Platform Engineering Foundations on Kubernetes
Learn to run Kubernetes for many teams: tenant namespaces, quotas, Kyverno guardrails, Crossplane self-service, and cluster upgrades done safely.
What You'll Learn
Understanding the Platform Team's Job
acme-shop's product teams have grown from one to three, and all three now deploy to the same Kubernetes cluster.
Designing Multi-Tenancy with Namespaces
A tenant is a team that shares your cluster. Multi-tenancy means giving each tenant enough isolation that one team's mistake stays inside that team.
Preventing Noisy Neighbours with Quotas and LimitRanges
A noisy neighbour is a workload that uses so much of a shared resource that others suffer. Quotas and LimitRanges are your first defence.
Isolating Teams with RBAC and Network Policies
Quotas protect resources. RBAC and network policies protect access. Kubernetes Security teaches the mechanics; here you design them for tenants.
Understanding Admission Control
Admission control is the checkpoint every create or update request passes before it is saved. It is where your platform's rules live.
Writing Guardrails with Kyverno
Kyverno is a policy engine that runs as an admission webhook. Policies are Kubernetes YAML, so there is no new language to learn.
Skills You'll Master
Curriculum Index12 topics
Understanding the Platform Team's Job
acme-shop's product teams have grown from one to three, and all three now deploy to the same Kubernetes cluster.
Designing Multi-Tenancy with Namespaces
A tenant is a team that shares your cluster.
Preventing Noisy Neighbours with Quotas and LimitRanges
A noisy neighbour is a workload that uses so much of a shared resource that others suffer.
Isolating Teams with RBAC and Network Policies
Quotas protect resources. RBAC and network policies protect access.
Understanding Admission Control
Admission control is the checkpoint every create or update request passes before it is saved.
Writing Guardrails with Kyverno
Kyverno is a policy engine that runs as an admission webhook.
Extending Kubernetes with CRDs and Operators
You already use extensions: Argo CD adds Application, Kyverno adds ClusterPolicy, cert-manager adds Certificate.
Offering Self-Service Infrastructure with Crossplane
Self-service means a team gets what it needs by committing a YAML file, not by opening a ticket.
Managing the Cluster Lifecycle
Platform teams run the cluster itself, not just what is on it. The main risk is upgrades.
Running the Hands-On Lab
You will onboard three acme-shop teams onto platform-lab: payments, orders, and catalog.
Quick Reference and Common Mistakes
Quick Reference Common Mistakes Default deny without DNS.
What You Built and What Comes Next
You gave three acme-shop teams safe, isolated namespaces with quotas, default-deny networking, and automatic...
Career Impact
Roles that use the skills in this module.
DevOps Engineer
Site Reliability Engineer
Platform Engineer
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
A DevOps engineer usually helps one product team ship and run its software. A platform engineer builds the shared paved road that many teams use, with safe defaults, guardrails, and self-service. The skills overlap, but the platform engineer treats other engineers as customers.
It is safe enough for teams inside one company when you add quotas, RBAC, network policies, and admission policies. It is not a hard security boundary for teams that do not trust each other. For that you need separate clusters or virtual clusters.
If your policies only target Kubernetes, Kyverno is easier because policies are written in YAML. Gatekeeper uses the Rego language, which pays off when you want one policy language across several systems. This module teaches Kyverno.
No. Most platform work uses operators other people wrote, such as cert-manager or CloudNativePG. You should understand the reconcile loop well enough to debug one, and know when building your own is justified.