Docker, CI/CD and Deployment
Ship services the way platform teams do: the shell, Git, Dockerfiles, CI pipelines, safe deployments, Kubernetes and release automation, modeled in code you run.
26 lessons across 8 units: processes, signals and permissions, Git workflows and versions, Dockerfiles and the build cache, Compose and GitHub Actions, twelve-factor config, proxies and TLS, rolling and canary deployments, graceful shutdown and observability, Kubernetes manifests and Infrastructure as Code, and a release pipeline boss, with 26 runnable examples, quizzes and 28 coding problems.
- Units
- 8
- Lessons
- 26
- Coding problems
- 28
- Examples
- 26
Free: units 1 to 2 (7 lessons). Units 3 to 8 with DevArcade Pro.
What you'll learn
- Linux and the Shell for ServersProcesses, signals and exit codes, environment variables, permission bits, and pipelines with set -euo pipefail.
- Git WorkflowsThe commit graph and merge bases, branching workflows and merges, Conventional Commits and semantic versions.
- Containers and DockerfilesImages and references, layers and the build cache, .dockerignore and multi-stage non-root builds, a Dockerfile linter.
- Compose and CI PipelinesDocker Compose, GitHub Actions job graphs and matrices, caching and secrets hygiene.
- Config, Proxies and TLSTwelve-factor configuration, reverse proxies and client addresses, certificates and chains.
- Deploying and OperatingRolling, blue-green and canary deployments, metric gates, health checks and graceful shutdown, logs, metrics and traces.
- Kubernetes and Infrastructure as CodeCore objects and label selectors, validating manifests, and planning infrastructure changes.
- Shipping ReleasesBuild once and promote by digest, then the boss: a release pipeline validator.
Course outline
8 units and 26 lessons. Each lesson has a short read with examples you run, a quiz, and coding problems tested in your browser; most have a step-through visualizer.
- Free
Unit 1:Linux and the Shell for Servers
Processes, signals and exit codes, environment variables, permission bits, and pipelines with set -euo pipefail.
- Processes, Signals and Exit Codes What a server process is, how the system asks it to stop (SIGTERM, SIGINT, SIGKILL), and how exit codes tell success, failure and death by signal apart (127, 137, 143).1 problem
- Environment Variables and .env Files How processes inherit environment variables, PATH lookup, exporting, and the .env file format: comments, quotes, escapes and the mistakes that leak secrets.1 problem
- File Permissions as Bits Owner, group and others; read, write and execute as bits; octal modes like 644 and 755; umask; and why servers run as unprivileged users.1 problem
- Pipes, Redirection and Safer Scripts stdin, stdout and stderr; pipes and redirection; why a failing command in the middle of a pipe goes unnoticed; and set -euo pipefail for scripts in CI and containers.1 problem
-
- Free
Unit 2:Git Workflows
The commit graph and merge bases, branching workflows and merges, Conventional Commits and semantic versions.
- How Git Stores History Commits as snapshots with parents, branches and HEAD as movable pointers, and the merge base: the common ancestor every merge and rebase starts from.1 problem
- Branching Workflows and Merges Trunk-based development, GitHub flow and Git flow; fast-forward, merge commit, squash and rebase merges; and protecting the main branch.1 problem
- Commit Conventions and Semantic Versions Semantic Versioning's MAJOR.MINOR.PATCH, Conventional Commits messages (feat, fix, and breaking changes), and computing the next release automatically.1 problem
-
- Pro
Unit 3:Containers and Dockerfiles
Images and references, layers and the build cache, .dockerignore and multi-stage non-root builds, a Dockerfile linter.
- Images, Containers and Registries What a container is (an isolated process, not a VM), images as stacks of read-only layers, image references with registries, tags and digests, and why production pins digests.1 problem
- Layers and the Build Cache Each instruction is a cached step; a changed instruction or changed copied files invalidates it and everything after it. Order the Dockerfile so dependencies install before the code is copied.1 problem
- Small, Safe Images: .dockerignore, Multi-Stage and USER Keep secrets and junk out of the build context with .dockerignore, build in one stage and ship only the output in another, and run as a non-root user.1 problem
- Linting Dockerfiles The mistakes that make images insecure or fragile (floating tags, root users, shell-form CMD, secrets in ENV, ADD where COPY will do), and building a linter that reads a Dockerfile as text.1 problem
-
- Pro
Unit 4:Compose and CI Pipelines
Docker Compose, GitHub Actions job graphs and matrices, caching and secrets hygiene.
- Docker Compose Describe a multi-container app in compose.yaml: services, ports, environment, volumes, the network where service names resolve, and depends_on with health checks for start order.1 problem
- CI Pipelines with GitHub Actions The shape of a workflow file: triggers, jobs and steps, runners, needs for ordering jobs into a graph, if conditions, and matrices that fan one job out over versions.2 problems
- CI Caching and Secrets Hygiene Cache keys built from lockfile hashes and restore-key fallbacks; and keeping CI from leaking credentials: least-privilege tokens, OIDC instead of long-lived keys, pinned actions and untrusted pull requests.1 problem
-
- Pro
Unit 5:Config, Proxies and TLS
Twelve-factor configuration, reverse proxies and client addresses, certificates and chains.
- Twelve-Factor Configuration The Twelve-Factor App's rules that matter most for deployment: config in the environment, one build promoted through environments, stateless processes, logs as streams, and fast, graceful disposability.1 problem
- Reverse Proxies and Load Balancers What sits in front of an app (TLS termination, routing, compression, buffering), the X-Forwarded-* headers it adds, and finding the real client address without trusting what clients send.1 problem
- TLS and Certificates What TLS guarantees, how a certificate chain links a site to a trusted root, hostnames in subjectAltName (and wildcards), expiry and automated renewal with ACME.1 problem
-
- Pro
Unit 6:Deploying and Operating
Rolling, blue-green and canary deployments, metric gates, health checks and graceful shutdown, logs, metrics and traces.
- Rolling, Blue-Green and Canary Deployments Replacing a running version without downtime: rolling updates with maxSurge and maxUnavailable, blue-green switches, canaries that expose a few users first, and rollback for each.1 problem
- Canary Releases with Metric Gates Automating the canary decision: compare the canary's error rate and latency with the stable version's, wait for enough traffic, then promote step by step or roll back.1 problem
- Health Checks and Graceful Shutdown Liveness, readiness and startup probes and what each should check, and shutting down on SIGTERM without dropping requests: stop being ready, drain, close, exit.1 problem
- Logs, Metrics and Traces Structured logs to stdout, metrics in the Prometheus text format (counters, gauges, histograms), and distributed traces linked by the W3C traceparent header.2 problems
-
- Pro
Unit 7:Kubernetes and Infrastructure as Code
Core objects and label selectors, validating manifests, and planning infrastructure changes.
- Kubernetes Core Objects The desired-state model and the objects a web service uses: Pods, Deployments and ReplicaSets, Services, ConfigMaps and Secrets, Ingress, Namespaces, and how labels and selectors tie them together.1 problem
- Validating Manifests Catch broken manifests before the cluster does: names, required fields, selectors that do not match their templates, port ranges, resource requests above limits, and policy warnings like unpinned images.1 problem
- Infrastructure as Code Servers, networks and databases described in version-controlled files: desired state, state files and drift, plan then apply, resources that must be replaced rather than updated, and dependency order.1 problem
-
- Pro
Unit 8:Shipping Releases
Build once and promote by digest, then the boss: a release pipeline validator.
- Build Once, Promote Everywhere A release process that ships what was tested: immutable artifacts identified by digest, promotion through environments, approvals and gates, and rollback by pointing at an earlier artifact.1 problem
- Boss: A Release Pipeline Validator Combine the course into one tool: validate a release pipeline definition (pinned artifact, a sound stage graph, gates and approvals for production, no plaintext secrets) and plan its execution waves.1 problem
-
Start Docker, CI/CD and Deployment for free
Enroll for free and units 1 and 2 are yours. DevArcade Pro opens every unit of every course, including new ones as they launch, monthly or yearly.