Docker, CI/CD and Deployment

Ship services the way platform teams do: the shell, Git, Dockerfiles, CI pipelines, safe deployments, Kubernetes and release automation, modeled in code you run.

26 lessons across 8 units: processes, signals and permissions, Git workflows and versions, Dockerfiles and the build cache, Compose and GitHub Actions, twelve-factor config, proxies and TLS, rolling and canary deployments, graceful shutdown and observability, Kubernetes manifests and Infrastructure as Code, and a release pipeline boss, with 26 runnable examples, quizzes and 28 coding problems.

Units
8
Lessons
26
Coding problems
28
Examples
26

Free: units 1 to 2 (7 lessons). Units 3 to 8 with DevArcade Pro.

See pricing

What you'll learn

  • Linux and the Shell for ServersProcesses, signals and exit codes, environment variables, permission bits, and pipelines with set -euo pipefail.
  • Git WorkflowsThe commit graph and merge bases, branching workflows and merges, Conventional Commits and semantic versions.
  • Containers and DockerfilesImages and references, layers and the build cache, .dockerignore and multi-stage non-root builds, a Dockerfile linter.
  • Compose and CI PipelinesDocker Compose, GitHub Actions job graphs and matrices, caching and secrets hygiene.
  • Config, Proxies and TLSTwelve-factor configuration, reverse proxies and client addresses, certificates and chains.
  • Deploying and OperatingRolling, blue-green and canary deployments, metric gates, health checks and graceful shutdown, logs, metrics and traces.
  • Kubernetes and Infrastructure as CodeCore objects and label selectors, validating manifests, and planning infrastructure changes.
  • Shipping ReleasesBuild once and promote by digest, then the boss: a release pipeline validator.

Course outline

8 units and 26 lessons. Each lesson has a short read with examples you run, a quiz, and coding problems tested in your browser; most have a step-through visualizer.

  1. Unit 1:Linux and the Shell for Servers

    Processes, signals and exit codes, environment variables, permission bits, and pipelines with set -euo pipefail.

    Free
    1. Processes, Signals and Exit Codes What a server process is, how the system asks it to stop (SIGTERM, SIGINT, SIGKILL), and how exit codes tell success, failure and death by signal apart (127, 137, 143).
      1 problem
    2. Environment Variables and .env Files How processes inherit environment variables, PATH lookup, exporting, and the .env file format: comments, quotes, escapes and the mistakes that leak secrets.
      1 problem
    3. File Permissions as Bits Owner, group and others; read, write and execute as bits; octal modes like 644 and 755; umask; and why servers run as unprivileged users.
      1 problem
    4. Pipes, Redirection and Safer Scripts stdin, stdout and stderr; pipes and redirection; why a failing command in the middle of a pipe goes unnoticed; and set -euo pipefail for scripts in CI and containers.
      1 problem
  2. Unit 2:Git Workflows

    The commit graph and merge bases, branching workflows and merges, Conventional Commits and semantic versions.

    Free
    1. How Git Stores History Commits as snapshots with parents, branches and HEAD as movable pointers, and the merge base: the common ancestor every merge and rebase starts from.
      1 problem
    2. Branching Workflows and Merges Trunk-based development, GitHub flow and Git flow; fast-forward, merge commit, squash and rebase merges; and protecting the main branch.
      1 problem
    3. Commit Conventions and Semantic Versions Semantic Versioning's MAJOR.MINOR.PATCH, Conventional Commits messages (feat, fix, and breaking changes), and computing the next release automatically.
      1 problem
  3. Unit 3:Containers and Dockerfiles

    Images and references, layers and the build cache, .dockerignore and multi-stage non-root builds, a Dockerfile linter.

    Pro
    1. Images, Containers and Registries What a container is (an isolated process, not a VM), images as stacks of read-only layers, image references with registries, tags and digests, and why production pins digests.
      1 problem
    2. Layers and the Build Cache Each instruction is a cached step; a changed instruction or changed copied files invalidates it and everything after it. Order the Dockerfile so dependencies install before the code is copied.
      1 problem
    3. Small, Safe Images: .dockerignore, Multi-Stage and USER Keep secrets and junk out of the build context with .dockerignore, build in one stage and ship only the output in another, and run as a non-root user.
      1 problem
    4. Linting Dockerfiles The mistakes that make images insecure or fragile (floating tags, root users, shell-form CMD, secrets in ENV, ADD where COPY will do), and building a linter that reads a Dockerfile as text.
      1 problem
  4. Unit 4:Compose and CI Pipelines

    Docker Compose, GitHub Actions job graphs and matrices, caching and secrets hygiene.

    Pro
    1. Docker Compose Describe a multi-container app in compose.yaml: services, ports, environment, volumes, the network where service names resolve, and depends_on with health checks for start order.
      1 problem
    2. CI Pipelines with GitHub Actions The shape of a workflow file: triggers, jobs and steps, runners, needs for ordering jobs into a graph, if conditions, and matrices that fan one job out over versions.
      2 problems
    3. CI Caching and Secrets Hygiene Cache keys built from lockfile hashes and restore-key fallbacks; and keeping CI from leaking credentials: least-privilege tokens, OIDC instead of long-lived keys, pinned actions and untrusted pull requests.
      1 problem
  5. Unit 5:Config, Proxies and TLS

    Twelve-factor configuration, reverse proxies and client addresses, certificates and chains.

    Pro
    1. Twelve-Factor Configuration The Twelve-Factor App's rules that matter most for deployment: config in the environment, one build promoted through environments, stateless processes, logs as streams, and fast, graceful disposability.
      1 problem
    2. Reverse Proxies and Load Balancers What sits in front of an app (TLS termination, routing, compression, buffering), the X-Forwarded-* headers it adds, and finding the real client address without trusting what clients send.
      1 problem
    3. TLS and Certificates What TLS guarantees, how a certificate chain links a site to a trusted root, hostnames in subjectAltName (and wildcards), expiry and automated renewal with ACME.
      1 problem
  6. Unit 6:Deploying and Operating

    Rolling, blue-green and canary deployments, metric gates, health checks and graceful shutdown, logs, metrics and traces.

    Pro
    1. Rolling, Blue-Green and Canary Deployments Replacing a running version without downtime: rolling updates with maxSurge and maxUnavailable, blue-green switches, canaries that expose a few users first, and rollback for each.
      1 problem
    2. Canary Releases with Metric Gates Automating the canary decision: compare the canary's error rate and latency with the stable version's, wait for enough traffic, then promote step by step or roll back.
      1 problem
    3. Health Checks and Graceful Shutdown Liveness, readiness and startup probes and what each should check, and shutting down on SIGTERM without dropping requests: stop being ready, drain, close, exit.
      1 problem
    4. Logs, Metrics and Traces Structured logs to stdout, metrics in the Prometheus text format (counters, gauges, histograms), and distributed traces linked by the W3C traceparent header.
      2 problems
  7. Unit 7:Kubernetes and Infrastructure as Code

    Core objects and label selectors, validating manifests, and planning infrastructure changes.

    Pro
    1. Kubernetes Core Objects The desired-state model and the objects a web service uses: Pods, Deployments and ReplicaSets, Services, ConfigMaps and Secrets, Ingress, Namespaces, and how labels and selectors tie them together.
      1 problem
    2. Validating Manifests Catch broken manifests before the cluster does: names, required fields, selectors that do not match their templates, port ranges, resource requests above limits, and policy warnings like unpinned images.
      1 problem
    3. Infrastructure as Code Servers, networks and databases described in version-controlled files: desired state, state files and drift, plan then apply, resources that must be replaced rather than updated, and dependency order.
      1 problem
  8. Unit 8:Shipping Releases

    Build once and promote by digest, then the boss: a release pipeline validator.

    Pro
    1. Build Once, Promote Everywhere A release process that ships what was tested: immutable artifacts identified by digest, promotion through environments, approvals and gates, and rollback by pointing at an earlier artifact.
      1 problem
    2. Boss: A Release Pipeline Validator Combine the course into one tool: validate a release pipeline definition (pinned artifact, a sound stage graph, gates and approvals for production, no plaintext secrets) and plan its execution waves.
      1 problem

Start Docker, CI/CD and Deployment for free

Enroll for free and units 1 and 2 are yours. DevArcade Pro opens every unit of every course, including new ones as they launch, monthly or yearly.

All courses