production. It follows a fictional commerce system, CloudShop, from a single containerized service to a full enterprise production platform, connecting failure-aware scheduling, traffic control, data protection, security, observability, troubleshooting, GitOps, and managed-cloud integration into one continuous story.
Kubernetes 1.35+ (currently maintained releases: 1.35 / 1.36 / 1.37)
58,917 words (10 chapters)
Content complete — final technical review and proofreading in progress before publication
A fictional e-commerce platform that evolves throughout the book. It starts as a single containerized deployment and grows into a seven-namespace production system covering networking, storage, security, observability, troubleshooting, delivery, and enterprise governance.
An enterprise cloud architect with more than 20 years of experience in software development, application architecture, and technical architecture. Over the past five years he has designed, built, and operated Kubernetes-based platforms in real enterprise environments. He is the founder and operator of AIDevOps.kr.
Table of Contents
Chapters 1-3 lay the foundation — containers, workloads, and cluster design. Chapters 4-10 connect networking, storage, security, observability, troubleshooting, delivery, and enterprise governance through one continuous system, CloudShop.
What containers solved and what they did not, Kubernetes’ declarative control-loop model, and CloudShop’s first container architecture.
The request path from API server to kubelet, the Deployment/ReplicaSet/Pod relationship, and a first workload contract with probes and graceful shutdown.
Cluster design that starts from requirements, failure domains, resource requests/limits, and the HPA/node-autoscaling chain.
Gateway API as an organizational interface, per-team HTTPRoute ownership, and default-deny NetworkPolicy with explicit allows.
One chain from data classification through StatefulSet, the StorageClass promise, the backup system, to a verified restore.
RBAC, Pod Security Standards, and NetworkPolicy built around one question: what can an attacker reach in the first sixty seconds?
Metrics, logs, and traces; SLIs, SLOs, and error budgets; alerting that pages only on actionable conditions.
Hands-on diagnosis using CloudShop’s real failure-scenario manifests: Pending, ImagePullBackOff, CrashLoopBackOff, OOMKilled, and more.
Helm packaging, Git as desired state, the Argo CD pattern, and rollback as a designed capability rather than an afterthought.
Comparing EKS/AKS/GKE operating models, encoding governance as automation, and CloudShop’s final architecture and production readiness review.
Companion Materials
Every companion/... path referenced throughout the book maps to the same path inside the zip downloadable from this page. Every companion path referenced throughout the book (companion/manifests/..., companion/labs/..., companion/charts/...) maps to the same path inside this zip. This page is the official distribution point for the companion materials.
manifests/chapter01/product-service-deployment.yaml
CloudShop’s first Deployment — a minimal workload with no probes, security, or resource settings yet.
manifests/chapter02/cloudshop-workload-contract.yaml
A complete workload contract with three-stage probes and graceful shutdown.
manifests/chapter03/product-service-production-controls.yaml
Production controls: PriorityClass, topology spread, PodDisruptionBudget, and HPA.
manifests/chapter04/cloudshop-network.yaml
Gateway, three team-owned HTTPRoutes, and default-deny NetworkPolicy with explicit allows.
manifests/chapter05/cloudshop-storage-recovery.yaml
Redis StatefulSet, volumeClaimTemplates, and a backup-verification CronJob.
manifests/chapter06/cloudshop-security.yaml
RBAC, a restricted Pod Security Standard, and a NetworkPolicy that allows only DNS egress.
manifests/chapter07/cloudshop-observability.yaml
OTel/OTLP instrumentation, Prometheus scraping, and an SLO policy ConfigMap.
manifests/chapter08/troubleshooting-scenarios.yaml
Five deliberately broken scenarios: Pending, ImagePullBackOff, CrashLoopBackOff, OOMKilled, and a probe-path mismatch.
charts/cloudshop-service/
A Helm chart with a restricted-PSS-compliant securityContext and readiness/liveness probes.
manifests/chapter09/gitops-application.yaml
An Argo CD Application — selfHeal true, prune false.
manifests/chapter10/enterprise-baseline.yaml
ResourceQuota, LimitRange, restricted Pod Security Admission, and a production-readiness checklist ConfigMap.
labs/
Ten chapter-by-chapter lab guides.
Publication Status
This book is in pre-publication draft. It will be formally published once every gate below is complete. The EPUB available for download today reflects current progress as-is.
AIDevOps Cloud Native Series
This book is designed as the series foundation — a mental model and an architecture map. The books below go far deeper into each individual topic.