Page
1
(This page has no text content)
Page
2
The Ultimate Docker Container Book Fourth Edition Build, ship, deploy, and scale containerized applications with Docker, Kubernetes, and the cloud Dr. Gabriel N. Schenker
Page
3
The Ultimate Docker Container Book Fourth Edition Copyright © 2026 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the author, nor Packt Publishing or its dealers and distributors, will be held liable for any damages caused or alleged to have been caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. Portfolio Director: Kartikey Pandey Relationship Lead: Aaron Tanna Project Manager: Sonam Pandey Content Engineer: Arun Nadar Technical Editor: Simran Ali Copy Editor: Safis Editing Indexer: Tejal Soni Proofreader: Arun Nadar Production Designer: Shankar Kalbhor Growth Lead: Shreyans Singh First published: April 2018 Second Edition: March 2020 Third Edition: March 2023 Fourth edition: March 2026 Production reference: 1230326 Published by Packt Publishing Ltd. Grosvenor House 11 St Paul's Square Birmingham B3 1RB, UK. ISBN 978-1-80580-439-0 www.packtpub.com
Page
4
Contributors About the author Dr. Gabriel N. Schenker has more than 30 years of experience as a software engineer, architect, consultant, trainer, and engineering leader. He is currently head of platform engineering and lead architect at iptiQ Life & Health EMEA by Swiss Re, where he focuses on developer platforms, data mesh architectures, security, governance, and AI adoption in a highly regulated environment. Gabriel has worked with companies such as Docker, Confluent, and Maison du Software, holds a PhD in physics, and is a certified Apache Kafka developer and operator. He lives in Switzerland with his family.
Page
5
About the reviewers Kasun Rajapakse is a cloud-native and DevOps specialist with extensive experience in designing scalable, secure, and production-ready container platforms. He currently serves as a senior consultant at Avanade in the Netherlands, where he helps organizations modernize their infrastructure using Kubernetes and container technologies. Docker and Microsoft have recognized Kasun as a Docker Captain and a Microsoft MVP for his contributions to the cloud and developer communities. With multiple Kubernetes certifications (CKA, CKS, and CKAD) and hands-on implementation experience, he brings deep technical insight and practical expertise to reviewing content on Docker and containerization. Kunchala Vikram Babu is a distinguished DevSecOps engineer, cloud-native technologist, and community leader with deep expertise in containerization and automation. He currently serves as a senior technical specialist at Sony India, where he shapes scalable infrastructure solutions and accelerates cloud-native adoption across enterprise environments. Vikram is recognized globally as a Docker Captain, a title awarded to select contributors for their leadership and contributions to the Docker ecosystem. Since beginning his Docker journey in 2018, he has architected containerization solutions ranging from monolith modernizations to optimized microservices deployments. An avid educator and storyteller, Vikram created the DevOps Made Easy YouTube channel—where he demystifies complex DevOps and cloud-native workflows for thousands of learners worldwide, blending practical demos, coding walk-throughs, and real-world scenarios. A lifelong learner and certified expert, Vikram has earned multiple credentials from the Cloud Native Computing Foundation (CNCF) and Linux Foundation programs and holds the title of Kubestronaut—a prestigious distinction for professionals who have successfully completed all core Kubernetes certifications, underscoring his deep mastery of Kubernetes and cloud-native technologies. Beyond his professional work, he contributes to open source tooling, writes in Python and Golang, and advocates for community learning through meetups, talks, and published tutorials.
Page
6
Table of Contents Preface xxvii Free benefits with your book ......................................................................................................... xxxii Part 1: Introduction 1 Chapter 1: What Are Containers and Why Should I Use Them? 3 What are containers? ........................................................................................................................... 4 Why are containers important? ........................................................................................................... 7 What is the benefit of using containers for me or my company? .......................................................... 8 The Moby project ................................................................................................................................ 8 Docker products .................................................................................................................................. 9 Docker Desktop • 9 Docker Hub • 10 Docker EE • 10 Container architecture ...................................................................................................................... 10 What's new in containerization ......................................................................................................... 12 Enhanced supply chain security • 12 Debugging and operations in Kubernetes • 12 Docker Desktop extensions • 13 Evolving resource management • 13 Where do we go from here? • 13 Summary ........................................................................................................................................... 14 Further reading ................................................................................................................................. 14 Questions .......................................................................................................................................... 14 Answers .............................................................................................................................................. 15 Get this book's PDF version and more ................................................................................................ 17 Chapter 2: Setting Up a Working Environment 19 Technical requirements ..................................................................................................................... 20 Distinguishing the major operating systems ..................................................................................... 20 macOS • 20 Windows • 20 Linux • 20
Page
7
The Linux command shell .................................................................................................................. 21 PowerShell for Windows .................................................................................................................... 21 Installing and using a package manager ............................................................................................. 21 Installing Homebrew on macOS • 22 Installing Chocolatey on Windows • 22 Installing Git and cloning the code repository ................................................................................... 23 Choosing and installing a code editor ................................................................................................ 24 Installing VS Code on macOS • 25 Installing VS Code on Windows • 25 Installing VS Code on Linux • 26 Installing VS Code extensions • 26 Installing cursor.ai • 27 Installing Docker Desktop on macOS, Windows, or Linux ................................................................ 27 Testing Docker Engine • 29 Testing Docker Desktop • 32 Using Docker with WSL 2 on Windows ............................................................................................. 34 Installing Docker Toolbox ................................................................................................................. 35 Enabling Kubernetes on Docker Desktop .......................................................................................... 35 Installing Podman ............................................................................................................................. 36 Installing Podman on MacOS • 37 Installing Podman on Windows • 37 Installing Podman on Linux • 38 Installing minikube ........................................................................................................................... 39 Installing minikube on Linux, macOS, and Windows • 39 Installing minikube on macOS using Homebrew • 41 Testing minikube and kubectl • 42 Working with a multi-node minikube cluster • 45 Installing kind ................................................................................................................................... 46 Testing kind and minikube • 48 Summary ........................................................................................................................................... 50 Further reading ................................................................................................................................. 50 Questions ........................................................................................................................................... 51 Answers .............................................................................................................................................. 51 Part 2: Containerization Fundamentals 55 Chapter 3: Mastering Containers 57 Technical requirements ..................................................................................................................... 58 Table of Contents vi
Page
8
Running the first container ............................................................................................................... 58 Starting, stopping, and removing containers ..................................................................................... 59 Running a random trivia question container ..................................................................................... 62 Listing containers .............................................................................................................................. 64 Stopping and starting containers ...................................................................................................... 66 Removing containers ......................................................................................................................... 68 Inspecting containers ........................................................................................................................ 68 Executing commands in a running container .................................................................................... 70 Attaching to a running container ...................................................................................................... 72 Retrieving container logs ................................................................................................................... 75 Logging drivers • 77 Using a container-specific logging driver • 78 Advanced topic – changing the default logging driver • 78 The anatomy of containers ................................................................................................................ 83 Architecture • 83 Namespaces • 84 Control groups • 85 Union filesystem • 85 Container plumbing • 86 runc • 86 Containerd • 86 Summary ........................................................................................................................................... 86 Further reading ................................................................................................................................. 86 Questions .......................................................................................................................................... 87 Answers ............................................................................................................................................. 87 Get this book's PDF version and more ............................................................................................... 89 Chapter 4: Creating and Managing Container Images 91 What are images? .............................................................................................................................. 92 The layered filesystem • 92 The writable container layer • 93 Copy-on-write • 95 Graph drivers • 95 Creating Docker images ..................................................................................................................... 95 Interactive image creation • 96 Using Dockerfiles • 99 The FROM keyword • 101 The RUN keyword • 101 vii Table of Contents
Page
9
The COPY and ADD keywords • 102 The WORKDIR keyword • 103 The CMD and ENTRYPOINT keywords • 104 A complex Dockerfile • 106 Building an image • 107 Working with multi-stage builds • 109 Dockerfile best practices • 112 Saving and loading images • 115 Containerizing a legacy app using the lift and shift approach .......................................................... 115 Analyzing external dependencies • 116 Preparing source code and build instructions • 116 Configuration • 117 Secrets • 117 Authoring the Dockerfile • 117 The base image • 118 Assembling the sources • 118 Building the application • 118 Defining the start command • 119 Why bother? • 119 Sharing or shipping images ............................................................................................................. 120 Tagging an image • 120 Demystifying image namespaces • 120 Explaining official images • 122 Pushing images to a registry • 122 Supply chain security practices ........................................................................................................ 123 Summary ......................................................................................................................................... 124 Questions ........................................................................................................................................ 124 Answers ............................................................................................................................................ 125 Chapter 5: Data Volumes and Configuration 129 Technical requirements ................................................................................................................... 130 Creating and mounting data volumes ............................................................................................. 130 Modifying the container layer • 130 Creating volumes • 131 Mounting a volume • 134 Removing volumes • 136 Accessing Docker volumes • 137 Sharing data between containers ..................................................................................................... 141 Table of Contents viii
Page
10
Using host volumes .......................................................................................................................... 143 Defining volumes in images ............................................................................................................. 146 Configuring containers .................................................................................................................... 149 Defining environment variables for containers • 150 Using configuration files • 152 Defining environment variables in container images • 153 Environment variables at build time • 155 Persistent storage and stateful container patterns ........................................................................... 156 Understanding persistent storage in Docker • 156 Patterns for managing stateful containers • 156 Best practices for persistent storage • 156 Summary .......................................................................................................................................... 157 Further reading ................................................................................................................................ 157 Questions ........................................................................................................................................ 158 Answers ........................................................................................................................................... 158 Get this book's PDF version and more .............................................................................................. 162 Chapter 6: Debugging Code Running in Containers 163 Technical requirements ................................................................................................................... 164 Evolving and testing code running in a container ............................................................................ 164 Mounting evolving code in the running container • 169 Auto-restarting code upon changes .................................................................................................. 171 Auto-restarting for Node.js • 172 Auto-restarting for Java and Spring Boot • 174 Installing JDK 21 on macOS • 174 Installing JDK 21 on Windows • 175 Installing Java Extensions for VS Code • 175 Auto-restarting for Python • 180 Prerequisites • 180 Auto-restarting for .NET • 185 Prerequisites • 186 Line-by-line code debugging inside a container ............................................................................... 192 Debugging a Node.js application • 192 Debugging a .NET application • 197 Instrumenting your code to produce meaningful logging information ........................................... 199 Instrumenting a Python application • 200 Instrumenting a .NET C# application • 203 Using OpenTelemetry and Jaeger to monitor and troubleshoot ....................................................... 205 ix Table of Contents
Page
11
Instrumenting a .NET application • 205 Instrumenting a Java application • 209 Summary .......................................................................................................................................... 213 Questions ......................................................................................................................................... 213 Answers ........................................................................................................................................... 214 Chapter 7: Testing Applications Running in Containers 217 Technical requirements ................................................................................................................... 218 Benefits of testing in containers ...................................................................................................... 218 Why do we test? • 218 Manual versus automated testing • 218 Why do we test in containers? • 220 Types of tests for containerized apps ............................................................................................... 220 Unit tests • 220 Integration tests • 221 Acceptance tests • 221 Tools, frameworks, and test environments ...................................................................................... 222 Implementing a sample component • 223 Implementing and running unit and integration tests • 231 Implementing and running black-box tests • 234 Best practices for setting up a testing environment ......................................................................... 239 Tips for debugging and troubleshooting issues ............................................................................... 240 Challenges and considerations when testing applications running in containers ........................... 241 Case studies ..................................................................................................................................... 241 Summary ......................................................................................................................................... 242 Questions ........................................................................................................................................ 242 Answers ........................................................................................................................................... 242 Get this book's PDF version and more ............................................................................................. 244 Chapter 8: Increasing Productivity with Docker Tips and Tricks 245 Technical requirements ................................................................................................................... 246 Keeping your Docker environment clean ......................................................................................... 246 Using a .dockerignore file ................................................................................................................ 247 Executing simple admin tasks in a container ................................................................................... 248 Running a Perl script • 248 Running a Python script • 250 Limiting the resource usage of a container ...................................................................................... 252 Limiting memory resources • 252 Table of Contents x
Page
12
Limiting CPU resources • 253 Limiting block I/O (disk I/O) resources • 253 Limiting process IDs • 254 Avoiding running a container as root .............................................................................................. 254 Step 1: Running the container as root (default) • 254 Step 2: Running the container as non-root • 255 Running Docker CLI commands from within Docker ...................................................................... 255 Special case: Docker-in-Docker • 256 Automating a pipeline • 257 Optimizing your build process ........................................................................................................ 259 Scanning for vulnerabilities and secrets .......................................................................................... 260 Using Snyk to scan a Docker image • 261 Using Docker Scout to scan a Docker image for vulnerabilities • 262 Running your development environment in a container ................................................................. 265 Summary ......................................................................................................................................... 269 Questions ........................................................................................................................................ 269 Answers ........................................................................................................................................... 269 Part 3: Orchestration Fundamentals 271 Chapter 9: Learning about Distributed Application Architecture 273 What is a distributed application architecture? ............................................................................... 273 Defining the terminology • 274 Patterns and best practices .............................................................................................................. 276 Loosely coupled components • 277 Stateful versus stateless • 277 Service discovery • 277 Routing • 279 Load balancing • 279 Defensive programming • 279 Retries • 280 Logging • 280 Error handling • 280 Redundancy • 280 Health checks • 281 Circuit breaker pattern • 281 Rate limiter • 282 Bulkhead • 282 xi Table of Contents
Page
13
Running in production .................................................................................................................... 283 Logging • 283 Tracing • 284 Monitoring • 284 Application updates • 284 Rolling updates • 284 Blue-green deployments • 284 Canary releases • 285 Irreversible data changes • 285 Changing the data structure at scale • 286 Rollback and roll forward • 286 Modern microservice patterns ........................................................................................................ 287 Summary ......................................................................................................................................... 287 Further reading ............................................................................................................................... 288 Questions ........................................................................................................................................ 288 Answers ........................................................................................................................................... 289 Get this book's PDF version and more ............................................................................................. 291 Chapter 10: Using Single-Host Networking 293 Technical requirements ................................................................................................................... 294 Dissecting the container network model ......................................................................................... 294 Network firewalling ........................................................................................................................ 296 IPv4, IPv6, and dual-stack networking • 297 nftables versus iptables • 298 Best practice: Least-privilege networking • 298 Working with the bridge network ................................................................................................... 298 Creating a custom bridge network • 302 IPv6 and dual-stack bridge networks • 302 Configuring the MTU and other options • 303 Attaching containers to custom bridge networks • 303 The host and null network types ...................................................................................................... 311 The host network • 311 The null (none) network • 313 Running in an existing network namespace ..................................................................................... 314 How Kubernetes uses this concept • 317 Practical debugging use case • 317 Managing container ports ................................................................................................................ 317 What actually happens under the hood • 320 Table of Contents xii
Page
14
Platform specifics and common pitfalls • 320 Advanced publishing patterns • 321 Multiple services and avoiding collisions • 321 Security checklist • 322 HTTP-level routing using a reverse proxy ........................................................................................ 322 Containerizing the monolith • 322 Extracting the first microservice • 327 Using Traefik to reroute traffic • 328 Summary ......................................................................................................................................... 330 Further reading ................................................................................................................................ 331 Questions ......................................................................................................................................... 331 Answers ........................................................................................................................................... 332 Chapter 11: Managing Containers with Docker Compose 337 Technical requirements ................................................................................................................... 338 Demystifying declarative versus imperative orchestration of containers ........................................ 338 What has changed since the last edition of the book ....................................................................... 339 Running a multi-service app ........................................................................................................... 340 Building images with Docker Compose ........................................................................................... 346 Running an application with Docker Compose ............................................................................... 355 Scaling a service .............................................................................................................................. 357 Building and pushing an application ............................................................................................... 360 Using Docker Compose overrides .................................................................................................... 362 Modularizing applications with include ......................................................................................... 365 When to use Docker Compose versus a full orchestration system .................................................... 369 Summary ......................................................................................................................................... 370 Further reading ................................................................................................................................ 371 Questions ......................................................................................................................................... 371 Answers ........................................................................................................................................... 372 Get this book's PDF version and more ............................................................................................. 376 Chapter 12: Shipping Logs and Monitoring Containers 377 Technical requirements ................................................................................................................... 378 Platform differences • 378 Why logging and monitoring matter ............................................................................................... 379 Shipping container logs ................................................................................................................... 380 Configuring log rotation and retention policies • 380 Configuring the logging driver • 380 xiii Table of Contents
Page
15
Globally setting the log driver • 380 Locally setting the log driver • 382 Setting log rotation and retention policies • 382 Using a log management system • 383 Step 1a – Setting up the ELK Stack on Linux • 383 Step 1b – Installing and configuring Filebeat • 384 Running the sample on a Linux computer • 384 Running the sample on a Mac or Windows computer • 385 Shipping Docker daemon logs .......................................................................................................... 391 Docker daemon logs on Mac • 392 Docker daemon logs on a Windows computer • 392 Querying a centralized log with Kibana .......................................................................................... 393 Step 1 – Preparing your project folder • 393 Step 2 – Creating the Node.js API • 394 Step 3 – Creating the Ruby worker • 395 Step 4 – Filebeat configuration (macOS/Windows pattern) • 395 Step 5 – Creating the Docker Compose file • 396 Step 5 – Running the stack • 398 Step 6 – Generating some logs • 398 Step 7 – Accessing Kibana • 399 Step 8 – Creating a data view in Kibana • 399 Step 9 – Exploring your logs • 400 Step 10 – Filtering and searching • 401 Step 11 – Visualizing and saving • 401 Step 12 – Cleaning up • 402 What you learned • 402 Collecting and scraping metrics with Prometheus .......................................................................... 402 Step 1 – Preparing the project structure • 402 Step 2 – Implementing the Go service • 403 Step 3 – Implementing the Python service • 404 Step 4 – Implementing the C# (.NET) service • 405 Step 5 – Configuring Prometheus • 406 Step 6 – Creating the Docker Compose stack • 406 Step 7 – Verifying Prometheus targets • 407 Step 8 – Exploring metrics • 408 Step 9 – Cleaning up • 408 What you learned • 408 Monitoring a containerized application ......................................................................................... 408 Table of Contents xiv
Page
16
Step 1 – Preparing the folder structure • 408 Step 2 – Creating a simple sample application • 409 Step 3 – Configuring Prometheus • 410 Step 4 – Writing the Docker Compose file • 410 Step 5 – Verifying Prometheus targets • 411 Step 6 – Accessing Grafana and connect Prometheus • 411 Step 7 – Creating a dashboard • 412 Step 8 – (Optionally) Adding alerts • 412 Step 9 – Exploring further metrics • 412 Step 10 – Cleaning up • 412 What you learned • 412 Observability and security monitoring ............................................................................................. 413 Summary .......................................................................................................................................... 413 Questions ........................................................................................................................................ 414 Answers ............................................................................................................................................ 415 Chapter 13: Securing Containers 417 Technical requirements .................................................................................................................... 417 Installing Ruby on macOS • 418 Installing Ruby on Windows • 419 Installing Trivy and Cosign on macOS • 419 Installing Trivy and Cosign on Windows • 420 Supply chain security ...................................................................................................................... 420 Understanding what makes up your image • 421 Generating an SBOM • 421 Verifying image provenance • 422 Building a sample application • 422 Implementing the application • 422 Building and running the image • 425 Generating a BOM and scanning the image • 425 Scanning the image • 425 Verifying and signing the image • 425 Securing the pipeline • 426 Image vulnerability scanning and content trust .............................................................................. 426 Why scan container images? • 427 Scanning with Trivy • 427 Content trust: cryptographic guarantees via Cosign • 428 Signing and verifying with Cosign • 429 xv Table of Contents
Page
17
Enforcing signing and verifying in CI/CD pipelines and at runtime • 429 Container hardening practices ........................................................................................................ 430 Principle of least privilege: run as non-root and drop capabilities • 430 Adding a non-root user in your Dockerfile • 430 Dropping unnecessary Linux capabilities • 431 Using --no-new-privileges • 432 Read-only filesystems, immutable layers, and minimal mounts • 432 Mounting your container rootfs as read-only • 432 Mounting specific directories as writable volumes • 432 Using minimal images (scratch or distroless) • 433 Kernel-level security: seccomp, AppArmor, SELinux, and user namespaces • 433 Resource limits and cgroups • 434 Health checks, monitoring, and defense in depth • 434 Adding a HEALTHCHECK statement to your Dockerfile • 434 Logging and monitoring agent • 435 Immutable infrastructure mindset • 435 Putting it all together: hardened example for hello-ruby • 435 Trade-offs to understand when hardening containers • 436 Secrets management ....................................................................................................................... 437 Why not bake secrets into your image or env vars? • 438 Runtime secret injection • 438 Docker Swarm and Docker secrets (for services) • 438 Docker Compose and secrets • 439 Build-time secrets • 440 External secret management (vault, cloud, and sidecars) • 440 Trade-offs and caveats • 441 Secrets injection in our Ruby app • 441 Runtime security tools .................................................................................................................... 442 Why runtime security matters • 443 Introducing Falco • 443 Deploying Falco in a Docker environment • 444 Customizing detection rules • 444 Integrating alerts into response workflows • 445 Deployment considerations and trade-offs • 445 Summary ......................................................................................................................................... 446 References ....................................................................................................................................... 446 Questions ........................................................................................................................................ 446 Answers ........................................................................................................................................... 447 Table of Contents xvi
Page
18
Get this book's PDF version and more ............................................................................................. 448 Chapter 14: Introducing Container Orchestration 449 What are orchestrators, and why do we need them? ....................................................................... 450 The tasks of an orchestrator ............................................................................................................ 450 Reconciling the desired state • 450 Replicated and global services • 451 Service discovery • 452 Routing • 452 Load balancing • 453 Scaling • 453 Intelligent autoscaling and cost-aware scheduling • 454 Self-healing • 454 Data persistence and storage management • 455 Zero-downtime deployments • 455 Affinity and location awareness • 456 Security • 457 Secure communication and cryptographic node identity • 457 Secure networks and network policies • 458 Role-based access control (RBAC) • 458 Secrets • 458 Content trust • 459 Reverse uptime • 459 Introspection • 460 The tasks of an orchestrator summary • 461 Overview of popular orchestrators .................................................................................................. 461 Kubernetes – the de facto standard • 462 Docker Swarm – simplicity over features • 463 Amazon Elastic Kubernetes Service (EKS) • 463 Azure Kubernetes Service (AKS) • 464 Google Kubernetes Engine (GKE) • 465 HashiCorp Nomad — a lightweight alternative • 466 Historical note – Mesos and classic ECS • 467 When to use which orchestrator • 467 Emerging orchestration trends ........................................................................................................ 468 Serverless containers • 468 GitOps and declarative management • 469 Multi-cluster and edge orchestration • 469 xvii Table of Contents
Page
19
AI-driven scheduling and optimization • 469 Security and policy as code • 469 Abstracted platforms and developer experience • 470 Summary ......................................................................................................................................... 470 Further reading ............................................................................................................................... 470 Questions ......................................................................................................................................... 471 Answers ............................................................................................................................................ 471 Part 4: Docker, Kubernetes, and the Cloud 473 Chapter 15: Introducing Kubernetes 475 Technical requirements ................................................................................................................... 476 Understanding Kubernetes architecture ......................................................................................... 477 Kubernetes master nodes ................................................................................................................ 479 Cluster nodes ................................................................................................................................... 481 Introduction to local Kubernetes ..................................................................................................... 482 Docker Desktop with Kubernetes • 482 Running Kubernetes with minikube • 484 Running Kubernetes with kind • 485 Choosing the right local environment • 486 Introduction to Pods ........................................................................................................................ 487 Comparing Docker container networking and Kubernetes Pod networking • 488 Sharing the network namespace • 489 Pod life cycle • 492 Pod specifications • 492 Pods and volumes • 496 Kubernetes ReplicaSet ..................................................................................................................... 499 ReplicaSet specification • 499 Self-healing • 501 Kubernetes Deployments ................................................................................................................ 502 Kubernetes Services ......................................................................................................................... 503 Hands-on exercise using Kubernetes Services • 505 Context-based routing .................................................................................................................... 510 Hands-on exercise for context-based routing • 512 Popular tools: GitOps, Helm 3, and Kustomize ................................................................................. 517 GitOps: Declarative delivery through version control • 517 Helm 3: The package manager for Kubernetes • 518 Kustomize: Native configuration customization • 519 Table of Contents xviii
Page
20
Bringing it all together • 519 Popular tools summary • 520 Summary ......................................................................................................................................... 520 Further reading ............................................................................................................................... 520 Questions ......................................................................................................................................... 521 Answers ........................................................................................................................................... 522 Get this book's PDF version and more ............................................................................................. 523 Chapter 16: Deploying, Updating, and Securing an Application with Kubernetes 525 Technical requirements ................................................................................................................... 526 Deploying our first application ........................................................................................................ 527 Key takeaways – Deploying our first application • 533 Defining liveness, readiness, and startup probes ............................................................................. 534 Key takeaways – Defining liveness, readiness, and startup probes • 538 Zero-downtime deployments .......................................................................................................... 538 How rolling updates work • 539 Hands-on rolling update • 539 Step 1 – Verifying current setup • 539 Step 2 – Introducing a new version of the API • 539 Step 3 – Triggering a rolling update • 540 Step 4 – Observing what happens • 541 Step 5 – Testing the new version • 541 Step 6 – Rolling back if needed • 542 Step 7 – Controlling the rollout speed • 542 Hands-on blue-green (red-green) deployments • 542 Step 1 – Rolling back to API version 1.0.0 • 543 Step 2 – Labeling the existing Deployment as "blue" • 543 Step 3 – Deploying the "green" version (1.1.0) • 543 Step 4 – Verifying the "green" version • 545 Step 5 – Switching the Service to the green Deployment • 545 Step 6 – Validating and cleaning up • 546 Step 7 – Rolling back (if needed) • 546 Key takeaways – Zero-downtime deployments • 547 Security best practices ..................................................................................................................... 547 Step 1 – Running as non-root (and read-only filesystem) • 548 1.1 – Updating the images (TaskBoard) • 548 1.2 – Enforcing at the Pod level (securityContext) • 549 1.3 – Testing a non-root user • 551 xix Table of Contents