Học Platform engineering (3)
LAYER 4 - CLOUD NATIVE ENGINEERING (Syllabus chi tiết theo ngày)
Tài nguyên: Kubernetes docs, Programming Kubernetes (Hausenblas & Schimanski), Kubernetes Patterns, kubebuilder book, controller-runtime/client-go, Envoy/Istio docs, OCI spec, Gateway API/Crossplane/ArgoCD docs, CNCF landscape.
KHỐI A - Container (Ngày 1-30) → P1 OCI/CRI mini runtime
Ngày 1: Khởi động Layer 4
Mục tiêu: Dựng cluster lab + bản đồ cloud-native.
Lý thuyết: landscape CNCF, cluster components, cách lab bằng kind/kubeadm.
Thực hành: Repo
cloud-native/; dựng cụm kind nhiều node.
Ngày 2: Container recap từ Layer 2
Mục tiêu: Nối mini container đã có.
Lý thuyết: ns + cgroups v2 + overlayfs + seccomp = container; cần chuẩn hoá.
Thực hành: Chạy lại
mycontainer(Layer 2); liệt kê chỗ chưa "chuẩn".
Ngày 3: OCI overview
Mục tiêu: Ba spec làm nên hệ container.
Lý thuyết: image-spec, runtime-spec, distribution-spec.
Thực hành: Đọc cấu trúc một OCI image bằng
skopeo/crane.
Ngày 4: OCI runtime-spec
Mục tiêu: Chuẩn chạy container.
Lý thuyết:
config.json, bundle, lifecycle (create/start/kill/delete), hooks.Thực hành: Đọc
config.jsondo runc sinh; ánh xạ sang ns/cgroups.
Ngày 5: OCI image-spec
Mục tiêu: Cấu trúc image.
Lý thuyết: layer (tar+gzip), manifest, config, digest, content-addressable.
Thực hành: Bóc tách layers một image thủ công.
Ngày 6: OCI distribution-spec
Mục tiêu: Registry hoạt động thế nào.
Lý thuyết: registry API (v2), push/pull, blob, manifest, tag.
Thực hành: Push/pull với một local registry; xem HTTP calls.
Ngày 7: runc
Mục tiêu: Runtime tham chiếu.
Lý thuyết: kiến trúc runc, libcontainer, tạo container từ bundle.
Thực hành: Chạy container bằng runc trực tiếp (không Docker).
Ngày 8: crun & youki
Mục tiêu: Runtime thay thế.
Lý thuyết: crun (C, nhẹ), youki (Rust), tương thích OCI.
Thực hành: So thời gian khởi động runc vs crun.
Ngày 9: containerd
Mục tiêu: Runtime cấp cao dùng trong k8s.
Lý thuyết: kiến trúc, shim, snapshotter, task.
Thực hành: Dùng
ctrchạy container; quan sát shim process.
Ngày 10: containerd - content & image
Mục tiêu: Quản lý image/blob.
Lý thuyết: content store, image service, snapshotter (overlayfs).
Thực hành: Pull image qua containerd; xem content store.
Ngày 11: CRI
Mục tiêu: Kết nối kubelet ↔ runtime.
Lý thuyết: Container Runtime Interface (RuntimeService, ImageService), gRPC.
Thực hành:
crictlthao tác pod/container qua CRI.
Ngày 12: CRI-O
Mục tiêu: Runtime chuyên cho k8s.
Lý thuyết: CRI-O tối giản, chỉ phục vụ Kubernetes.
Thực hành: Đối chiếu CRI-O vs containerd.
Ngày 13: BuildKit
Mục tiêu: Build image hiện đại.
Lý thuyết: LLB, cache, frontend (Dockerfile), rootless build.
Thực hành: Build image bằng BuildKit; quan sát cache layers.
Ngày 14: Rootless containers
Mục tiêu: Container không cần root.
Lý thuyết: user namespace mapping (nối Layer 2), subuid/subgid.
Thực hành: Chạy rootless container; kiểm tra UID map.
Ngày 15: Image layers & overlayfs
Mục tiêu: Hiểu chia sẻ tầng.
Lý thuyết: overlayfs (nối Layer 3), copy-up, dedup layer.
Thực hành: Đo tiết kiệm dung lượng khi share base layer.
Ngày 16: Registry vận hành
Mục tiêu: Registry production.
Lý thuyết: Harbor/distribution, mirroring, GC, retention.
Thực hành: Dựng registry + mirror; cấu hình pull-through cache.
Ngày 17: Image signing (preview)
Mục tiêu: Tin cậy image (nối Layer 8).
Lý thuyết: cosign/Sigstore, digest pinning.
Thực hành: Ký + verify một image bằng cosign.
Ngày 18: P1 - runtime-spec compliance
Mục tiêu: Nâng mini container lên OCI.
Lý thuyết: đọc & tuân
config.jsonđầy đủ.Thực hành: Mini runtime parse config.json chuẩn OCI.
Ngày 19: P1 - config parsing
Mục tiêu: Áp cấu hình vào ns/cgroups.
Lý thuyết: map các trường (mounts, caps, seccomp, cgroups) sang syscall.
Thực hành: Áp mounts + caps + seccomp từ config.
Ngày 20: P1 - lifecycle
Mục tiêu: Vòng đời chuẩn.
Lý thuyết: create/start/kill/delete state, state.json.
Thực hành: Cài đủ lifecycle;
runc-compatible CLI subset.
Ngày 21: P1 - hooks
Mục tiêu: Điểm mở rộng.
Lý thuyết: prestart/poststart/poststop hooks.
Thực hành: Thêm hook chạy script; test.
Ngày 22: P1 - pull image
Mục tiêu: Lấy image từ registry.
Lý thuyết: distribution API, resolve manifest + blobs.
Thực hành: Pull một OCI image (không dùng docker).
Ngày 23: P1 - unpack rootfs
Mục tiêu: Từ layers ra rootfs.
Lý thuyết: apply layers qua overlayfs, whiteout.
Thực hành: Unpack image thành rootfs chạy được.
Ngày 24: P1 - CRI shim
Mục tiêu: Nói chuyện được với kubelet.
Lý thuyết: implement subset RuntimeService/ImageService.
Thực hành: CRI shim tối giản;
crictlgọi được.
Ngày 25: CNI - spec
Mục tiêu: Chuẩn mạng container.
Lý thuyết: Container Network Interface, ADD/DEL, IPAM, plugin chain.
Thực hành: Đọc spec + chạy plugin
bridgemẫu.
Ngày 26: CNI - viết plugin
Mục tiêu: Tự cấp mạng cho container.
Lý thuyết: veth + bridge + IPAM (nối Layer 3 netns).
Thực hành: CNI plugin nhỏ: tạo veth, gán IP, route.
Ngày 27: CSI - spec
Mục tiêu: Chuẩn lưu trữ container.
Lý thuyết: Container Storage Interface, controller vs node plugin, volume lifecycle.
Thực hành: Đọc CSI; map sang PV/PVC (Khối B).
Ngày 28: Integrate container + CNI
Mục tiêu: Container có mạng.
Lý thuyết: gọi CNI plugin từ mini runtime.
Thực hành: Container tự viết ping được qua CNI plugin tự viết.
Ngày 29: Test OCI/CRI compliance
Mục tiêu: Kiểm chứng chuẩn.
Lý thuyết: oci runtime-tools, so hành vi với runc.
Thực hành: Chạy test suite; sửa lệch.
Ngày 30: CỘT MỐC 30
Mục tiêu: Chốt container; release P1.
Lý thuyết: Ôn A; kiểm kê: OCI runtime + CRI shim + CNI plugin.
Thực hành: P1 done; đề thi #1 (OCI/CRI/CNI) + tự chấm; blog #43 ("Từ mini container tới một OCI runtime + CRI shim"); tag
layer4-day030; nghỉ nửa ngày. Đã đi 30/210 (14%).
KHỐI B - Kubernetes Core (Ngày 31-66)
Ngày 31: Kiến trúc Kubernetes
Mục tiêu: Bản đồ toàn cluster.
Lý thuyết: control plane (apiserver/etcd/scheduler/controller-manager) + node (kubelet/kube-proxy/runtime).
Thực hành: Vẽ sơ đồ; xác định process trong cụm kind.
Ngày 32: Mô hình API khai báo
Mục tiêu: Tư tưởng cốt lõi k8s.
Lý thuyết: desired vs actual state, reconciliation, declarative.
Thực hành: Apply một manifest; quan sát controller đưa về desired.
Ngày 33: kube-apiserver
Mục tiêu: Cửa ngõ cluster.
Lý thuyết: REST, resources, API groups/versions, serialization.
Thực hành: Gọi API trực tiếp (
kubectl get --raw); duyệt API groups.
Ngày 34: API machinery
Mục tiêu: Watch/list cơ chế.
Lý thuyết: list-watch, resourceVersion, optimistic concurrency, bookmark.
Thực hành: Watch một resource qua raw API; quan sát event stream.
Ngày 35: etcd trong k8s
Mục tiêu: Store nhất quán.
Lý thuyết: Raft (nối Layer 3), MVCC, revision, watch, compaction.
Thực hành:
etcdctlxem key k8s; quan sát revision.
Ngày 36: etcd - vận hành
Mục tiêu: Store bền vững.
Lý thuyết: lease, compaction, defrag, backup/restore (nối Layer 11 DR).
Thực hành: Backup + restore etcd của lab.
Ngày 37: API server - authentication
Mục tiêu: Ai đang gọi.
Lý thuyết: client cert, token, OIDC, service account.
Thực hành: Tạo SA + token; gọi API bằng token đó.
Ngày 38: API server - authorization
Mục tiêu: Được làm gì.
Lý thuyết: RBAC (Role/Binding), Node, ABAC.
Thực hành: Tạo Role least-privilege; kiểm
kubectl auth can-i.
Ngày 39: Admission chain (preview)
Mục tiêu: Chặn/sửa request (nối Khối E).
Lý thuyết: mutating → validating, built-in admission plugins.
Thực hành: Liệt kê admission plugins đang bật.
Ngày 40: kubelet
Mục tiêu: Agent trên node.
Lý thuyết: pod lifecycle, PLEG, sync loop, static pods.
Thực hành: Đọc log kubelet khi tạo pod; theo sync loop.
Ngày 41: kubelet - CRI/CNI/CSI
Mục tiêu: Nối Khối A vào node.
Lý thuyết: kubelet gọi CRI để chạy pod, CNI để nối mạng, CSI để mount.
Thực hành: Trace một pod: kubelet → CRI → runtime.
Ngày 42: kube-proxy & eBPF
Mục tiêu: Hiện thực Service.
Lý thuyết: iptables vs IPVS vs eBPF (Cilium, nối Layer 2), DNAT tới pod.
Thực hành: Xem rule kube-proxy; so mode iptables vs IPVS.
Ngày 43: Service & Endpoints
Mục tiêu: Trừu tượng kết nối.
Lý thuyết: Service, Endpoints, EndpointSlice, selector.
Thực hành: Tạo Service; quan sát EndpointSlice cập nhật khi scale.
Ngày 44: DNS trong cluster
Mục tiêu: Service discovery nội bộ.
Lý thuyết: CoreDNS (nối Layer 3), service/pod DNS records.
Thực hành: Resolve service DNS từ pod; đọc Corefile.
Ngày 45: kube-scheduler
Mục tiêu: Đặt pod lên node.
Lý thuyết: kiến trúc scheduler, scheduling cycle.
Thực hành: Quan sát quyết định scheduling qua events.
Ngày 46: Scheduler - filter & score
Mục tiêu: Cách chọn node.
Lý thuyết: filtering (predicates), scoring (priorities).
Thực hành: Ép pod pending bằng resource request lớn; đọc lý do.
Ngày 47: Scheduler framework
Mục tiêu: Mở rộng scheduler.
Lý thuyết: plugins, extension points (PreFilter…Bind).
Thực hành: Đọc một plugin; ý tưởng plugin tuỳ biến.
Ngày 48: Affinity & topology
Mục tiêu: Điều khiển đặt pod.
Lý thuyết: node/pod affinity, taints/tolerations, topology spread.
Thực hành: Dùng anti-affinity + spread cho HA.
Ngày 49: kube-controller-manager
Mục tiêu: Các controller built-in.
Lý thuyết: node/replicaset/deployment/endpoint controllers.
Thực hành: Liệt kê controllers; quan sát một cái hoạt động.
Ngày 50: Control loop
Mục tiêu: Nền của mọi controller.
Lý thuyết: level-triggered reconciliation, observe→diff→act.
Thực hành: Vẽ vòng lặp; đối chiếu với event-driven.
Ngày 51: Deployment chain
Mục tiêu: Chuỗi controller thực tế.
Lý thuyết: Deployment → ReplicaSet → Pod, rollout/rollback.
Thực hành: Rollout + rollback; quan sát ReplicaSet.
Ngày 52: Workload controllers khác
Mục tiêu: Ngoài Deployment.
Lý thuyết: StatefulSet, DaemonSet, Job/CronJob.
Thực hành: Dựng StatefulSet có PVC; quan sát ordering.
Ngày 53: Storage - PV/PVC/CSI
Mục tiêu: Lưu trữ cho pod.
Lý thuyết: PV/PVC/StorageClass, dynamic provisioning, CSI (nối Layer 3).
Thực hành: Provision volume động; mount vào pod.
Ngày 54: Config & Secret
Mục tiêu: Cấu hình workload.
Lý thuyết: ConfigMap/Secret, projected/immutable, mount vs env.
Thực hành: Inject config + secret; kiểm tra reload behavior.
Ngày 55: Pod internals
Mục tiêu: Pod là gì thật sự.
Lý thuyết: pause container, shared ns (net/ipc), lifecycle (nối Layer 2).
Thực hành: Quan sát pause container + shared netns trong pod.
Ngày 56: Init/sidecar/ephemeral
Mục tiêu: Các loại container trong pod.
Lý thuyết: init containers, native sidecar, ephemeral (debug).
Thực hành: Dùng ephemeral container debug pod đang chạy.
Ngày 57: Resource management
Mục tiêu: Chia tài nguyên.
Lý thuyết: requests/limits, QoS class, ánh xạ cgroups v2 (nối Layer 2).
Thực hành: Đặt requests/limits; xem cgroup của pod trên node.
Ngày 58: Pod security
Mục tiêu: Chạy pod an toàn.
Lý thuyết: securityContext, seccomp/AppArmor, Pod Security Admission.
Thực hành: Áp PSA restricted; chặn pod privileged.
Ngày 59: Networking model
Mục tiêu: Mô hình mạng k8s.
Lý thuyết: pod-to-pod flat, ClusterIP/NodePort/LoadBalancer, CNI (Cilium/Calico).
Thực hành: Cài Cilium; quan sát pod networking + NetworkPolicy.
Ngày 60: CỘT MỐC 60
Mục tiêu: Chốt Kubernetes core.
Lý thuyết: Ôn B; kiểm kê: hiểu control plane + node + workloads + networking.
Thực hành: Đề thi #2 (apiserver/etcd/scheduler/kubelet/service) + tự chấm; blog #44 ("Đường đi của một Pod: từ kubectl apply tới container chạy"); tag
layer4-day060; nghỉ nửa ngày. Đã đi 60/210 (29%).
Ngày 61: Ingress vs Gateway API (preview)
Mục tiêu: Vào cluster từ ngoài.
Lý thuyết: Ingress, hạn chế; Gateway API sắp học (Khối G).
Thực hành: Expose app qua Ingress đơn giản.
Ngày 62: Cluster bootstrap
Mục tiêu: Dựng cluster thật.
Lý thuyết: kubeadm, control plane HA, certs, etcd topology.
Thực hành: Bootstrap một cụm HA nhỏ bằng kubeadm.
Ngày 63: kubeconfig & access
Mục tiêu: Truy cập cluster.
Lý thuyết: kubeconfig, context, cluster/user/namespace.
Thực hành: Nhiều context; chuyển đổi an toàn.
Ngày 64: kubectl internals
Mục tiêu: Client hoạt động thế nào.
Lý thuyết: client-go, discovery, REST mapping, server-side apply.
Thực hành: Đọc verbose
kubectl -v=8; theo request.
Ngày 65: Ôn Khối B
Mục tiêu: Khâu control plane thành một luồng.
Lý thuyết: rà đường tạo Pod xuyên apiserver→scheduler→kubelet.
Thực hành: Vẽ end-to-end request flow.
Ngày 66: Chuẩn bị Control Plane Engineering
Mục tiêu: Bắc cầu sang viết controller.
Lý thuyết: vì sao cần hiểu informer/cache trước khi viết operator.
Thực hành: Setup môi trường Go + client-go + controller-runtime.
KHỐI C - Control Plane Engineering (Ngày 67-90)
Ngày 67: Reconciliation loop
Mục tiêu: Trái tim của controller.
Lý thuyết: observe → diff → act, idempotency, eventual consistency.
Thực hành: Viết pseudo-reconcile cho một resource giả định.
Ngày 68: Informer
Mục tiêu: Theo dõi state hiệu quả.
Lý thuyết: watch + local cache + event handlers, giảm tải apiserver.
Thực hành: Chạy một informer in ra add/update/delete.
Ngày 69: SharedInformer & Lister
Mục tiêu: Chia sẻ cache.
Lý thuyết: SharedInformerFactory, Lister, Indexer.
Thực hành: Đọc qua Lister thay vì gọi apiserver trực tiếp.
Ngày 70: Work queue
Mục tiêu: Xử lý event có kiểm soát.
Lý thuyết: rate-limited queue, dedup, retry với backoff.
Thực hành: Cài workqueue; xử lý item + requeue khi lỗi.
Ngày 71: client-go tổng hợp
Mục tiêu: Ghép các mảnh.
Lý thuyết: informer → workqueue → reconcile → apiserver.
Thực hành: Viết một controller thô bằng client-go.
Ngày 72: Controller thô
Mục tiêu: Hiểu tận gốc trước khi dùng framework.
Lý thuyết: vòng đời controller, sync handler.
Thực hành: Hoàn thiện controller đếm/ghi nhãn một resource.
Ngày 73: controller-runtime
Mục tiêu: Framework hiện đại.
Lý thuyết: Manager, Reconciler, Client, cache, scheme.
Thực hành: Viết lại controller trên bằng controller-runtime.
Ngày 74: kubebuilder & Operator SDK
Mục tiêu: Scaffold nhanh.
Lý thuyết: kubebuilder markers, project layout, Operator SDK.
Thực hành: Scaffold một project kubebuilder.
Ngày 75: Reconcile đúng cách
Mục tiêu: Idempotent & bền.
Lý thuyết: requeue, backoff, tránh side-effect kép.
Thực hành: Làm reconcile idempotent; test gọi lặp.
Ngày 76: Owner refs & GC
Mục tiêu: Dọn tài nguyên con.
Lý thuyết: ownerReferences, garbage collection, cascade delete.
Thực hành: Set owner ref; xoá cha → con tự xoá.
Ngày 77: Finalizers
Mục tiêu: Cleanup trước khi xoá.
Lý thuyết: finalizer, deletion timestamp, external cleanup.
Thực hành: Thêm finalizer gọi cleanup ngoài cluster.
Ngày 78: Status & conditions
Mục tiêu: Báo cáo trạng thái.
Lý thuyết: status subresource, conditions, observedGeneration.
Thực hành: Cập nhật status + conditions chuẩn.
Ngày 79: Events
Mục tiêu: Ghi lại điều xảy ra.
Lý thuyết: EventRecorder, reason/message.
Thực hành: Phát event; xem
kubectl describe.
Ngày 80: Leader election
Mục tiêu: Controller HA.
Lý thuyết: lease-based leader election, tránh double-reconcile.
Thực hành: Bật leader election; chạy 2 replica.
Ngày 81: Caching & reads
Mục tiêu: Đọc hiệu quả & đúng.
Lý thuyết: cache-backed client vs direct read, stale cache.
Thực hành: Khi nào cần đọc direct (uncached); thử nghiệm.
Ngày 82: Optimistic concurrency
Mục tiêu: Cập nhật an toàn.
Lý thuyết: resourceVersion conflict, retry-on-conflict, server-side apply.
Thực hành: Gây conflict; xử lý retry.
Ngày 83: Webhooks (tích hợp)
Mục tiêu: Bắc cầu Khối E.
Lý thuyết: admission webhook gắn với controller-runtime.
Thực hành: Scaffold webhook (chưa logic).
Ngày 84: Rate limiting & hiệu năng
Mục tiêu: Controller chịu tải.
Lý thuyết: client rate limit, concurrent reconciles, resync period.
Thực hành: Đo throughput reconcile; tuning.
Ngày 85: Testing controller
Mục tiêu: Kiểm thử tin cậy.
Lý thuyết: envtest (apiserver+etcd giả), fake client.
Thực hành: Viết test reconcile với envtest.
Ngày 86: Observability controller
Mục tiêu: Nhìn thấy controller (nối Layer 7).
Lý thuyết: metrics (reconcile time, queue depth), logs có cấu trúc.
Thực hành: Expose Prometheus metrics từ controller.
Ngày 87: Level vs edge triggered
Mục tiêu: Hiểu lựa chọn thiết kế k8s.
Lý thuyết: vì sao level-triggered bền hơn edge; self-healing.
Thực hành: Mô phỏng mất event; level-triggered vẫn hội tụ.
Ngày 88: Patterns & anti-patterns
Mục tiêu: Viết controller tốt.
Lý thuyết: single source of truth, không lưu state ngoài, idempotency.
Thực hành: Checklist review controller.
Ngày 89: Ôn Khối C
Mục tiêu: Sẵn sàng cho flagship.
Lý thuyết: rà informer/cache/queue/reconcile/finalizer/status.
Thực hành: Chuẩn bị thiết kế Operator.
Ngày 90: CỘT MỐC 90
Mục tiêu: Chốt control plane engineering.
Lý thuyết: Ôn C; kiểm kê: viết được controller đúng chuẩn với controller-runtime.
Thực hành: Đề thi #3 (informer/reconcile/finalizer/status) + tự chấm; blog #45 ("Bên trong một Kubernetes controller: informer, work queue, reconcile"); tag
layer4-day090; nghỉ nửa ngày.
KHỐI D - CRD + Controller + Operator (Ngày 91-124) → P2 flagship
Ngày 91: CRD - nền
Mục tiêu: Mở rộng API k8s.
Lý thuyết: CustomResourceDefinition, custom resource, API group.
Thực hành: Tạo một CRD đơn giản; apply CR.
Ngày 92: CRD - schema
Mục tiêu: Ràng buộc & mặc định.
Lý thuyết: OpenAPI v3 schema, validation, defaulting, x-kubernetes markers.
Thực hành: Thêm validation + default cho CRD.
Ngày 93: CRD - versioning
Mục tiêu: Tiến hoá API.
Lý thuyết: multi-version, storage version, conversion webhook.
Thực hành: Thêm version v1beta1→v1; scaffold conversion.
Ngày 94: CRD - subresources
Mục tiêu: Status & scale.
Lý thuyết: status subresource, scale subresource, printer columns.
Thực hành: Bật /status + /scale + additionalPrinterColumns.
Ngày 95: Operator pattern
Mục tiêu: Khi nào cần operator.
Lý thuyết: encode operational knowledge, day-2 operations.
Thực hành: Liệt kê ứng viên domain cho flagship.
Ngày 96: Thiết kế flagship
Mục tiêu: Đóng khung P2.
Lý thuyết: chọn domain (ví dụ CRD
AppPlatform: app + service + ingress + config).Thực hách:
operator-design.md: API + reconcile model.
Ngày 97: API design
Mục tiêu: Spec/status tốt.
Lý thuyết: declarative spec, status phản ánh thực tế, conditions.
Thực hành: Định nghĩa types Go cho CRD.
Ngày 98: Scaffold
Mục tiêu: Khung code.
Lý thuyết: kubebuilder generate CRD + controller skeleton.
Thực hành: Scaffold + apply CRD lên cluster.
Ngày 99: API types
Mục tiêu: Hoàn thiện spec/status.
Lý thuyết: markers cho validation/default/printcolumn.
Thực hành: Cài đầy đủ types + generate manifests.
Ngày 100:
Mục tiêu: Kiểm kê lớn giữa Layer 4.
Lý thuyết: Ôn A→C + đầu D; kiểm kê lớn: OCI runtime + hiểu control plane + viết controller + CRD; đối chiếu "Sâu".
Thực hành: Đề thi #4 tích lũy (container + core + control plane) + tự chấm theo rubric; blog #46 ("100 ngày cloud-native: từ OCI runtime tới CRD đầu tiên"); tag
layer4-day100; nghỉ nửa ngày. Đã đi 100/210 (48%).
Ngày 101: Reconcile v1
Mục tiêu: Tạo tài nguyên con.
Lý thuyết: từ CR → Deployment/Service/ConfigMap.
Thực hành: Reconcile tạo child resources.
Ngày 102: Reconcile - idempotency & owner
Mục tiêu: An toàn khi lặp.
Lý thuyết: create-or-update, owner refs, server-side apply.
Thực hành: Đảm bảo reconcile lặp không đổi kết quả.
Ngày 103: Status & conditions
Mục tiêu: CR báo cáo trạng thái.
Lý thuyết: aggregate trạng thái con → status CR.
Thực hành: Cập nhật Ready/Progressing conditions.
Ngày 104: Finalizers & cleanup
Mục tiêu: Xoá sạch.
Lý thuyết: finalizer, xoá tài nguyên ngoài scope owner-ref.
Thực hành: Thêm finalizer + cleanup logic.
Ngày 105: Validation/defaulting webhook
Mục tiêu: Chặn cấu hình sai.
Lý thuyết: validating/mutating webhook cho CRD.
Thực hành: Cài webhook validate + default cho AppPlatform.
Ngày 106: Conversion webhook
Mục tiêu: Multi-version thật.
Lý thuyết: convert giữa versions, hub-and-spoke.
Thực hành: Cài conversion v1beta1↔v1.
Ngày 107: Xử lý drift
Mục tiêu: Tự chữa.
Lý thuyết: phát hiện thay đổi ngoài ý muốn, reconcile về desired.
Thực hành: Sửa tay child resource; operator kéo về.
Ngày 108: Tích hợp hệ ngoài
Mục tiêu: Operator điều khiển ngoài cluster.
Lý thuyết: gọi API ngoài (preview Crossplane), lưu state ở đâu.
Thực hành: Reconcile gọi một API giả lập bên ngoài.
Ngày 109: Error & requeue
Mục tiêu: Bền với lỗi.
Lý thuyết: phân loại lỗi, backoff, requeueAfter.
Thực hành: Chiến lược requeue theo loại lỗi.
Ngày 110: Observability operator
Mục tiêu: Nhìn thấy operator (nối Layer 7).
Lý thuyết: metrics, events, structured logs.
Thực hành: Thêm metrics reconcile + events.
Ngày 111: Testing - envtest
Mục tiêu: Test logic reconcile.
Lý thuyết: envtest, giả lập apiserver.
Thực hành: Test các nhánh reconcile.
Ngày 112: E2E test
Mục tiêu: Chạy thật.
Lý thuyết: test trên kind, apply CR → kiểm child + status.
Thực hành: E2E test trong CI.
Ngày 113: Upgrade & migration
Mục tiêu: Nâng cấp an toàn.
Lý thuyết: CRD migration, storage version bump.
Thực hành: Migrate CR sang version mới.
Ngày 114: OLM
Mục tiêu: Vòng đời operator.
Lý thuyết: Operator Lifecycle Manager, bundle, catalog.
Thực hành: Đóng gói operator theo OLM (khái niệm + thử).
Ngày 115: Packaging
Mục tiêu: Phân phối operator.
Lý thuyết: Helm chart / kustomize cho CRD + controller + RBAC.
Thực hành: Đóng gói cài đặt bằng Helm.
Ngày 116: RBAC least-privilege
Mục tiêu: Operator an toàn.
Lý thuyết: quyền tối thiểu cho controller.
Thực hành: Rà + siết ClusterRole của operator.
Ngày 117: Multi-tenancy cho operator
Mục tiêu: Chạy chung an toàn.
Lý thuyết: namespace-scoped vs cluster-scoped, isolation.
Thực hành: Cấu hình operator theo tenant model.
Ngày 118: Hiệu năng quy mô lớn
Mục tiêu: Nhiều CR.
Lý thuyết: concurrent reconciles, cache pressure, resync.
Thực hành: Load test với nhiều CR; tuning.
Ngày 119: Hardening
Mục tiêu: Chuẩn bảo mật (nối Layer 8).
Lý thuyết: webhook TLS, image, supply chain.
Thực hành: Rà bảo mật operator.
Ngày 120: CỘT MỐC 120
Mục tiêu: Chốt phần chính operator.
Lý thuyết: Ôn D; kiểm kê: CRD + reconcile + webhook + finalizer + status hoàn chỉnh.
Thực hành: Đề thi #5 (CRD/operator/webhook) + tự chấm; blog #47 ("Thiết kế một Operator: CRD, reconcile, finalizer, webhook"); tag
layer4-day120; nghỉ nửa ngày. Đã đi 120/210 (57%).
Ngày 121: Hoàn thiện tính năng
Mục tiêu: Operator đủ dùng.
Lý thuyết: rà use case còn thiếu.
Thực hành: Bổ sung tính năng còn thiếu.
Ngày 122: Docs & examples
Mục tiêu: Dùng lại được.
Lý thuyết: README, API reference, ví dụ CR.
Thực hành: Viết docs + samples.
Ngày 123: Benchmark & chaos
Mục tiêu: Bền vững (nối Layer 11).
Lý thuyết: kill controller giữa reconcile, đảm bảo hội tụ.
Thực hành: Chaos test; xác nhận self-healing.
Ngày 124: P2 - Kubernetes Operator hoàn chỉnh
Mục tiêu: Release flagship.
Lý thuyết: rà "done": CRD + controller + webhook + tests + packaging.
Thực hành: Đóng gói + blog #48 ("Một Operator hoàn chỉnh từ số 0"). P2 done.
KHỐI E - Admission Control + Autoscaling (Ngày 125-150) → P3
Ngày 125: Admission control deep
Mục tiêu: Chặn/sửa ở apiserver.
Lý thuyết: mutating trước, validating sau, admission chain.
Thực hành: Vẽ vòng đời request qua admission.
Ngày 126: Validating webhook
Mục tiêu: Từ chối cấu hình xấu.
Lý thuyết: ValidatingWebhookConfiguration, review request/response.
Thực hành: Webhook từ chối pod thiếu label bắt buộc.
Ngày 127: Mutating webhook
Mục tiêu: Tự sửa/inject.
Lý thuyết: patch (JSONPatch), inject sidecar-style.
Thực hành: Webhook inject default resources/labels.
Ngày 128: Webhook vận hành
Mục tiêu: Không làm sập cluster.
Lý thuyết: failurePolicy, timeout, ordering, side effects, namespaceSelector.
Thực hành: Cấu hình fail-open/closed đúng chỗ; tránh self-lockout.
Ngày 129: OPA/Gatekeeper
Mục tiêu: Policy engine.
Lý thuyết: Rego, ConstraintTemplate, Constraint, audit.
Thực hành: Viết constraint cấm image latest.
Ngày 130: Gatekeeper - audit & mở rộng
Mục tiêu: Policy toàn cluster.
Lý thuyết: audit mode, mutation (Gatekeeper), external data.
Thực hành: Audit vi phạm hiện có; báo cáo.
Ngày 131: Kyverno
Mục tiêu: Policy kiểu k8s-native.
Lý thuyết: policy là CRD, validate/mutate/generate, không cần Rego.
Thực hành: Kyverno policy validate + generate (ví dụ default NetworkPolicy).
Ngày 132: So sánh policy
Mục tiêu: Chọn công cụ.
Lý thuyết: Gatekeeper vs Kyverno vs webhook thủ công.
Thực hành: Bảng đánh đổi.
Ngày 133: Policy as code
Mục tiêu: Quản trị nhất quán.
Lý thuyết: validate/mutate/generate patterns, test policy.
Thực hành: Viết test cho policy.
Ngày 134: P3 - thiết kế
Mục tiêu: Đóng khung P3.
Lý thuyết: policy controller (webhook + bộ policy) cho platform.
Thực hành:
policy-controller-design.md.
Ngày 135: P3 - validating rules
Mục tiêu: Chặn cấu hình nguy hiểm.
Lý thuyết: rule chặn privileged, hostPath, image không ký (nối Layer 8).
Thực hành: Cài + test validating rules.
Ngày 136: P3 - mutating rules
Mục tiêu: Áp default an toàn.
Lý thuyết: inject securityContext, resource defaults, labels.
Thực hành: Cài + test mutating rules.
Ngày 137: P3 - audit & report
Mục tiêu: Nhìn được vi phạm.
Lý thuyết: audit mode, PolicyReport.
Thực hành: Sinh report; dashboard đơn giản (nối Layer 7).
Ngày 138: P3 - test & package
Mục tiêu: Sẵn sàng release.
Lý thuyết: test coverage policy, packaging.
Thực hành: Đóng gói P3 (finalize ở mốc 150).
Ngày 139: Autoscaling - tổng quan
Mục tiêu: Ba trục co giãn.
Lý thuyết: horizontal (pod) vs vertical (pod) vs cluster (node).
Thực hành: Bản đồ khi nào dùng cái nào.
Ngày 140: HPA
Mục tiêu: Co giãn theo tải.
Lý thuyết: metrics, thuật toán, custom/external metrics.
Thực hành: HPA theo CPU + custom metric.
Ngày 141: Metrics pipeline
Mục tiêu: Nguồn metric cho HPA.
Lý thuyết: metrics-server, custom metrics API, Prometheus adapter (nối Layer 7).
Thực hành: Dựng Prometheus adapter cho custom metric.
Ngày 142: VPA
Mục tiêu: Chỉnh requests tự động.
Lý thuyết: recommend/auto mode, hạn chế (restart), xung đột HPA.
Thực hành: VPA recommend cho một workload.
Ngày 143: Cluster Autoscaler
Mục tiêu: Co giãn node.
Lý thuyết: scale-up theo pending pod, scale-down an toàn.
Thực hành: CA trên cluster có pending pods.
Ngày 144: Karpenter
Mục tiêu: Provisioning node hiện đại.
Lý thuyết: just-in-time nodes, consolidation, NodePool.
Thực hành: So Karpenter vs Cluster Autoscaler.
Ngày 145: KEDA
Mục tiêu: Event-driven scaling.
Lý thuyết: scaler (Kafka/queue), scale-to-zero.
Thực hành: KEDA scale theo độ dài queue.
Ngày 146: Tương tác & bẫy
Mục tiêu: Tránh xung đột.
Lý thuyết: HPA+VPA conflict, thrashing, stabilization window.
Thực hành: Thiết kế autoscaling ổn định.
Ngày 147: Capacity & cost
Mục tiêu: Co giãn có kinh tế (nối Layer 11).
Lý thuyết: bin-packing, spot, overprovision, FinOps preview.
Thực hành: Ước lượng cost khi scale.
Ngày 148: Lab autoscaling E2E
Mục tiêu: Ghép lại.
Lý thuyết: HPA + Karpenter/CA cùng hoạt động.
Thực hành: Load test → pod scale → node scale; quan sát.
Ngày 149: Ôn Khối E; P3 finalize
Mục tiêu: Chốt admission + autoscaling.
Lý thuyết: rà webhook/policy + HPA/VPA/CA/Karpenter/KEDA.
Thực hành: Hoàn thiện + test P3.
Ngày 150: CỘT MỐC 150
Mục tiêu: Chốt policy & co giãn; release P3.
Lý thuyết: Ôn E; kiểm kê: policy controller + autoscaling stack.
Thực hành: P3 done; đề thi #6 (admission/policy/autoscaling) + tự chấm; blog #49 ("Policy-as-code và autoscaling trong Kubernetes"); tag
layer4-day150; nghỉ nửa ngày. Đã đi 150/210 (71%).
KHỐI F - Service Mesh + xDS (Ngày 151-178) → P4
Ngày 151: Service mesh - vì sao
Mục tiêu: Bài toán mesh giải quyết.
Lý thuyết: mTLS, traffic mgmt, observability tách khỏi app; sidecar model.
Thực hành: Liệt kê cross-cutting concerns mesh xử lý.
Ngày 152: Data plane vs control plane
Mục tiêu: Hai mặt của mesh.
Lý thuyết: proxy (data) + control (config/policy), tách biệt.
Thực hành: Vẽ kiến trúc mesh.
Ngày 153: Envoy - kiến trúc
Mục tiêu: Proxy nền tảng.
Lý thuyết: listeners, routes, clusters, endpoints, filters.
Thực hành: Chạy Envoy config tĩnh; proxy một service.
Ngày 154: Envoy - filter chain
Mục tiêu: Xử lý request.
Lý thuyết: HTTP connection manager, filter chain, retry/timeout.
Thực hành: Thêm filter (header manipulation, rate limit local).
Ngày 155: Envoy tĩnh → động
Mục tiêu: Vì sao cần xDS.
Lý thuyết: hạn chế config tĩnh, cần cập nhật động.
Thực hành: Chuyển một phần config sang dynamic.
Ngày 156: xDS overview
Mục tiêu: Giao thức cấu hình Envoy.
Lý thuyết: LDS/RDS/CDS/EDS, discovery services.
Thực hành: Map từng xDS sang thành phần Envoy.
Ngày 157: ADS
Mục tiêu: Cấu hình nhất quán.
Lý thuyết: aggregated xDS, ordering, tránh traffic drop.
Thực hành: Đọc luồng ADS; hiểu thứ tự cập nhật.
Ngày 158: SDS & delta xDS
Mục tiêu: Secret & hiệu quả.
Lý thuyết: SDS (cert cho mTLS), delta (incremental) xDS.
Thực hành: Cấp cert qua SDS.
Ngày 159: xDS protocol
Mục tiêu: Cơ chế truyền.
Lý thuyết: gRPC streaming, version/nonce, ACK/NACK.
Thực hành: Bắt gRPC stream giữa Envoy và control plane.
Ngày 160: P4 - xDS control plane (nền)
Mục tiêu: Bắt đầu P4.
Lý thuyết: go-control-plane, snapshot cache.
Thực hành: Control plane phục vụ Envoy một cấu hình tối giản.
Ngày 161: P4 - CDS/EDS
Mục tiêu: Cluster & endpoint động.
Lý thuyết: khai báo cluster + endpoints từ nguồn (k8s Service).
Thực hành: Đẩy CDS/EDS; Envoy route tới backend.
Ngày 162: P4 - LDS/RDS
Mục tiêu: Listener & routing động.
Lý thuyết: listener + route config động.
Thực hành: Định tuyến theo path/host qua RDS.
Ngày 163: P4 - cập nhật động
Mục tiêu: Zero-drop reconfig.
Lý thuyết: snapshot versioning, watch nguồn (informer, nối Khối C).
Thực hành: Thay đổi backend → Envoy cập nhật không rớt kết nối.
Ngày 164: Istio - kiến trúc
Mục tiêu: Mesh sản xuất.
Lý thuyết: istiod, sidecar injection, xDS phía sau.
Thực hành: Cài Istio; inject sidecar cho một app.
Ngày 165: Istio - traffic management
Mục tiêu: Điều khiển lưu lượng.
Lý thuyết: VirtualService, DestinationRule, subset.
Thực hành: Route theo header/weight.
Ngày 166: Istio - security
Mục tiêu: mTLS & policy.
Lý thuyết: PeerAuthentication (mTLS), AuthorizationPolicy.
Thực hành: Bật mTLS strict; áp authz.
Ngày 167: Istio ambient mesh
Mục tiêu: Mesh không sidecar.
Lý thuyết: ztunnel (L4) + waypoint (L7), tiết kiệm tài nguyên.
Thực hành: Thử ambient mode; so với sidecar.
Ngày 168: Sidecar vs ambient
Mục tiêu: Chọn mô hình.
Lý thuyết: overhead, độ trễ, vận hành.
Thực hành: Bảng đánh đổi.
Ngày 169: Observability mesh
Mục tiêu: Nhìn thấy traffic (nối Layer 7).
Lý thuyết: telemetry, distributed tracing, golden signals.
Thực hành: Xem traces/metrics từ mesh.
Ngày 170: Resilience trong mesh
Mục tiêu: Chịu lỗi.
Lý thuyết: retry, timeout, circuit breaking, outlier detection.
Thực hành: Cấu hình + mô phỏng backend lỗi.
Ngày 171: Traffic shifting
Mục tiêu: Canary qua mesh (nối Layer 6).
Lý thuyết: weighted routing, progressive shift.
Thực hành: Canary 5%→100% một version.
Ngày 172: Multi-cluster mesh (preview)
Mục tiêu: Mesh xuyên cluster.
Lý thuyết: east-west gateway, shared trust.
Thực hành: Đọc kiến trúc multi-cluster mesh.
Ngày 173: eBPF-based mesh
Mục tiêu: Mesh sidecarless kiểu khác.
Lý thuyết: Cilium service mesh, eBPF datapath (nối Layer 2).
Thực hành: So mô hình eBPF vs Envoy sidecar.
Ngày 174: P4 - điều khiển Envoy fleet
Mục tiêu: Control plane thực dụng.
Lý thuyết: nhiều Envoy, per-node/per-workload config.
Thực hành: Control plane phục vụ nhiều Envoy.
Ngày 175: P4 - mTLS qua SDS
Mục tiêu: Bảo mật kết nối.
Lý thuyết: cấp/rotate cert qua SDS.
Thực hành: Bật mTLS giữa các Envoy do control plane cấp.
Ngày 176: P4 - dynamic routing/canary
Mục tiêu: Ứng dụng thật.
Lý thuyết: weighted route động từ control plane.
Thực hành: Canary điều khiển từ control plane.
Ngày 177: P4 - test & benchmark
Mục tiêu: Đảm bảo tin cậy.
Lý thuyết: đo latency thêm vào, zero-drop khi reconfig.
Thực hành: Benchmark + chaos reconfig.
Ngày 178: P4 - xDS control plane
Mục tiêu: Release P4.
Lý thuyết: rà "done": LDS/RDS/CDS/EDS + SDS + dynamic update.
Thực hành: Writeup + blog #50 ("Tự viết một control plane xDS điều khiển Envoy"). P4 done.
KHỐI G - API Gateway (Ngày 179-190)
Ngày 179: Gateway vs Ingress vs Mesh
Mục tiêu: Định vị API gateway.
Lý thuyết: north-south (gateway) vs east-west (mesh), Ingress cũ.
Thực hành: Sơ đồ vị trí gateway trong kiến trúc.
Ngày 180: CỘT MỐC 180
Mục tiêu: Chốt mesh; vào gateway.
Lý thuyết: Ôn F; kiểm kê: xDS control plane + hiểu Istio/ambient.
Thực hành: Đề thi #7 (Envoy/xDS/Istio) + tự chấm; blog #51 ("Service mesh và xDS: điều khiển hàng nghìn proxy"); tag
layer4-day180; nghỉ nửa ngày.
Ngày 181: Vì sao Gateway API
Mục tiêu: Kế thừa Ingress.
Lý thuyết: hạn chế Ingress, role-oriented, mở rộng.
Thực hành: Đọc spec Gateway API.
Ngày 182: Gateway API - tài nguyên
Mục tiêu: Mô hình mới.
Lý thuyết: GatewayClass, Gateway, HTTPRoute, TCPRoute.
Thực hành: Expose app qua Gateway + HTTPRoute.
Ngày 183: Gateway API - role & GAMMA
Mục tiêu: Phân vai infra/app + mesh.
Lý thuyết: infra provider vs app dev; GAMMA (mesh dùng Gateway API).
Thực hành: Tách quyền GatewayClass vs HTTPRoute.
Ngày 184: Envoy Gateway
Mục tiêu: Gateway API trên Envoy.
Lý thuyết: Envoy Gateway = Gateway API + Envoy + xDS (nối P4).
Thực hành: Cài Envoy Gateway; route một app.
Ngày 185: Kong
Mục tiêu: Gateway plugin-rich.
Lý thuyết: plugin architecture, DB-less, Kong Ingress Controller.
Thực hành: Cấu hình auth + rate limit plugin.
Ngày 186: APISIX
Mục tiêu: Gateway động.
Lý thuyết: dynamic routing, plugins, etcd-backed.
Thực hành: So APISIX với Kong/Envoy Gateway.
Ngày 187: Tính năng gateway
Mục tiêu: Chức năng thường dùng.
Lý thuyết: rate limit, auth (JWT/OIDC), transformation, WAF.
Thực hành: Áp một chuỗi policy tại gateway.
Ngày 188: TLS & cert
Mục tiêu: Vào bằng HTTPS.
Lý thuyết: cert-manager, ACME, TLS termination/passthrough.
Thực hành: cert-manager cấp cert tự động cho Gateway.
Ngày 189: Lab gateway E2E
Mục tiêu: Ghép lại.
Lý thuyết: Gateway API + policy + TLS.
Thực hành: Expose app đầy đủ auth + rate limit + TLS.
Ngày 190: So sánh gateways
Mục tiêu: Chọn đúng.
Lý thuyết: Envoy Gateway vs Kong vs APISIX theo bối cảnh.
Thực hành: Ma trận quyết định.
KHỐI H - Platform Abstractions + Multi-tenancy (Ngày 191-200)
Ngày 191: Trừu tượng trên k8s
Mục tiêu: Vì sao cần lớp platform.
Lý thuyết: k8s là "platform for platforms", self-service.
Thực hành: Liệt kê thứ cần trừu tượng cho dev.
Ngày 192: Crossplane - nền
Mục tiêu: Control plane cho hạ tầng.
Lý thuyết: XRD, Composition, Composite Resource, providers.
Thực hành: Cài Crossplane; định nghĩa một XRD.
Ngày 193: Crossplane - managed resources
Mục tiêu: Điều khiển cloud từ k8s (nối Layer 5).
Lý thuyết: provider AWS/GCP, managed resource reconcile.
Thực hành: Provision một tài nguyên (mock/local) qua Crossplane.
Ngày 194: Crossplane - compose platform API
Mục tiêu: Self-service infra.
Lý thuyết: compose nhiều managed resource thành một API cấp cao.
Thực hành: Tạo
DatabaseXR self-service.
Ngày 195: KCP
Mục tiêu: Control plane tách cluster.
Lý thuyết: workspaces, transparent multi-cluster, API export.
Thực hành: Đọc kiến trúc KCP; use case.
Ngày 196: Mô hình multi-tenancy
Mục tiêu: Chạy nhiều tenant.
Lý thuyết: namespace vs cluster vs virtual cluster; soft vs hard isolation.
Thực hành: Bảng đánh đổi các mô hình.
Ngày 197: vcluster
Mục tiêu: Virtual cluster.
Lý thuyết: control plane ảo trong namespace, isolation mạnh hơn namespace.
Thực hành: Dựng vcluster cho một tenant.
Ngày 198: Capsule & HNC
Mục tiêu: Multi-tenancy nhẹ.
Lý thuyết: Capsule (tenant), Hierarchical Namespaces.
Thực hành: Dựng tenant với HNC; quan sát policy propagation.
Ngày 199: Tenant isolation
Mục tiêu: Cách ly thật (nối Layer 8).
Lý thuyết: RBAC + NetworkPolicy + ResourceQuota + PSA + node isolation.
Thực hành: Áp bộ isolation đầy đủ cho một tenant.
Ngày 200:
Mục tiêu: Kiểm kê lớn cận cuối Layer 4.
Lý thuyết: Ôn A→H; kiểm kê lớn: OCI runtime + operator + policy + xDS + gateway + platform abstractions; đối chiếu "Sâu".
Thực hành: Đề thi #8 tích lũy (toàn cloud-native) + tự chấm theo rubric; blog #52 ("200 ngày cloud-native: container, operator, mesh, platform"); tag
layer4-day200; nghỉ nửa ngày. Đã đi 200/210 (95%).
KHỐI I - GitOps + Multi-cluster (Ngày 201-210) → P5 platform capstone
Ngày 201: GitOps - nguyên lý
Mục tiêu: Git là nguồn sự thật.
Lý thuyết: declarative + Git + pull-based reconcile + drift detection.
Thực hành: Sơ đồ vòng GitOps.
Ngày 202: ArgoCD
Mục tiêu: GitOps phổ biến.
Lý thuyết: Application, sync, app-of-apps, ApplicationSet.
Thực hành: Triển khai app qua ArgoCD từ Git.
Ngày 203: Flux
Mục tiêu: GitOps kiểu controller.
Lý thuyết: source/kustomize/helm controllers, image automation.
Thực hành: Triển khai app qua Flux; image update tự động.
Ngày 204: ArgoCD vs Flux + progressive delivery
Mục tiêu: Chọn & nối Layer 6.
Lý thuyết: so sánh; Argo Rollouts/Flagger (canary, nối Layer 6).
Thực hành: Canary qua GitOps (preview).
Ngày 205: Multi-cluster - Cluster API
Mục tiêu: Cluster như tài nguyên (nối Metal³ Layer 3).
Lý thuyết: Cluster API, declarative cluster lifecycle.
Thực hách: Đọc kiến trúc CAPI; tạo cluster khai báo (mock).
Ngày 206: Multi-cluster - fleet
Mục tiêu: Quản lý nhiều cluster.
Lý thuyết: Karmada/Open Cluster Management, federation, placement.
Thực hành: Đọc mô hình fleet; deploy tới nhiều cluster (khái niệm/lab nhỏ).
Ngày 207: P5 - tích hợp platform
Mục tiêu: Ghép tất cả thành một platform.
Lý thuyết: operator (P2) + Gateway API + GitOps + multi-tenancy.
Thực hành: Dựng platform: dev apply CR → operator tạo app + expose + policy.
Ngày 208: P5 - golden path self-service
Mục tiêu: Trải nghiệm dev (preview Layer 6 IDP).
Lý thuyết: self-service qua CR/Git, guardrails bằng policy.
Thực hành: Một golden path: từ Git → app chạy, có mesh + gateway + policy.
Ngày 209: P5 - E2E & docs; ôn Layer 4
Mục tiêu: Hoàn thiện.
Lý thuyết: rà toàn platform + docs.
Thực hành: E2E test platform; viết docs/RFC (nối Layer 6).
Ngày 210: HOÀN THÀNH LAYER 4
Mục tiêu: Chốt Cloud Native Engineering ở mức Sâu.
Lý thuyết: Ôn toàn layer; kiểm kê tổng: P1 OCI/CRI runtime + P2 Operator + P3 policy controller + P4 xDS control plane + P5 Kubernetes Platform.
Thực hành: P5 done; đề thi #9 tích lũy (toàn layer) + tự chấm theo rubric; blog #53 ("Nhìn lại 210 ngày cloud-native: tự xây một Kubernetes Platform"); tag
layer4-complete; nghỉ nửa ngày
LAYER 5 - CLOUD PLATFORM ENGINEERING
Tài nguyên: AWS Well-Architected, docs AWS/Azure/GCP, Terraform: Up & Running (Brikman), HashiCorp Vault/Boundary docs, BeyondCorp papers, CIS Benchmarks.
KHỐI A - Public Cloud Core (Ngày 1-36)
Ngày 1: Khởi động Layer 5
Mục tiêu: Đặt khung tư duy cloud + lab an toàn.
Lý thuyết: shared responsibility model, region/AZ, control plane vs data plane của cloud.
Thực hành: Repo
cloud-platform/; tạo tài khoản sandbox + billing alert.
Ngày 2: Mô hình tài khoản & tổ chức
Mục tiêu: Ranh giới quản trị.
Lý thuyết: AWS Account/Organizations/OU · Azure Subscription/Management Group · GCP Project/Folder/Org.
Thực hành: Vẽ cây tổ chức mục tiêu cho doanh nghiệp giả định.
Ngày 3: IAM - nguyên lý
Mục tiêu: Nền của mọi thứ trong cloud.
Lý thuyết: principal, policy, permission, resource; deny-by-default.
Thực hành: Đọc một IAM policy JSON; giải thích từng phần.
Ngày 4: AWS IAM (vừa đủ)
Mục tiêu: Mô hình IAM chuẩn.
Lý thuyết: user/role/policy, STS assume-role, permission boundary, trust policy.
Thực hành: Tạo role + trust policy; assume-role bằng STS.
Ngày 5: IAM - policy evaluation
Mục tiêu: Vì sao được/không được.
Lý thuyết: thứ tự đánh giá (explicit deny > allow), SCP, resource policy, session policy.
Thực hành: Debug một "access denied" bằng policy simulator.
Ngày 6: IAM cross-cloud
Mục tiêu: Nắm mô hình chung.
Lý thuyết: Azure RBAC + Entra ID · GCP IAM (role binding, predefined/custom).
Thực hành: Bảng ánh xạ khái niệm IAM giữa 3 cloud.
Ngày 7: Identity federation
Mục tiêu: Đăng nhập tập trung.
Lý thuyết: SAML/OIDC federation, SSO, IAM Identity Center, workload identity federation.
Thực hành: Cấu hình OIDC federation (ví dụ CI → cloud không cần key dài hạn).
Ngày 8: Compute - máy ảo
Mục tiêu: Đơn vị compute cơ bản.
Lý thuyết: EC2/VM/Compute Engine, instance type, spot/preemptible, autoscaling group.
Thực hành: Dựng một VM + user-data; ghi chú spot vs on-demand.
Ngày 9: Compute - image & lifecycle
Mục tiêu: Máy chuẩn hoá.
Lý thuyết: AMI/image, golden image, immutable infra (preview Packer).
Thực hành: Tạo custom image; boot từ image đó.
Ngày 10: Storage - object
Mục tiêu: Lưu trữ chủ đạo cloud (nối Layer 3).
Lý thuyết: S3/Blob/GCS, class, lifecycle, versioning, consistency.
Thực hành: Bucket + lifecycle + versioning; policy truy cập.
Ngày 11: Storage - block & file
Mục tiêu: Lưu trữ gắn máy.
Lý thuyết: EBS/Managed Disk/PD, snapshot; EFS/Filestore.
Thực hành: Gắn volume + snapshot + restore.
Ngày 12: Managed database
Mục tiêu: DB không tự vận hành (nối Layer 3 internals).
Lý thuyết: RDS/Aurora, Cloud SQL, Cosmos/DynamoDB, backup, read replica.
Thực hành: Dựng managed Postgres; test failover/backup.
Ngày 13: Messaging & queue
Mục tiêu: Ghép hệ phân tán.
Lý thuyết: SQS/SNS, Pub/Sub, Event Grid, at-least-once semantics.
Thực hành: Queue + consumer; quan sát retry/DLQ.
Ngày 14: Managed Kubernetes
Mục tiêu: K8s trên cloud (nối Layer 4).
Lý thuyết: EKS/AKS/GKE, node pool, control plane managed, IAM ↔ RBAC (IRSA/Workload Identity).
Thực hành: Dựng cluster managed; map cloud identity → pod.
Ngày 15: Observability của cloud
Mục tiêu: Nhìn thấy tài nguyên (nối Layer 7).
Lý thuyết: CloudWatch/Monitor/Cloud Logging, metrics/logs/alarms.
Thực hành: Dashboard + alarm cho một service.
Ngày 16: Cost model
Mục tiêu: Hiểu tiền (nối Layer 11 FinOps).
Lý thuyết: on-demand/reserved/savings plan/spot, egress cost, tagging cho cost.
Thực hành: Đọc cost explorer; ước tính chi phí một kiến trúc.
Ngày 17: Region & data residency
Mục tiêu: Chọn nơi đặt.
Lý thuyết: latency, sovereignty/compliance, multi-region tradeoff.
Thực hành: Quyết định region cho use case giả định.
Ngày 18: Encryption & KMS
Mục tiêu: Mã hoá dữ liệu (nối Layer 8).
Lý thuyết: KMS/Key Vault/Cloud KMS, envelope encryption, CMK vs managed key.
Thực hành: Tạo CMK; mã hoá bucket/volume bằng CMK.
Ngày 19: Tagging & resource organization
Mục tiêu: Quản lý ở quy mô.
Lý thuyết: tag strategy, resource group, naming convention.
Thực hành: Chuẩn tag (owner/env/cost-center) áp cho tài nguyên.
Ngày 20: Service quotas & limits
Mục tiêu: Tránh bất ngờ vận hành.
Lý thuyết: quota, throttling, request increase.
Thực hành: Kiểm quota quan trọng; xin tăng (khái niệm).
Ngày 21: CLI & SDK
Mục tiêu: Tự động hoá tay.
Lý thuyết: aws/az/gcloud CLI, SDK, credential chain.
Thực hành: Script hoá một tác vụ bằng CLI.
Ngày 22: Billing & account hygiene
Mục tiêu: Tài khoản sạch, an toàn.
Lý thuyết: root account, MFA, budget, break-glass.
Thực hành: Bật MFA root, tạo budget, tách admin khỏi root.
Ngày 23: Well-Architected Framework
Mục tiêu: Khung đánh giá kiến trúc.
Lý thuyết: 6 trụ (operational/security/reliability/performance/cost/sustainability).
Thực hành: Review một kiến trúc theo 6 trụ.
Ngày 24: AWS core tổng hợp
Mục tiêu: Ghép dịch vụ AWS.
Lý thuyết: map compute/storage/db/network/iam thành một app 3 lớp.
Thực hành: Vẽ + dựng tay một web app 3 lớp.
Ngày 25: Azure core (đối chiếu)
Mục tiêu: Nắm khác biệt Azure.
Lý thuyết: Resource Manager, Management Group, Entra ID, VNet, Azure Policy.
Thực hành: Dựng tương đương app 3 lớp trên Azure (khái niệm/lab nhỏ).
Ngày 26: GCP core (đối chiếu)
Mục tiêu: Nắm khác biệt GCP.
Lý thuyết: project/folder/org, VPC global, IAM, Org Policy.
Thực hành: Dựng tương đương trên GCP (khái niệm/lab nhỏ).
Ngày 27: So sánh 3 cloud
Mục tiêu: Chọn cloud/multi-cloud.
Lý thuyết: mô hình mạng, IAM, quản trị tổ chức khác nhau ra sao.
Thực hành: Bảng đối chiếu 3 cloud theo từng mảng.
Ngày 28: Managed identity cho workload
Mục tiêu: App lấy quyền không cần secret.
Lý thuyết: instance profile/IRSA · Managed Identity · Workload Identity.
Thực hành: Cho một app đọc bucket qua managed identity (không key).
Ngày 29: Cloud networking preview
Mục tiêu: Bắc cầu Khối B.
Lý thuyết: VPC/VNet, subnet, security group, route.
Thực hành: Dựng VPC + subnet public/private cơ bản.
Ngày 30: CỘT MỐC 30
Mục tiêu: Chốt nền cloud core.
Lý thuyết: Ôn A; kiểm kê: IAM + compute/storage/db + tổ chức tài khoản + Well-Architected.
Thực hành: Đề thi #1 (IAM/core services/account model) + tự chấm; blog #54 ("Mô hình cloud: IAM, tổ chức tài khoản, và dịch vụ lõi"); tag
layer5-day030; nghỉ nửa ngày. Đã đi 30/150 (20%).
Ngày 31: Public cloud edge
Mục tiêu: Đưa dịch vụ ra biên.
Lý thuyết: CDN (CloudFront), edge, global vs regional.
Thực hành: Đặt CDN trước bucket/app.
Ngày 32: Serverless preview
Mục tiêu: Bắc cầu Khối C.
Lý thuyết: managed vs serverless, khi nào dùng.
Thực hành: Liệt kê workload phù hợp serverless.
Ngày 33: Account provisioning tự động
Mục tiêu: Tạo account có kiểm soát.
Lý thuyết: Control Tower/Account Factory, vending machine.
Thực hành: Đọc mô hình account vending (chuẩn bị landing zone).
Ngày 34: Guardrails preview
Mục tiêu: Ràng buộc tổ chức.
Lý thuyết: SCP (AWS), Azure Policy, Org Policy (GCP) - deny toàn org.
Thực hành: Viết một SCP cấm region/hành vi nguy hiểm.
Ngày 35: Centralized logging preview
Mục tiêu: Audit tập trung.
Lý thuyết: CloudTrail/Activity Log/Audit Logs, log archive account.
Thực hành: Bật audit log; gom về một nơi (khái niệm).
Ngày 36: Ôn Khối A
Mục tiêu: Sẵn sàng đi networking.
Lý thuyết: rà cloud core + các preview cho landing zone.
Thực hành: Chuẩn bị lab networking.
KHỐI B - Cloud Networking (Ngày 37-58)
Ngày 37: VPC/VNet nền
Mục tiêu: Mạng ảo trong cloud.
Lý thuyết: CIDR, subnet, public/private, IGW/NAT (nối Layer 3).
Thực hành: VPC nhiều subnet + NAT gateway.
Ngày 38: Routing & gateways
Mục tiêu: Đường đi trong/ra.
Lý thuyết: route table, internet/NAT/egress-only gateway.
Thực hành: Cấu hình routing public/private đúng.
Ngày 39: Security group & NACL
Mục tiêu: Firewall cloud.
Lý thuyết: stateful SG vs stateless NACL, least-privilege network.
Thực hành: Siết SG chỉ mở cổng cần thiết.
Ngày 40: VPC peering
Mục tiêu: Nối hai mạng.
Lý thuyết: peering, non-transitive, CIDR overlap.
Thực hành: Peer hai VPC; test kết nối.
Ngày 41: Transit/hub-spoke
Mục tiêu: Mạng quy mô lớn.
Lý thuyết: Transit Gateway/vWAN/NCC, hub-spoke topology.
Thực hành: Vẽ + dựng hub-spoke với transit.
Ngày 42: Private connectivity tới service
Mục tiêu: Không đi Internet.
Lý thuyết: VPC endpoint/Private Link/Private Service Connect.
Thực hành: Truy cập S3/service qua private endpoint.
Ngày 43: Hybrid connectivity
Mục tiêu: Nối on-prem.
Lý thuyết: VPN, Direct Connect/ExpressRoute/Interconnect, BGP (nối Layer 3).
Thực hành: Dựng VPN site-to-site (lab/mô phỏng).
Ngày 44: Cloud DNS
Mục tiêu: Phân giải trong cloud (nối Layer 3).
Lý thuyết: Route53/Azure DNS/Cloud DNS, private zone, split-horizon.
Thực hành: Private + public zone; resolution routing.
Ngày 45: Cloud load balancing
Mục tiêu: Phân phối tải managed (nối Layer 3 L4/L7).
Lý thuyết: NLB (L4) vs ALB (L7), global LB, health check.
Thực hành: Dựng ALB + target group + health check.
Ngày 46: Global traffic management
Mục tiêu: Đa vùng.
Lý thuyết: anycast (nối Layer 3), latency/geo routing, failover.
Thực hành: DNS/global LB failover giữa 2 region.
Ngày 47: DDoS & WAF
Mục tiêu: Bảo vệ biên (nối Layer 8).
Lý thuyết: Shield/DDoS Protection, WAF rules.
Thực hành: Áp WAF rule cơ bản trước app.
Ngày 48: Network security posture
Mục tiêu: Mạng an toàn.
Lý thuyết: flow logs, network firewall, egress control.
Thực hành: Bật flow logs; phát hiện traffic bất thường.
Ngày 49: IPv6 & dual-stack
Mục tiêu: Địa chỉ hiện đại.
Lý thuyết: IPv6 trong VPC, dual-stack.
Thực hành: Bật IPv6 cho một subnet.
Ngày 50: Multi-region networking
Mục tiêu: Mạng xuyên vùng.
Lý thuyết: inter-region peering, egress cost, latency.
Thực hành: Nối 2 region qua transit; đo latency.
Ngày 51: k8s networking trên cloud
Mục tiêu: Nối Layer 4.
Lý thuyết: CNI cloud (VPC CNI), LoadBalancer service → cloud LB, Ingress.
Thực hành: Expose service EKS qua cloud LB.
Ngày 52: Service discovery & mesh trên cloud
Mục tiêu: Kết nối service.
Lý thuyết: Cloud Map/private DNS, mesh managed (App Mesh) (nối Layer 4).
Thực hành: Đăng ký service discovery.
Ngày 53: Network baseline cho landing zone
Mục tiêu: Chuẩn mạng doanh nghiệp.
Lý thuyết: shared network account, hub-spoke, centralized egress/firewall.
Thực hành: Thiết kế network baseline (dùng lại ở P3).
Ngày 54: Debug mạng cloud
Mục tiêu: Chẩn đoán thực chiến.
Lý thuyết: reachability analyzer, flow logs, common failure (SG/route/NAT).
Thực hành: Sửa một sự cố "không kết nối được".
Ngày 55: Đo & tối ưu mạng
Mục tiêu: Hiệu năng & chi phí.
Lý thuyết: egress cost, cross-AZ traffic, placement.
Thực hành: Giảm cross-AZ/egress cho một kiến trúc.
Ngày 56: Cloud networking cross-provider
Mục tiêu: Nắm khác biệt.
Lý thuyết: VPC global (GCP) vs regional (AWS), Azure VNet.
Thực hành: Bảng đối chiếu networking 3 cloud.
Ngày 57: Ôn Khối B
Mục tiêu: Khâu networking.
Lý thuyết: rà VPC → transit → hybrid → DNS → LB → security.
Thực hành: Chuẩn bị baseline mạng.
Ngày 58: Chuẩn bị Serverless
Mục tiêu: Bắc cầu Khối C.
Lý thuyết: networking cho serverless (VPC-attached functions).
Thực hành: Ghi chú ràng buộc mạng của FaaS.
KHỐI C - Serverless/FaaS (Ngày 59-70)
Ngày 59: Serverless - nguyên lý
Mục tiêu: Không quản server.
Lý thuyết: event-driven, pay-per-use, scale-to-zero, statelessness.
Thực hành: Deploy một function "hello".
Ngày 60: CỘT MỐC 60
Mục tiêu: Chốt cloud networking.
Lý thuyết: Ôn B; kiểm kê: VPC/transit/hybrid/DNS/LB + network baseline.
Thực hành: Đề thi #2 (VPC/routing/LB/hybrid) + tự chấm; blog #55 ("Cloud networking: VPC, transit, hybrid, và một network baseline doanh nghiệp"); tag
layer5-day060; nghỉ nửa ngày. Đã đi 60/150 (40%).
Ngày 61: FaaS internals
Mục tiêu: Hiểu để tối ưu.
Lý thuyết: cold start, execution model, concurrency, memory/CPU coupling; microVM (nối Layer 2 Firecracker).
Thực hành: Đo cold vs warm; giảm cold start.
Ngày 62: Triggers & integration
Mục tiêu: Nối sự kiện.
Lý thuyết: HTTP/queue/storage/schedule triggers, event source mapping.
Thực hành: Function chạy khi có object mới trong bucket.
Ngày 63: API tầng serverless
Mục tiêu: Expose function.
Lý thuyết: API Gateway (managed), auth, throttling.
Thực hành: Expose function qua API Gateway + auth.
Ngày 64: State cho serverless
Mục tiêu: Lưu trạng thái.
Lý thuyết: managed DB/KV, idempotency, step functions/workflows.
Thực hành: Orchestrate nhiều function bằng workflow.
Ngày 65: Serverless containers
Mục tiêu: Ngoài function.
Lý thuyết: Fargate/Cloud Run/Container Apps, scale-to-zero cho container.
Thực hành: Deploy container serverless.
Ngày 66: Serverless observability
Mục tiêu: Debug hàm (nối Layer 7).
Lý thuyết: structured logs, tracing, cold start metrics.
Thực hành: Trace một invocation xuyên nhiều function.
Ngày 67: Serverless security & IAM
Mục tiêu: Ít quyền, an toàn.
Lý thuyết: function role least-privilege, secret injection.
Thực hành: Siết quyền function; inject secret an toàn.
Ngày 68: Serverless cost & limits
Mục tiêu: Kinh tế FaaS.
Lý thuyết: billing per-invocation, concurrency limit, khi nào KHÔNG dùng serverless.
Thực hành: So chi phí serverless vs container cho một tải.
Ngày 69: Serverless cross-provider
Mục tiêu: Nắm khác biệt.
Lý thuyết: Lambda vs Functions vs Cloud Functions/Run.
Thực hành: Bảng đối chiếu.
Ngày 70: Ôn Khối C
Mục tiêu: Chốt serverless.
Lý thuyết: rà FaaS + serverless container + integration.
Thực hành: Chuẩn bị IaC (sẽ IaC hoá tất cả).
KHỐI D - Infrastructure as Code (Ngày 71-100) → P1
Ngày 71: IaC - nguyên lý
Mục tiêu: Hạ tầng khai báo, versioned.
Lý thuyết: declarative vs imperative, idempotency, drift (nối reconcile Layer 4).
Thực hành: So tay-vs-IaC cho một tài nguyên.
Ngày 72: Terraform/OpenTofu nền
Mục tiêu: Công cụ IaC chủ đạo.
Lý thuyết: HCL, provider, resource, plan/apply/destroy.
Thực hành: Provision VPC + VM bằng Terraform/OpenTofu.
Ngày 73: State
Mục tiêu: Nguồn sự thật của IaC.
Lý thuyết: state file, remote backend, locking, sensitive data.
Thực hành: Dùng remote backend (S3+lock) an toàn.
Ngày 74: Variables & outputs
Mục tiêu: Cấu hình linh hoạt.
Lý thuyết: variable/locals/output, tfvars, precedence.
Thực hành: Tham số hoá một config.
Ngày 75: Modules
Mục tiêu: Tái sử dụng.
Lý thuyết: module input/output, versioning, registry.
Thực hành: Viết một module network tái dùng.
Ngày 76: Workspaces & environments
Mục tiêu: dev/stg/prod.
Lý thuyết: workspace vs thư mục env, tránh nhầm prod.
Thực hành: Tách môi trường an toàn.
Ngày 77: Dependency & graph
Mục tiêu: Thứ tự đúng.
Lý thuyết: implicit/explicit depends_on, resource graph, apply ordering.
Thực hành: Đọc
terraform graph.
Ngày 78: Data sources & imports
Mục tiêu: Làm việc với hạ tầng có sẵn.
Lý thuyết: data source,
import, brownfield.Thực hành: Import một tài nguyên tạo tay vào state.
Ngày 79: Provisioners & lifecycle
Mục tiêu: Kiểm soát vòng đời.
Lý thuyết: lifecycle (prevent_destroy, create_before_destroy), khi nào tránh provisioner.
Thực hành: Zero-downtime replace bằng create_before_destroy.
Ngày 80: Terragrunt & DRY
Mục tiêu: Quản lý nhiều env/account.
Lý thuyết: Terragrunt, DRY backend/provider, dependency giữa stacks.
Thực hành: Cấu trúc repo đa account bằng Terragrunt (khái niệm/thử).
Ngày 81: Packer
Mục tiêu: Golden image as code.
Lý thuyết: Packer build, provisioner, image pipeline (nối immutable infra).
Thực hành: Build golden image bằng Packer.
Ngày 82: IaC testing
Mục tiêu: Đảm bảo đúng trước apply.
Lý thuyết: validate/fmt/plan review, terratest, checkov/tfsec (nối Layer 8).
Thực hành: Chạy static scan + một test terratest nhỏ.
Ngày 83: IaC CI/CD
Mục tiêu: Apply có kiểm soát.
Lý thuyết: plan trên PR, approval, apply pipeline, OIDC (không key).
Thực hành: Pipeline: PR → plan → review → apply.
Ngày 84: Policy-as-code cho IaC
Mục tiêu: Guardrail trước khi tạo (nối Khối F).
Lý thuyết: OPA/conftest, Sentinel, chặn config vi phạm.
Thực hành: Chặn resource public/không mã hoá bằng policy.
Ngày 85: Secrets trong IaC
Mục tiêu: Không lộ secret.
Lý thuyết: không hardcode, tham chiếu secret manager, state sensitivity.
Thực hành: Lấy secret runtime thay vì để trong code/state.
Ngày 86: Multi-account IaC
Mục tiêu: Quy mô tổ chức.
Lý thuyết: provider alias/assume-role, cấu trúc account.
Thực hành: Apply xuyên nhiều account bằng assume-role.
Ngày 87: Drift & reconciliation
Mục tiêu: Giữ thực tế = code.
Lý thuyết: drift detection, refresh, GitOps cho infra (Crossplane, nối Layer 4).
Thực hành: Gây drift; phát hiện + hoà giải.
Ngày 88: CDK/Pulumi
Mục tiêu: IaC bằng ngôn ngữ lập trình.
Lý thuyết: CDK/Pulumi vs HCL, khi nào chọn.
Thực hành: Đọc một ví dụ CDK; so với Terraform.
Ngày 89: Crossplane vs Terraform
Mục tiêu: Control-plane IaC (nối Layer 4).
Lý thuyết: push (Terraform) vs continuous reconcile (Crossplane).
Thực hành: Provision cùng tài nguyên bằng Crossplane; so sánh.
Ngày 90: CỘT MỐC 90
Mục tiêu: Chốt IaC nền.
Lý thuyết: Ôn D tới giờ; kiểm kê: module + state + CI/CD + policy-as-code.
Thực hành: Đề thi #3 (Terraform/state/module/pipeline) + tự chấm; blog #56 ("IaC nghiêm túc: module, state, CI/CD, policy-as-code"); tag
layer5-day090; nghỉ nửa ngày. Đã đi 90/150 (60%).
Ngày 91: P1 - thiết kế module library
Mục tiêu: Đóng khung P1.
Lý thuyết: module cần có (network/compute/iam/data/observability), convention.
Thực hách:
module-library-design.md.
Ngày 92: P1 - module network
Mục tiêu: Nền mạng tái dùng.
Lý thuyết: VPC/subnet/routing/endpoints tham số hoá.
Thực hành: Module network hoàn chỉnh + ví dụ.
Ngày 93: P1 - module compute/k8s
Mục tiêu: Compute chuẩn.
Lý thuyết: ASG/managed k8s node pool tham số hoá.
Thực hành: Module compute/EKS.
Ngày 94: P1 - module IAM/security
Mục tiêu: Quyền tái dùng an toàn.
Lý thuyết: role/policy chuẩn least-privilege.
Thực hành: Module IAM baseline.
Ngày 95: P1 - module data
Mục tiêu: DB/bucket chuẩn.
Lý thuyết: encryption/backup mặc định bật.
Thực hành: Module database + object storage an toàn mặc định.
Ngày 96: P1 - composition
Mục tiêu: Ghép module thành stack.
Lý thuyết: root module gọi child, env layering.
Thực hành: Stack dev/prod từ module library.
Ngày 97: P1 - testing & scan
Mục tiêu: Chất lượng.
Lý thuyết: terratest + tfsec/checkov + policy.
Thực hành: Test + scan toàn bộ module.
Ngày 98: P1 - CI/CD
Mục tiêu: Vận hành module.
Lý thuyết: versioned modules, release, plan/apply pipeline.
Thực hành: Pipeline hoàn chỉnh cho module library.
Ngày 99: P1 - docs
Mục tiêu: Dùng lại được.
Lý thuyết: README/examples/terraform-docs.
Thực hành: Sinh docs tự động; ví dụ sử dụng.
Ngày 100:
Mục tiêu: Kiểm kê lớn; release P1.
Lý thuyết: Ôn A→D; kiểm kê lớn: cloud core + networking + serverless + IaC library; đối chiếu "biết dùng tốt".
Thực hành: P1 done; đề thi #4 tích lũy (core+network+serverless+IaC) + tự chấm theo rubric; blog #57 ("100 ngày cloud platform: từ IAM tới một thư viện IaC dùng chung"); tag
layer5-day100; nghỉ nửa ngày. Đã đi 100/150 (67%).
KHỐI E - Secrets & Identity (Ngày 101-124) → P2
Ngày 101: Secret management - nguyên lý
Mục tiêu: Không để secret rải rác.
Lý thuyết: static vs dynamic secret, rotation, least exposure.
Thực hành: Kiểm kê nơi secret đang nằm; điểm rủi ro.
Ngày 102: Cloud secret managers
Mục tiêu: Dùng managed trước.
Lý thuyết: Secrets Manager/Key Vault/Secret Manager, rotation, IAM access.
Thực hành: Lưu + truy cập secret qua managed service + IAM.
Ngày 103: Vault - kiến trúc
Mục tiêu: Secret engine trung tâm.
Lý thuyết: seal/unseal, storage backend, auth methods, secret engines, lease.
Thực hành: Dựng Vault dev + KV engine.
Ngày 104: Vault - auth methods
Mục tiêu: Ai được lấy secret.
Lý thuyết: token, AppRole, k8s auth, cloud IAM auth.
Thực hành: k8s/cloud auth → pod lấy secret không cần key tĩnh.
Ngày 105: Vault - dynamic secrets
Mục tiêu: Secret ngắn hạn.
Lý thuyết: dynamic DB/cloud credentials, TTL, revoke.
Thực hành: Cấp credential DB động, tự hết hạn.
Ngày 106: Vault - transit & encryption
Mục tiêu: Encryption-as-a-service.
Lý thuyết: transit engine, encrypt/decrypt không lộ key.
Thực hành: App mã hoá field qua transit.
Ngày 107: PKI - nền
Mục tiêu: Chứng chỉ & tin cậy (nối Layer 8).
Lý thuyết: CA hierarchy (root/intermediate), cert lifecycle, CRL/OCSP.
Thực hành: Vẽ chuỗi tin cậy mục tiêu.
Ngày 108: Vault PKI engine
Mục tiêu: Cấp cert tự động.
Lý thuyết: PKI secret engine, short-lived cert, mTLS.
Thực hành: Cấp cert ngắn hạn cho service; auto-rotate.
Ngày 109: cert-manager tích hợp
Mục tiêu: Cert trong k8s (nối Layer 4).
Lý thuyết: cert-manager + Vault/ACME issuer.
Thực hành: Cấp cert cho Gateway qua cert-manager+Vault.
Ngày 110: Secret injection cho workload
Mục tiêu: App nhận secret an toàn.
Lý thuyết: sidecar/agent injector, CSI secret driver, tránh env leak.
Thực hành: Inject secret vào pod qua agent/CSI.
Ngày 111: Boundary - access
Mục tiêu: Truy cập hạ tầng theo identity.
Lý thuyết: identity-based access, session brokering, không lộ credential/host.
Thực hành: Truy cập một target qua Boundary.
Ngày 112: Just-in-time access
Mục tiêu: Quyền tạm thời.
Lý thuyết: JIT elevation, approval, session recording.
Thực hành: Cấp quyền admin tạm có hết hạn.
Ngày 113: Identity governance
Mục tiêu: Quản trị danh tính.
Lý thuyết: least privilege, access review, permission boundary, SoD.
Thực hành: Access review một role; siết quyền thừa.
Ngày 114: Machine & workload identity
Mục tiêu: Máy có danh tính.
Lý thuyết: SPIFFE/SPIRE (workload identity), mTLS identity (nối Layer 4 mesh).
Thực hành: Cấp SVID cho workload; xác thực mTLS.
Ngày 115: Key management
Mục tiêu: Quản khoá đúng.
Lý thuyết: KMS/HSM (nối Layer 8), key rotation, envelope encryption.
Thực hành: Rotate CMK; kiểm tác động.
Ngày 116: Audit & secret hygiene
Mục tiêu: Kiểm soát rò rỉ.
Lý thuyết: audit log Vault, secret scanning (git), rotation policy.
Thực hành: Bật audit; scan repo tìm secret lộ.
Ngày 117: P2 - thiết kế baseline
Mục tiêu: Đóng khung P2.
Lý thuyết: Vault + PKI + dynamic secret + Boundary + injection.
Thực hách:
secrets-identity-design.md.
Ngày 118: P2 - Vault + auth
Mục tiêu: Nền secret.
Lý thuyết: HA Vault, auth cloud/k8s.
Thực hành: Dựng Vault + auth methods.
Ngày 119: P2 - dynamic secrets + PKI
Mục tiêu: Secret ngắn hạn + cert.
Lý thuyết: DB dynamic creds + PKI mTLS.
Thực hành: Cấp dynamic DB creds + short-lived cert.
Ngày 120: CỘT MỐC 120
Mục tiêu: Chốt phần chính secrets/identity.
Lý thuyết: Ôn E tới giờ; kiểm kê: Vault/PKI/dynamic secret/Boundary.
Thực hành: Đề thi #5 (Vault/PKI/identity) + tự chấm; blog #58 ("Secrets & identity: Vault, PKI động, và truy cập theo danh tính"); tag
layer5-day120; nghỉ nửa ngày. Đã đi 120/150 (80%).
Ngày 121: P2 - Boundary access
Mục tiêu: Truy cập an toàn.
Lý thuyết: target/host set, session brokering.
Thực hành: Truy cập DB/host qua Boundary, không lộ credential.
Ngày 122: P2 - workload injection
Mục tiêu: App nhận secret.
Lý thuyết: injector + CSI + auto-rotate.
Thực hành: Inject dynamic secret vào app k8s.
Ngày 123: P2 - audit & rotation
Mục tiêu: Vận hành bền.
Lý thuyết: rotation policy, audit, revoke.
Thực hành: Thiết lập rotation + audit; test revoke.
Ngày 124: P2 - Secrets & Identity baseline
Mục tiêu: Release P2.
Lý thuyết: rà "done": Vault+PKI+dynamic+Boundary+injection+audit.
Thực hành: Đóng gói + writeup. P2 done.
KHỐI F - Policy (Ngày 125-136)
Ngày 125: Policy - nguyên lý
Mục tiêu: Guardrail nhất quán.
Lý thuyết: preventive vs detective, policy-as-code, shift-left.
Thực hành: Phân loại policy cần có cho tổ chức.
Ngày 126: OPA/Rego
Mục tiêu: Policy engine đa dụng (nối Layer 4).
Lý thuyết: Rego, decision, data, input.
Thực hành: Viết policy Rego cho một quyết định.
Ngày 127: conftest cho IaC
Mục tiêu: Chặn hạ tầng xấu trước apply.
Lý thuyết: conftest trên Terraform plan JSON.
Thực hành: Chặn resource public/không mã hoá ở CI.
Ngày 128: Kyverno (k8s)
Mục tiêu: Policy cluster (nối Layer 4).
Lý thuyết: validate/mutate/generate, PolicyReport.
Thực hành: Áp policy k8s (đối chiếu Layer 4 P3).
Ngày 129: Cloud org guardrails
Mục tiêu: Ràng buộc cấp tổ chức.
Lý thuyết: SCP (AWS) · Azure Policy · Org Policy (GCP), preventive.
Thực hành: Viết SCP/Azure Policy cấm hành vi nguy hiểm toàn org.
Ngày 130: Compliance-as-code
Mục tiêu: Ánh xạ chuẩn.
Lý thuyết: CIS/NIST → policy, config rules, drift compliance (nối Layer 8).
Thực hành: Map một CIS control thành rule tự động.
Ngày 131: Detective controls
Mục tiêu: Phát hiện vi phạm đang tồn tại.
Lý thuyết: Config/Policy compliance scan, remediation.
Thực hành: Scan tài khoản; sinh báo cáo non-compliant.
Ngày 132: Auto-remediation
Mục tiêu: Tự sửa vi phạm.
Lý thuyết: event → function → remediate, hoặc reconcile.
Thực hành: Auto-remediate một vi phạm (ví dụ bucket public).
Ngày 133: Policy testing & rollout
Mục tiêu: Không phá vỡ prod.
Lý thuyết: audit/dry-run trước enforce, exception process.
Thực hành: Rollout policy theo audit → warn → enforce.
Ngày 134: Policy cho landing zone
Mục tiêu: Guardrail nền tảng.
Lý thuyết: bộ guardrail chuẩn cho org (region/encryption/public/tagging).
Thực hành: Soạn bộ guardrail dùng ở P3.
Ngày 135: Policy cross-provider
Mục tiêu: Nắm khác biệt.
Lý thuyết: SCP vs Azure Policy vs Org Policy.
Thực hành: Bảng đối chiếu guardrail 3 cloud.
Ngày 136: Ôn Khối F
Mục tiêu: Chốt policy.
Lý thuyết: rà OPA/Kyverno/org guardrail/compliance.
Thực hành: Chuẩn bị Zero Trust + landing zone.
KHỐI G - Zero Trust + Enterprise Landing Zone (Ngày 137-150) → P3 flagship
Ngày 137: Zero Trust - nguyên lý
Mục tiêu: Không tin ngầm.
Lý thuyết: "never trust, always verify", identity-centric, giả định breach; BeyondCorp.
Thực hành: Đối chiếu perimeter vs zero-trust cho một hệ thống.
Ngày 138: Zero Trust - identity & device
Mục tiêu: Xác thực liên tục.
Lý thuyết: strong identity, device trust, context-aware access.
Thực hành: Thiết kế access policy theo identity+context.
Ngày 139: Zero Trust - network
Mục tiêu: Bỏ tin cậy theo vị trí mạng.
Lý thuyết: microsegmentation, identity-aware proxy, mTLS mọi nơi (nối Layer 4 mesh).
Thực hành: Segment + IAP cho một app nội bộ.
Ngày 140: Zero Trust - data & workload
Mục tiêu: Bảo vệ tận lõi.
Lý thuyết: least privilege, encryption everywhere, workload identity (SPIFFE).
Thực hành: Áp least-privilege + workload identity cho một service.
Ngày 141: Landing Zone - kiến trúc
Mục tiêu: Đóng khung P3.
Lý thuyết: multi-account org, core accounts (management/log-archive/security/network/shared-services).
Thực hách:
landing-zone-design.md.
Ngày 142: LZ - org & account vending
Mục tiêu: Cấu trúc tổ chức.
Lý thuyết: OU/folder, account factory, baseline mỗi account.
Thực hành: Dựng org + OU + account vending (IaC, dùng P1 modules).
Ngày 143: LZ - guardrails
Mục tiêu: Ràng buộc toàn org.
Lý thuyết: SCP/Policy preventive + detective (Khối F).
Thực hành: Áp bộ guardrail (region/encryption/public/tag) toàn org.
Ngày 144: LZ - network baseline
Mục tiêu: Mạng chuẩn doanh nghiệp.
Lý thuyết: shared network account, hub-spoke/transit, centralized egress/firewall (Khối B).
Thực hành: Dựng network baseline bằng IaC.
Ngày 145: LZ - identity baseline
Mục tiêu: Đăng nhập & quyền tập trung.
Lý thuyết: SSO/IdP, permission set, cross-account role, break-glass.
Thực hành: SSO + permission set cho các account.
Ngày 146: LZ - security & logging baseline
Mục tiêu: Audit + phát hiện tập trung.
Lý thuyết: centralized CloudTrail/audit → log archive, GuardDuty/Defender, config rules.
Thực hành: Bật audit + threat detection tập trung.
Ngày 147: LZ - secrets & PKI baseline
Mục tiêu: Ghép P2 vào nền tảng.
Lý thuyết: Vault/secret manager + PKI dùng chung toàn org.
Thực hành: Tích hợp baseline secrets/identity (P2) vào LZ.
Ngày 148: LZ - self-service & provisioning
Mục tiêu: Trao nền tảng cho team (nối Layer 4/6).
Lý thuyết: account/app vending self-service, guardrail tự động áp.
Thực hành: Team mới xin account → tự động có baseline + guardrail.
Ngày 149: LZ - validate & docs; ôn Layer 5
Mục tiêu: Hoàn thiện.
Lý thuyết: kiểm tra guardrail hiệu lực, drift, chi phí; rà toàn layer.
Thực hành: Test tuân thủ toàn org; viết runbook/docs (nối Layer 6/11).
Ngày 150: HOÀN THÀNH LAYER 5
Mục tiêu: Chốt Cloud Platform Engineering ở mức "biết dùng vững".
Lý thuyết: Ôn toàn layer; kiểm kê tổng: cloud core + networking + serverless + IaC library (P1) + secrets/identity (P2) + Enterprise Landing Zone (P3).
Thực hành: P3 done; đề thi #6 tích lũy (toàn layer) + tự chấm theo rubric; blog #59 ("Nhìn lại 150 ngày cloud platform: một Enterprise Landing Zone an toàn từ số 0"); tag
layer5-complete; nghỉ nửa ngày.