Skip to main content

Command Palette

Search for a command to run...

Học Platform engineering (3)

Updated
62 min readView as Markdown

LAYER 4 - CLOUD NATIVE ENGINEERING (Syllabus chi tiết theo ngày)

Tài nguyên: Kubernetes docs, Programming Kubernetes (Hausenblas & Schimanski), Kubernetes Patterns, kubebuilder book, controller-runtime/client-go, Envoy/Istio docs, OCI spec, Gateway API/Crossplane/ArgoCD docs, CNCF landscape.

KHỐI A - Container (Ngày 1-30) → P1 OCI/CRI mini runtime

Ngày 1: Khởi động Layer 4

  • Mục tiêu: Dựng cluster lab + bản đồ cloud-native.

  • Lý thuyết: landscape CNCF, cluster components, cách lab bằng kind/kubeadm.

  • Thực hành: Repo cloud-native/; dựng cụm kind nhiều node.

Ngày 2: Container recap từ Layer 2

  • Mục tiêu: Nối mini container đã có.

  • Lý thuyết: ns + cgroups v2 + overlayfs + seccomp = container; cần chuẩn hoá.

  • Thực hành: Chạy lại mycontainer (Layer 2); liệt kê chỗ chưa "chuẩn".

Ngày 3: OCI overview

  • Mục tiêu: Ba spec làm nên hệ container.

  • Lý thuyết: image-spec, runtime-spec, distribution-spec.

  • Thực hành: Đọc cấu trúc một OCI image bằng skopeo/crane.

Ngày 4: OCI runtime-spec

  • Mục tiêu: Chuẩn chạy container.

  • Lý thuyết: config.json, bundle, lifecycle (create/start/kill/delete), hooks.

  • Thực hành: Đọc config.json do runc sinh; ánh xạ sang ns/cgroups.

Ngày 5: OCI image-spec

  • Mục tiêu: Cấu trúc image.

  • Lý thuyết: layer (tar+gzip), manifest, config, digest, content-addressable.

  • Thực hành: Bóc tách layers một image thủ công.

Ngày 6: OCI distribution-spec

  • Mục tiêu: Registry hoạt động thế nào.

  • Lý thuyết: registry API (v2), push/pull, blob, manifest, tag.

  • Thực hành: Push/pull với một local registry; xem HTTP calls.

Ngày 7: runc

  • Mục tiêu: Runtime tham chiếu.

  • Lý thuyết: kiến trúc runc, libcontainer, tạo container từ bundle.

  • Thực hành: Chạy container bằng runc trực tiếp (không Docker).

Ngày 8: crun & youki

  • Mục tiêu: Runtime thay thế.

  • Lý thuyết: crun (C, nhẹ), youki (Rust), tương thích OCI.

  • Thực hành: So thời gian khởi động runc vs crun.

Ngày 9: containerd

  • Mục tiêu: Runtime cấp cao dùng trong k8s.

  • Lý thuyết: kiến trúc, shim, snapshotter, task.

  • Thực hành: Dùng ctr chạy container; quan sát shim process.

Ngày 10: containerd - content & image

  • Mục tiêu: Quản lý image/blob.

  • Lý thuyết: content store, image service, snapshotter (overlayfs).

  • Thực hành: Pull image qua containerd; xem content store.

Ngày 11: CRI

  • Mục tiêu: Kết nối kubelet ↔ runtime.

  • Lý thuyết: Container Runtime Interface (RuntimeService, ImageService), gRPC.

  • Thực hành: crictl thao tác pod/container qua CRI.

Ngày 12: CRI-O

  • Mục tiêu: Runtime chuyên cho k8s.

  • Lý thuyết: CRI-O tối giản, chỉ phục vụ Kubernetes.

  • Thực hành: Đối chiếu CRI-O vs containerd.

Ngày 13: BuildKit

  • Mục tiêu: Build image hiện đại.

  • Lý thuyết: LLB, cache, frontend (Dockerfile), rootless build.

  • Thực hành: Build image bằng BuildKit; quan sát cache layers.

Ngày 14: Rootless containers

  • Mục tiêu: Container không cần root.

  • Lý thuyết: user namespace mapping (nối Layer 2), subuid/subgid.

  • Thực hành: Chạy rootless container; kiểm tra UID map.

Ngày 15: Image layers & overlayfs

  • Mục tiêu: Hiểu chia sẻ tầng.

  • Lý thuyết: overlayfs (nối Layer 3), copy-up, dedup layer.

  • Thực hành: Đo tiết kiệm dung lượng khi share base layer.

Ngày 16: Registry vận hành

  • Mục tiêu: Registry production.

  • Lý thuyết: Harbor/distribution, mirroring, GC, retention.

  • Thực hành: Dựng registry + mirror; cấu hình pull-through cache.

Ngày 17: Image signing (preview)

  • Mục tiêu: Tin cậy image (nối Layer 8).

  • Lý thuyết: cosign/Sigstore, digest pinning.

  • Thực hành: Ký + verify một image bằng cosign.

Ngày 18: P1 - runtime-spec compliance

  • Mục tiêu: Nâng mini container lên OCI.

  • Lý thuyết: đọc & tuân config.json đầy đủ.

  • Thực hành: Mini runtime parse config.json chuẩn OCI.

Ngày 19: P1 - config parsing

  • Mục tiêu: Áp cấu hình vào ns/cgroups.

  • Lý thuyết: map các trường (mounts, caps, seccomp, cgroups) sang syscall.

  • Thực hành: Áp mounts + caps + seccomp từ config.

Ngày 20: P1 - lifecycle

  • Mục tiêu: Vòng đời chuẩn.

  • Lý thuyết: create/start/kill/delete state, state.json.

  • Thực hành: Cài đủ lifecycle; runc-compatible CLI subset.

Ngày 21: P1 - hooks

  • Mục tiêu: Điểm mở rộng.

  • Lý thuyết: prestart/poststart/poststop hooks.

  • Thực hành: Thêm hook chạy script; test.

Ngày 22: P1 - pull image

  • Mục tiêu: Lấy image từ registry.

  • Lý thuyết: distribution API, resolve manifest + blobs.

  • Thực hành: Pull một OCI image (không dùng docker).

Ngày 23: P1 - unpack rootfs

  • Mục tiêu: Từ layers ra rootfs.

  • Lý thuyết: apply layers qua overlayfs, whiteout.

  • Thực hành: Unpack image thành rootfs chạy được.

Ngày 24: P1 - CRI shim

  • Mục tiêu: Nói chuyện được với kubelet.

  • Lý thuyết: implement subset RuntimeService/ImageService.

  • Thực hành: CRI shim tối giản; crictl gọi được.

Ngày 25: CNI - spec

  • Mục tiêu: Chuẩn mạng container.

  • Lý thuyết: Container Network Interface, ADD/DEL, IPAM, plugin chain.

  • Thực hành: Đọc spec + chạy plugin bridge mẫu.

Ngày 26: CNI - viết plugin

  • Mục tiêu: Tự cấp mạng cho container.

  • Lý thuyết: veth + bridge + IPAM (nối Layer 3 netns).

  • Thực hành: CNI plugin nhỏ: tạo veth, gán IP, route.

Ngày 27: CSI - spec

  • Mục tiêu: Chuẩn lưu trữ container.

  • Lý thuyết: Container Storage Interface, controller vs node plugin, volume lifecycle.

  • Thực hành: Đọc CSI; map sang PV/PVC (Khối B).

Ngày 28: Integrate container + CNI

  • Mục tiêu: Container có mạng.

  • Lý thuyết: gọi CNI plugin từ mini runtime.

  • Thực hành: Container tự viết ping được qua CNI plugin tự viết.

Ngày 29: Test OCI/CRI compliance

  • Mục tiêu: Kiểm chứng chuẩn.

  • Lý thuyết: oci runtime-tools, so hành vi với runc.

  • Thực hành: Chạy test suite; sửa lệch.

Ngày 30: CỘT MỐC 30

  • Mục tiêu: Chốt container; release P1.

  • Lý thuyết: Ôn A; kiểm kê: OCI runtime + CRI shim + CNI plugin.

  • Thực hành: P1 done; đề thi #1 (OCI/CRI/CNI) + tự chấm; blog #43 ("Từ mini container tới một OCI runtime + CRI shim"); tag layer4-day030; nghỉ nửa ngày. Đã đi 30/210 (14%).

KHỐI B - Kubernetes Core (Ngày 31-66)

Ngày 31: Kiến trúc Kubernetes

  • Mục tiêu: Bản đồ toàn cluster.

  • Lý thuyết: control plane (apiserver/etcd/scheduler/controller-manager) + node (kubelet/kube-proxy/runtime).

  • Thực hành: Vẽ sơ đồ; xác định process trong cụm kind.

Ngày 32: Mô hình API khai báo

  • Mục tiêu: Tư tưởng cốt lõi k8s.

  • Lý thuyết: desired vs actual state, reconciliation, declarative.

  • Thực hành: Apply một manifest; quan sát controller đưa về desired.

Ngày 33: kube-apiserver

  • Mục tiêu: Cửa ngõ cluster.

  • Lý thuyết: REST, resources, API groups/versions, serialization.

  • Thực hành: Gọi API trực tiếp (kubectl get --raw); duyệt API groups.

Ngày 34: API machinery

  • Mục tiêu: Watch/list cơ chế.

  • Lý thuyết: list-watch, resourceVersion, optimistic concurrency, bookmark.

  • Thực hành: Watch một resource qua raw API; quan sát event stream.

Ngày 35: etcd trong k8s

  • Mục tiêu: Store nhất quán.

  • Lý thuyết: Raft (nối Layer 3), MVCC, revision, watch, compaction.

  • Thực hành: etcdctl xem key k8s; quan sát revision.

Ngày 36: etcd - vận hành

  • Mục tiêu: Store bền vững.

  • Lý thuyết: lease, compaction, defrag, backup/restore (nối Layer 11 DR).

  • Thực hành: Backup + restore etcd của lab.

Ngày 37: API server - authentication

  • Mục tiêu: Ai đang gọi.

  • Lý thuyết: client cert, token, OIDC, service account.

  • Thực hành: Tạo SA + token; gọi API bằng token đó.

Ngày 38: API server - authorization

  • Mục tiêu: Được làm gì.

  • Lý thuyết: RBAC (Role/Binding), Node, ABAC.

  • Thực hành: Tạo Role least-privilege; kiểm kubectl auth can-i.

Ngày 39: Admission chain (preview)

  • Mục tiêu: Chặn/sửa request (nối Khối E).

  • Lý thuyết: mutating → validating, built-in admission plugins.

  • Thực hành: Liệt kê admission plugins đang bật.

Ngày 40: kubelet

  • Mục tiêu: Agent trên node.

  • Lý thuyết: pod lifecycle, PLEG, sync loop, static pods.

  • Thực hành: Đọc log kubelet khi tạo pod; theo sync loop.

Ngày 41: kubelet - CRI/CNI/CSI

  • Mục tiêu: Nối Khối A vào node.

  • Lý thuyết: kubelet gọi CRI để chạy pod, CNI để nối mạng, CSI để mount.

  • Thực hành: Trace một pod: kubelet → CRI → runtime.

Ngày 42: kube-proxy & eBPF

  • Mục tiêu: Hiện thực Service.

  • Lý thuyết: iptables vs IPVS vs eBPF (Cilium, nối Layer 2), DNAT tới pod.

  • Thực hành: Xem rule kube-proxy; so mode iptables vs IPVS.

Ngày 43: Service & Endpoints

  • Mục tiêu: Trừu tượng kết nối.

  • Lý thuyết: Service, Endpoints, EndpointSlice, selector.

  • Thực hành: Tạo Service; quan sát EndpointSlice cập nhật khi scale.

Ngày 44: DNS trong cluster

  • Mục tiêu: Service discovery nội bộ.

  • Lý thuyết: CoreDNS (nối Layer 3), service/pod DNS records.

  • Thực hành: Resolve service DNS từ pod; đọc Corefile.

Ngày 45: kube-scheduler

  • Mục tiêu: Đặt pod lên node.

  • Lý thuyết: kiến trúc scheduler, scheduling cycle.

  • Thực hành: Quan sát quyết định scheduling qua events.

Ngày 46: Scheduler - filter & score

  • Mục tiêu: Cách chọn node.

  • Lý thuyết: filtering (predicates), scoring (priorities).

  • Thực hành: Ép pod pending bằng resource request lớn; đọc lý do.

Ngày 47: Scheduler framework

  • Mục tiêu: Mở rộng scheduler.

  • Lý thuyết: plugins, extension points (PreFilter…Bind).

  • Thực hành: Đọc một plugin; ý tưởng plugin tuỳ biến.

Ngày 48: Affinity & topology

  • Mục tiêu: Điều khiển đặt pod.

  • Lý thuyết: node/pod affinity, taints/tolerations, topology spread.

  • Thực hành: Dùng anti-affinity + spread cho HA.

Ngày 49: kube-controller-manager

  • Mục tiêu: Các controller built-in.

  • Lý thuyết: node/replicaset/deployment/endpoint controllers.

  • Thực hành: Liệt kê controllers; quan sát một cái hoạt động.

Ngày 50: Control loop

  • Mục tiêu: Nền của mọi controller.

  • Lý thuyết: level-triggered reconciliation, observe→diff→act.

  • Thực hành: Vẽ vòng lặp; đối chiếu với event-driven.

Ngày 51: Deployment chain

  • Mục tiêu: Chuỗi controller thực tế.

  • Lý thuyết: Deployment → ReplicaSet → Pod, rollout/rollback.

  • Thực hành: Rollout + rollback; quan sát ReplicaSet.

Ngày 52: Workload controllers khác

  • Mục tiêu: Ngoài Deployment.

  • Lý thuyết: StatefulSet, DaemonSet, Job/CronJob.

  • Thực hành: Dựng StatefulSet có PVC; quan sát ordering.

Ngày 53: Storage - PV/PVC/CSI

  • Mục tiêu: Lưu trữ cho pod.

  • Lý thuyết: PV/PVC/StorageClass, dynamic provisioning, CSI (nối Layer 3).

  • Thực hành: Provision volume động; mount vào pod.

Ngày 54: Config & Secret

  • Mục tiêu: Cấu hình workload.

  • Lý thuyết: ConfigMap/Secret, projected/immutable, mount vs env.

  • Thực hành: Inject config + secret; kiểm tra reload behavior.

Ngày 55: Pod internals

  • Mục tiêu: Pod là gì thật sự.

  • Lý thuyết: pause container, shared ns (net/ipc), lifecycle (nối Layer 2).

  • Thực hành: Quan sát pause container + shared netns trong pod.

Ngày 56: Init/sidecar/ephemeral

  • Mục tiêu: Các loại container trong pod.

  • Lý thuyết: init containers, native sidecar, ephemeral (debug).

  • Thực hành: Dùng ephemeral container debug pod đang chạy.

Ngày 57: Resource management

  • Mục tiêu: Chia tài nguyên.

  • Lý thuyết: requests/limits, QoS class, ánh xạ cgroups v2 (nối Layer 2).

  • Thực hành: Đặt requests/limits; xem cgroup của pod trên node.

Ngày 58: Pod security

  • Mục tiêu: Chạy pod an toàn.

  • Lý thuyết: securityContext, seccomp/AppArmor, Pod Security Admission.

  • Thực hành: Áp PSA restricted; chặn pod privileged.

Ngày 59: Networking model

  • Mục tiêu: Mô hình mạng k8s.

  • Lý thuyết: pod-to-pod flat, ClusterIP/NodePort/LoadBalancer, CNI (Cilium/Calico).

  • Thực hành: Cài Cilium; quan sát pod networking + NetworkPolicy.

Ngày 60: CỘT MỐC 60

  • Mục tiêu: Chốt Kubernetes core.

  • Lý thuyết: Ôn B; kiểm kê: hiểu control plane + node + workloads + networking.

  • Thực hành: Đề thi #2 (apiserver/etcd/scheduler/kubelet/service) + tự chấm; blog #44 ("Đường đi của một Pod: từ kubectl apply tới container chạy"); tag layer4-day060; nghỉ nửa ngày. Đã đi 60/210 (29%).

Ngày 61: Ingress vs Gateway API (preview)

  • Mục tiêu: Vào cluster từ ngoài.

  • Lý thuyết: Ingress, hạn chế; Gateway API sắp học (Khối G).

  • Thực hành: Expose app qua Ingress đơn giản.

Ngày 62: Cluster bootstrap

  • Mục tiêu: Dựng cluster thật.

  • Lý thuyết: kubeadm, control plane HA, certs, etcd topology.

  • Thực hành: Bootstrap một cụm HA nhỏ bằng kubeadm.

Ngày 63: kubeconfig & access

  • Mục tiêu: Truy cập cluster.

  • Lý thuyết: kubeconfig, context, cluster/user/namespace.

  • Thực hành: Nhiều context; chuyển đổi an toàn.

Ngày 64: kubectl internals

  • Mục tiêu: Client hoạt động thế nào.

  • Lý thuyết: client-go, discovery, REST mapping, server-side apply.

  • Thực hành: Đọc verbose kubectl -v=8; theo request.

Ngày 65: Ôn Khối B

  • Mục tiêu: Khâu control plane thành một luồng.

  • Lý thuyết: rà đường tạo Pod xuyên apiserver→scheduler→kubelet.

  • Thực hành: Vẽ end-to-end request flow.

Ngày 66: Chuẩn bị Control Plane Engineering

  • Mục tiêu: Bắc cầu sang viết controller.

  • Lý thuyết: vì sao cần hiểu informer/cache trước khi viết operator.

  • Thực hành: Setup môi trường Go + client-go + controller-runtime.

KHỐI C - Control Plane Engineering (Ngày 67-90)

Ngày 67: Reconciliation loop

  • Mục tiêu: Trái tim của controller.

  • Lý thuyết: observe → diff → act, idempotency, eventual consistency.

  • Thực hành: Viết pseudo-reconcile cho một resource giả định.

Ngày 68: Informer

  • Mục tiêu: Theo dõi state hiệu quả.

  • Lý thuyết: watch + local cache + event handlers, giảm tải apiserver.

  • Thực hành: Chạy một informer in ra add/update/delete.

Ngày 69: SharedInformer & Lister

  • Mục tiêu: Chia sẻ cache.

  • Lý thuyết: SharedInformerFactory, Lister, Indexer.

  • Thực hành: Đọc qua Lister thay vì gọi apiserver trực tiếp.

Ngày 70: Work queue

  • Mục tiêu: Xử lý event có kiểm soát.

  • Lý thuyết: rate-limited queue, dedup, retry với backoff.

  • Thực hành: Cài workqueue; xử lý item + requeue khi lỗi.

Ngày 71: client-go tổng hợp

  • Mục tiêu: Ghép các mảnh.

  • Lý thuyết: informer → workqueue → reconcile → apiserver.

  • Thực hành: Viết một controller thô bằng client-go.

Ngày 72: Controller thô

  • Mục tiêu: Hiểu tận gốc trước khi dùng framework.

  • Lý thuyết: vòng đời controller, sync handler.

  • Thực hành: Hoàn thiện controller đếm/ghi nhãn một resource.

Ngày 73: controller-runtime

  • Mục tiêu: Framework hiện đại.

  • Lý thuyết: Manager, Reconciler, Client, cache, scheme.

  • Thực hành: Viết lại controller trên bằng controller-runtime.

Ngày 74: kubebuilder & Operator SDK

  • Mục tiêu: Scaffold nhanh.

  • Lý thuyết: kubebuilder markers, project layout, Operator SDK.

  • Thực hành: Scaffold một project kubebuilder.

Ngày 75: Reconcile đúng cách

  • Mục tiêu: Idempotent & bền.

  • Lý thuyết: requeue, backoff, tránh side-effect kép.

  • Thực hành: Làm reconcile idempotent; test gọi lặp.

Ngày 76: Owner refs & GC

  • Mục tiêu: Dọn tài nguyên con.

  • Lý thuyết: ownerReferences, garbage collection, cascade delete.

  • Thực hành: Set owner ref; xoá cha → con tự xoá.

Ngày 77: Finalizers

  • Mục tiêu: Cleanup trước khi xoá.

  • Lý thuyết: finalizer, deletion timestamp, external cleanup.

  • Thực hành: Thêm finalizer gọi cleanup ngoài cluster.

Ngày 78: Status & conditions

  • Mục tiêu: Báo cáo trạng thái.

  • Lý thuyết: status subresource, conditions, observedGeneration.

  • Thực hành: Cập nhật status + conditions chuẩn.

Ngày 79: Events

  • Mục tiêu: Ghi lại điều xảy ra.

  • Lý thuyết: EventRecorder, reason/message.

  • Thực hành: Phát event; xem kubectl describe.

Ngày 80: Leader election

  • Mục tiêu: Controller HA.

  • Lý thuyết: lease-based leader election, tránh double-reconcile.

  • Thực hành: Bật leader election; chạy 2 replica.

Ngày 81: Caching & reads

  • Mục tiêu: Đọc hiệu quả & đúng.

  • Lý thuyết: cache-backed client vs direct read, stale cache.

  • Thực hành: Khi nào cần đọc direct (uncached); thử nghiệm.

Ngày 82: Optimistic concurrency

  • Mục tiêu: Cập nhật an toàn.

  • Lý thuyết: resourceVersion conflict, retry-on-conflict, server-side apply.

  • Thực hành: Gây conflict; xử lý retry.

Ngày 83: Webhooks (tích hợp)

  • Mục tiêu: Bắc cầu Khối E.

  • Lý thuyết: admission webhook gắn với controller-runtime.

  • Thực hành: Scaffold webhook (chưa logic).

Ngày 84: Rate limiting & hiệu năng

  • Mục tiêu: Controller chịu tải.

  • Lý thuyết: client rate limit, concurrent reconciles, resync period.

  • Thực hành: Đo throughput reconcile; tuning.

Ngày 85: Testing controller

  • Mục tiêu: Kiểm thử tin cậy.

  • Lý thuyết: envtest (apiserver+etcd giả), fake client.

  • Thực hành: Viết test reconcile với envtest.

Ngày 86: Observability controller

  • Mục tiêu: Nhìn thấy controller (nối Layer 7).

  • Lý thuyết: metrics (reconcile time, queue depth), logs có cấu trúc.

  • Thực hành: Expose Prometheus metrics từ controller.

Ngày 87: Level vs edge triggered

  • Mục tiêu: Hiểu lựa chọn thiết kế k8s.

  • Lý thuyết: vì sao level-triggered bền hơn edge; self-healing.

  • Thực hành: Mô phỏng mất event; level-triggered vẫn hội tụ.

Ngày 88: Patterns & anti-patterns

  • Mục tiêu: Viết controller tốt.

  • Lý thuyết: single source of truth, không lưu state ngoài, idempotency.

  • Thực hành: Checklist review controller.

Ngày 89: Ôn Khối C

  • Mục tiêu: Sẵn sàng cho flagship.

  • Lý thuyết: rà informer/cache/queue/reconcile/finalizer/status.

  • Thực hành: Chuẩn bị thiết kế Operator.

Ngày 90: CỘT MỐC 90

  • Mục tiêu: Chốt control plane engineering.

  • Lý thuyết: Ôn C; kiểm kê: viết được controller đúng chuẩn với controller-runtime.

  • Thực hành: Đề thi #3 (informer/reconcile/finalizer/status) + tự chấm; blog #45 ("Bên trong một Kubernetes controller: informer, work queue, reconcile"); tag layer4-day090; nghỉ nửa ngày.

KHỐI D - CRD + Controller + Operator (Ngày 91-124) → P2 flagship

Ngày 91: CRD - nền

  • Mục tiêu: Mở rộng API k8s.

  • Lý thuyết: CustomResourceDefinition, custom resource, API group.

  • Thực hành: Tạo một CRD đơn giản; apply CR.

Ngày 92: CRD - schema

  • Mục tiêu: Ràng buộc & mặc định.

  • Lý thuyết: OpenAPI v3 schema, validation, defaulting, x-kubernetes markers.

  • Thực hành: Thêm validation + default cho CRD.

Ngày 93: CRD - versioning

  • Mục tiêu: Tiến hoá API.

  • Lý thuyết: multi-version, storage version, conversion webhook.

  • Thực hành: Thêm version v1beta1→v1; scaffold conversion.

Ngày 94: CRD - subresources

  • Mục tiêu: Status & scale.

  • Lý thuyết: status subresource, scale subresource, printer columns.

  • Thực hành: Bật /status + /scale + additionalPrinterColumns.

Ngày 95: Operator pattern

  • Mục tiêu: Khi nào cần operator.

  • Lý thuyết: encode operational knowledge, day-2 operations.

  • Thực hành: Liệt kê ứng viên domain cho flagship.

Ngày 96: Thiết kế flagship

  • Mục tiêu: Đóng khung P2.

  • Lý thuyết: chọn domain (ví dụ CRD AppPlatform: app + service + ingress + config).

  • Thực hách: operator-design.md: API + reconcile model.

Ngày 97: API design

  • Mục tiêu: Spec/status tốt.

  • Lý thuyết: declarative spec, status phản ánh thực tế, conditions.

  • Thực hành: Định nghĩa types Go cho CRD.

Ngày 98: Scaffold

  • Mục tiêu: Khung code.

  • Lý thuyết: kubebuilder generate CRD + controller skeleton.

  • Thực hành: Scaffold + apply CRD lên cluster.

Ngày 99: API types

  • Mục tiêu: Hoàn thiện spec/status.

  • Lý thuyết: markers cho validation/default/printcolumn.

  • Thực hành: Cài đầy đủ types + generate manifests.

Ngày 100:

  • Mục tiêu: Kiểm kê lớn giữa Layer 4.

  • Lý thuyết: Ôn A→C + đầu D; kiểm kê lớn: OCI runtime + hiểu control plane + viết controller + CRD; đối chiếu "Sâu".

  • Thực hành: Đề thi #4 tích lũy (container + core + control plane) + tự chấm theo rubric; blog #46 ("100 ngày cloud-native: từ OCI runtime tới CRD đầu tiên"); tag layer4-day100; nghỉ nửa ngày. Đã đi 100/210 (48%).

Ngày 101: Reconcile v1

  • Mục tiêu: Tạo tài nguyên con.

  • Lý thuyết: từ CR → Deployment/Service/ConfigMap.

  • Thực hành: Reconcile tạo child resources.

Ngày 102: Reconcile - idempotency & owner

  • Mục tiêu: An toàn khi lặp.

  • Lý thuyết: create-or-update, owner refs, server-side apply.

  • Thực hành: Đảm bảo reconcile lặp không đổi kết quả.

Ngày 103: Status & conditions

  • Mục tiêu: CR báo cáo trạng thái.

  • Lý thuyết: aggregate trạng thái con → status CR.

  • Thực hành: Cập nhật Ready/Progressing conditions.

Ngày 104: Finalizers & cleanup

  • Mục tiêu: Xoá sạch.

  • Lý thuyết: finalizer, xoá tài nguyên ngoài scope owner-ref.

  • Thực hành: Thêm finalizer + cleanup logic.

Ngày 105: Validation/defaulting webhook

  • Mục tiêu: Chặn cấu hình sai.

  • Lý thuyết: validating/mutating webhook cho CRD.

  • Thực hành: Cài webhook validate + default cho AppPlatform.

Ngày 106: Conversion webhook

  • Mục tiêu: Multi-version thật.

  • Lý thuyết: convert giữa versions, hub-and-spoke.

  • Thực hành: Cài conversion v1beta1↔v1.

Ngày 107: Xử lý drift

  • Mục tiêu: Tự chữa.

  • Lý thuyết: phát hiện thay đổi ngoài ý muốn, reconcile về desired.

  • Thực hành: Sửa tay child resource; operator kéo về.

Ngày 108: Tích hợp hệ ngoài

  • Mục tiêu: Operator điều khiển ngoài cluster.

  • Lý thuyết: gọi API ngoài (preview Crossplane), lưu state ở đâu.

  • Thực hành: Reconcile gọi một API giả lập bên ngoài.

Ngày 109: Error & requeue

  • Mục tiêu: Bền với lỗi.

  • Lý thuyết: phân loại lỗi, backoff, requeueAfter.

  • Thực hành: Chiến lược requeue theo loại lỗi.

Ngày 110: Observability operator

  • Mục tiêu: Nhìn thấy operator (nối Layer 7).

  • Lý thuyết: metrics, events, structured logs.

  • Thực hành: Thêm metrics reconcile + events.

Ngày 111: Testing - envtest

  • Mục tiêu: Test logic reconcile.

  • Lý thuyết: envtest, giả lập apiserver.

  • Thực hành: Test các nhánh reconcile.

Ngày 112: E2E test

  • Mục tiêu: Chạy thật.

  • Lý thuyết: test trên kind, apply CR → kiểm child + status.

  • Thực hành: E2E test trong CI.

Ngày 113: Upgrade & migration

  • Mục tiêu: Nâng cấp an toàn.

  • Lý thuyết: CRD migration, storage version bump.

  • Thực hành: Migrate CR sang version mới.

Ngày 114: OLM

  • Mục tiêu: Vòng đời operator.

  • Lý thuyết: Operator Lifecycle Manager, bundle, catalog.

  • Thực hành: Đóng gói operator theo OLM (khái niệm + thử).

Ngày 115: Packaging

  • Mục tiêu: Phân phối operator.

  • Lý thuyết: Helm chart / kustomize cho CRD + controller + RBAC.

  • Thực hành: Đóng gói cài đặt bằng Helm.

Ngày 116: RBAC least-privilege

  • Mục tiêu: Operator an toàn.

  • Lý thuyết: quyền tối thiểu cho controller.

  • Thực hành: Rà + siết ClusterRole của operator.

Ngày 117: Multi-tenancy cho operator

  • Mục tiêu: Chạy chung an toàn.

  • Lý thuyết: namespace-scoped vs cluster-scoped, isolation.

  • Thực hành: Cấu hình operator theo tenant model.

Ngày 118: Hiệu năng quy mô lớn

  • Mục tiêu: Nhiều CR.

  • Lý thuyết: concurrent reconciles, cache pressure, resync.

  • Thực hành: Load test với nhiều CR; tuning.

Ngày 119: Hardening

  • Mục tiêu: Chuẩn bảo mật (nối Layer 8).

  • Lý thuyết: webhook TLS, image, supply chain.

  • Thực hành: Rà bảo mật operator.

Ngày 120: CỘT MỐC 120

  • Mục tiêu: Chốt phần chính operator.

  • Lý thuyết: Ôn D; kiểm kê: CRD + reconcile + webhook + finalizer + status hoàn chỉnh.

  • Thực hành: Đề thi #5 (CRD/operator/webhook) + tự chấm; blog #47 ("Thiết kế một Operator: CRD, reconcile, finalizer, webhook"); tag layer4-day120; nghỉ nửa ngày. Đã đi 120/210 (57%).

Ngày 121: Hoàn thiện tính năng

  • Mục tiêu: Operator đủ dùng.

  • Lý thuyết: rà use case còn thiếu.

  • Thực hành: Bổ sung tính năng còn thiếu.

Ngày 122: Docs & examples

  • Mục tiêu: Dùng lại được.

  • Lý thuyết: README, API reference, ví dụ CR.

  • Thực hành: Viết docs + samples.

Ngày 123: Benchmark & chaos

  • Mục tiêu: Bền vững (nối Layer 11).

  • Lý thuyết: kill controller giữa reconcile, đảm bảo hội tụ.

  • Thực hành: Chaos test; xác nhận self-healing.

Ngày 124: P2 - Kubernetes Operator hoàn chỉnh

  • Mục tiêu: Release flagship.

  • Lý thuyết: rà "done": CRD + controller + webhook + tests + packaging.

  • Thực hành: Đóng gói + blog #48 ("Một Operator hoàn chỉnh từ số 0"). P2 done.

KHỐI E - Admission Control + Autoscaling (Ngày 125-150) → P3

Ngày 125: Admission control deep

  • Mục tiêu: Chặn/sửa ở apiserver.

  • Lý thuyết: mutating trước, validating sau, admission chain.

  • Thực hành: Vẽ vòng đời request qua admission.

Ngày 126: Validating webhook

  • Mục tiêu: Từ chối cấu hình xấu.

  • Lý thuyết: ValidatingWebhookConfiguration, review request/response.

  • Thực hành: Webhook từ chối pod thiếu label bắt buộc.

Ngày 127: Mutating webhook

  • Mục tiêu: Tự sửa/inject.

  • Lý thuyết: patch (JSONPatch), inject sidecar-style.

  • Thực hành: Webhook inject default resources/labels.

Ngày 128: Webhook vận hành

  • Mục tiêu: Không làm sập cluster.

  • Lý thuyết: failurePolicy, timeout, ordering, side effects, namespaceSelector.

  • Thực hành: Cấu hình fail-open/closed đúng chỗ; tránh self-lockout.

Ngày 129: OPA/Gatekeeper

  • Mục tiêu: Policy engine.

  • Lý thuyết: Rego, ConstraintTemplate, Constraint, audit.

  • Thực hành: Viết constraint cấm image latest.

Ngày 130: Gatekeeper - audit & mở rộng

  • Mục tiêu: Policy toàn cluster.

  • Lý thuyết: audit mode, mutation (Gatekeeper), external data.

  • Thực hành: Audit vi phạm hiện có; báo cáo.

Ngày 131: Kyverno

  • Mục tiêu: Policy kiểu k8s-native.

  • Lý thuyết: policy là CRD, validate/mutate/generate, không cần Rego.

  • Thực hành: Kyverno policy validate + generate (ví dụ default NetworkPolicy).

Ngày 132: So sánh policy

  • Mục tiêu: Chọn công cụ.

  • Lý thuyết: Gatekeeper vs Kyverno vs webhook thủ công.

  • Thực hành: Bảng đánh đổi.

Ngày 133: Policy as code

  • Mục tiêu: Quản trị nhất quán.

  • Lý thuyết: validate/mutate/generate patterns, test policy.

  • Thực hành: Viết test cho policy.

Ngày 134: P3 - thiết kế

  • Mục tiêu: Đóng khung P3.

  • Lý thuyết: policy controller (webhook + bộ policy) cho platform.

  • Thực hành: policy-controller-design.md.

Ngày 135: P3 - validating rules

  • Mục tiêu: Chặn cấu hình nguy hiểm.

  • Lý thuyết: rule chặn privileged, hostPath, image không ký (nối Layer 8).

  • Thực hành: Cài + test validating rules.

Ngày 136: P3 - mutating rules

  • Mục tiêu: Áp default an toàn.

  • Lý thuyết: inject securityContext, resource defaults, labels.

  • Thực hành: Cài + test mutating rules.

Ngày 137: P3 - audit & report

  • Mục tiêu: Nhìn được vi phạm.

  • Lý thuyết: audit mode, PolicyReport.

  • Thực hành: Sinh report; dashboard đơn giản (nối Layer 7).

Ngày 138: P3 - test & package

  • Mục tiêu: Sẵn sàng release.

  • Lý thuyết: test coverage policy, packaging.

  • Thực hành: Đóng gói P3 (finalize ở mốc 150).

Ngày 139: Autoscaling - tổng quan

  • Mục tiêu: Ba trục co giãn.

  • Lý thuyết: horizontal (pod) vs vertical (pod) vs cluster (node).

  • Thực hành: Bản đồ khi nào dùng cái nào.

Ngày 140: HPA

  • Mục tiêu: Co giãn theo tải.

  • Lý thuyết: metrics, thuật toán, custom/external metrics.

  • Thực hành: HPA theo CPU + custom metric.

Ngày 141: Metrics pipeline

  • Mục tiêu: Nguồn metric cho HPA.

  • Lý thuyết: metrics-server, custom metrics API, Prometheus adapter (nối Layer 7).

  • Thực hành: Dựng Prometheus adapter cho custom metric.

Ngày 142: VPA

  • Mục tiêu: Chỉnh requests tự động.

  • Lý thuyết: recommend/auto mode, hạn chế (restart), xung đột HPA.

  • Thực hành: VPA recommend cho một workload.

Ngày 143: Cluster Autoscaler

  • Mục tiêu: Co giãn node.

  • Lý thuyết: scale-up theo pending pod, scale-down an toàn.

  • Thực hành: CA trên cluster có pending pods.

Ngày 144: Karpenter

  • Mục tiêu: Provisioning node hiện đại.

  • Lý thuyết: just-in-time nodes, consolidation, NodePool.

  • Thực hành: So Karpenter vs Cluster Autoscaler.

Ngày 145: KEDA

  • Mục tiêu: Event-driven scaling.

  • Lý thuyết: scaler (Kafka/queue), scale-to-zero.

  • Thực hành: KEDA scale theo độ dài queue.

Ngày 146: Tương tác & bẫy

  • Mục tiêu: Tránh xung đột.

  • Lý thuyết: HPA+VPA conflict, thrashing, stabilization window.

  • Thực hành: Thiết kế autoscaling ổn định.

Ngày 147: Capacity & cost

  • Mục tiêu: Co giãn có kinh tế (nối Layer 11).

  • Lý thuyết: bin-packing, spot, overprovision, FinOps preview.

  • Thực hành: Ước lượng cost khi scale.

Ngày 148: Lab autoscaling E2E

  • Mục tiêu: Ghép lại.

  • Lý thuyết: HPA + Karpenter/CA cùng hoạt động.

  • Thực hành: Load test → pod scale → node scale; quan sát.

Ngày 149: Ôn Khối E; P3 finalize

  • Mục tiêu: Chốt admission + autoscaling.

  • Lý thuyết: rà webhook/policy + HPA/VPA/CA/Karpenter/KEDA.

  • Thực hành: Hoàn thiện + test P3.

Ngày 150: CỘT MỐC 150

  • Mục tiêu: Chốt policy & co giãn; release P3.

  • Lý thuyết: Ôn E; kiểm kê: policy controller + autoscaling stack.

  • Thực hành: P3 done; đề thi #6 (admission/policy/autoscaling) + tự chấm; blog #49 ("Policy-as-code và autoscaling trong Kubernetes"); tag layer4-day150; nghỉ nửa ngày. Đã đi 150/210 (71%).

KHỐI F - Service Mesh + xDS (Ngày 151-178) → P4

Ngày 151: Service mesh - vì sao

  • Mục tiêu: Bài toán mesh giải quyết.

  • Lý thuyết: mTLS, traffic mgmt, observability tách khỏi app; sidecar model.

  • Thực hành: Liệt kê cross-cutting concerns mesh xử lý.

Ngày 152: Data plane vs control plane

  • Mục tiêu: Hai mặt của mesh.

  • Lý thuyết: proxy (data) + control (config/policy), tách biệt.

  • Thực hành: Vẽ kiến trúc mesh.

Ngày 153: Envoy - kiến trúc

  • Mục tiêu: Proxy nền tảng.

  • Lý thuyết: listeners, routes, clusters, endpoints, filters.

  • Thực hành: Chạy Envoy config tĩnh; proxy một service.

Ngày 154: Envoy - filter chain

  • Mục tiêu: Xử lý request.

  • Lý thuyết: HTTP connection manager, filter chain, retry/timeout.

  • Thực hành: Thêm filter (header manipulation, rate limit local).

Ngày 155: Envoy tĩnh → động

  • Mục tiêu: Vì sao cần xDS.

  • Lý thuyết: hạn chế config tĩnh, cần cập nhật động.

  • Thực hành: Chuyển một phần config sang dynamic.

Ngày 156: xDS overview

  • Mục tiêu: Giao thức cấu hình Envoy.

  • Lý thuyết: LDS/RDS/CDS/EDS, discovery services.

  • Thực hành: Map từng xDS sang thành phần Envoy.

Ngày 157: ADS

  • Mục tiêu: Cấu hình nhất quán.

  • Lý thuyết: aggregated xDS, ordering, tránh traffic drop.

  • Thực hành: Đọc luồng ADS; hiểu thứ tự cập nhật.

Ngày 158: SDS & delta xDS

  • Mục tiêu: Secret & hiệu quả.

  • Lý thuyết: SDS (cert cho mTLS), delta (incremental) xDS.

  • Thực hành: Cấp cert qua SDS.

Ngày 159: xDS protocol

  • Mục tiêu: Cơ chế truyền.

  • Lý thuyết: gRPC streaming, version/nonce, ACK/NACK.

  • Thực hành: Bắt gRPC stream giữa Envoy và control plane.

Ngày 160: P4 - xDS control plane (nền)

  • Mục tiêu: Bắt đầu P4.

  • Lý thuyết: go-control-plane, snapshot cache.

  • Thực hành: Control plane phục vụ Envoy một cấu hình tối giản.

Ngày 161: P4 - CDS/EDS

  • Mục tiêu: Cluster & endpoint động.

  • Lý thuyết: khai báo cluster + endpoints từ nguồn (k8s Service).

  • Thực hành: Đẩy CDS/EDS; Envoy route tới backend.

Ngày 162: P4 - LDS/RDS

  • Mục tiêu: Listener & routing động.

  • Lý thuyết: listener + route config động.

  • Thực hành: Định tuyến theo path/host qua RDS.

Ngày 163: P4 - cập nhật động

  • Mục tiêu: Zero-drop reconfig.

  • Lý thuyết: snapshot versioning, watch nguồn (informer, nối Khối C).

  • Thực hành: Thay đổi backend → Envoy cập nhật không rớt kết nối.

Ngày 164: Istio - kiến trúc

  • Mục tiêu: Mesh sản xuất.

  • Lý thuyết: istiod, sidecar injection, xDS phía sau.

  • Thực hành: Cài Istio; inject sidecar cho một app.

Ngày 165: Istio - traffic management

  • Mục tiêu: Điều khiển lưu lượng.

  • Lý thuyết: VirtualService, DestinationRule, subset.

  • Thực hành: Route theo header/weight.

Ngày 166: Istio - security

  • Mục tiêu: mTLS & policy.

  • Lý thuyết: PeerAuthentication (mTLS), AuthorizationPolicy.

  • Thực hành: Bật mTLS strict; áp authz.

Ngày 167: Istio ambient mesh

  • Mục tiêu: Mesh không sidecar.

  • Lý thuyết: ztunnel (L4) + waypoint (L7), tiết kiệm tài nguyên.

  • Thực hành: Thử ambient mode; so với sidecar.

Ngày 168: Sidecar vs ambient

  • Mục tiêu: Chọn mô hình.

  • Lý thuyết: overhead, độ trễ, vận hành.

  • Thực hành: Bảng đánh đổi.

Ngày 169: Observability mesh

  • Mục tiêu: Nhìn thấy traffic (nối Layer 7).

  • Lý thuyết: telemetry, distributed tracing, golden signals.

  • Thực hành: Xem traces/metrics từ mesh.

Ngày 170: Resilience trong mesh

  • Mục tiêu: Chịu lỗi.

  • Lý thuyết: retry, timeout, circuit breaking, outlier detection.

  • Thực hành: Cấu hình + mô phỏng backend lỗi.

Ngày 171: Traffic shifting

  • Mục tiêu: Canary qua mesh (nối Layer 6).

  • Lý thuyết: weighted routing, progressive shift.

  • Thực hành: Canary 5%→100% một version.

Ngày 172: Multi-cluster mesh (preview)

  • Mục tiêu: Mesh xuyên cluster.

  • Lý thuyết: east-west gateway, shared trust.

  • Thực hành: Đọc kiến trúc multi-cluster mesh.

Ngày 173: eBPF-based mesh

  • Mục tiêu: Mesh sidecarless kiểu khác.

  • Lý thuyết: Cilium service mesh, eBPF datapath (nối Layer 2).

  • Thực hành: So mô hình eBPF vs Envoy sidecar.

Ngày 174: P4 - điều khiển Envoy fleet

  • Mục tiêu: Control plane thực dụng.

  • Lý thuyết: nhiều Envoy, per-node/per-workload config.

  • Thực hành: Control plane phục vụ nhiều Envoy.

Ngày 175: P4 - mTLS qua SDS

  • Mục tiêu: Bảo mật kết nối.

  • Lý thuyết: cấp/rotate cert qua SDS.

  • Thực hành: Bật mTLS giữa các Envoy do control plane cấp.

Ngày 176: P4 - dynamic routing/canary

  • Mục tiêu: Ứng dụng thật.

  • Lý thuyết: weighted route động từ control plane.

  • Thực hành: Canary điều khiển từ control plane.

Ngày 177: P4 - test & benchmark

  • Mục tiêu: Đảm bảo tin cậy.

  • Lý thuyết: đo latency thêm vào, zero-drop khi reconfig.

  • Thực hành: Benchmark + chaos reconfig.

Ngày 178: P4 - xDS control plane

  • Mục tiêu: Release P4.

  • Lý thuyết: rà "done": LDS/RDS/CDS/EDS + SDS + dynamic update.

  • Thực hành: Writeup + blog #50 ("Tự viết một control plane xDS điều khiển Envoy"). P4 done.

KHỐI G - API Gateway (Ngày 179-190)

Ngày 179: Gateway vs Ingress vs Mesh

  • Mục tiêu: Định vị API gateway.

  • Lý thuyết: north-south (gateway) vs east-west (mesh), Ingress cũ.

  • Thực hành: Sơ đồ vị trí gateway trong kiến trúc.

Ngày 180: CỘT MỐC 180

  • Mục tiêu: Chốt mesh; vào gateway.

  • Lý thuyết: Ôn F; kiểm kê: xDS control plane + hiểu Istio/ambient.

  • Thực hành: Đề thi #7 (Envoy/xDS/Istio) + tự chấm; blog #51 ("Service mesh và xDS: điều khiển hàng nghìn proxy"); tag layer4-day180; nghỉ nửa ngày.

Ngày 181: Vì sao Gateway API

  • Mục tiêu: Kế thừa Ingress.

  • Lý thuyết: hạn chế Ingress, role-oriented, mở rộng.

  • Thực hành: Đọc spec Gateway API.

Ngày 182: Gateway API - tài nguyên

  • Mục tiêu: Mô hình mới.

  • Lý thuyết: GatewayClass, Gateway, HTTPRoute, TCPRoute.

  • Thực hành: Expose app qua Gateway + HTTPRoute.

Ngày 183: Gateway API - role & GAMMA

  • Mục tiêu: Phân vai infra/app + mesh.

  • Lý thuyết: infra provider vs app dev; GAMMA (mesh dùng Gateway API).

  • Thực hành: Tách quyền GatewayClass vs HTTPRoute.

Ngày 184: Envoy Gateway

  • Mục tiêu: Gateway API trên Envoy.

  • Lý thuyết: Envoy Gateway = Gateway API + Envoy + xDS (nối P4).

  • Thực hành: Cài Envoy Gateway; route một app.

Ngày 185: Kong

  • Mục tiêu: Gateway plugin-rich.

  • Lý thuyết: plugin architecture, DB-less, Kong Ingress Controller.

  • Thực hành: Cấu hình auth + rate limit plugin.

Ngày 186: APISIX

  • Mục tiêu: Gateway động.

  • Lý thuyết: dynamic routing, plugins, etcd-backed.

  • Thực hành: So APISIX với Kong/Envoy Gateway.

Ngày 187: Tính năng gateway

  • Mục tiêu: Chức năng thường dùng.

  • Lý thuyết: rate limit, auth (JWT/OIDC), transformation, WAF.

  • Thực hành: Áp một chuỗi policy tại gateway.

Ngày 188: TLS & cert

  • Mục tiêu: Vào bằng HTTPS.

  • Lý thuyết: cert-manager, ACME, TLS termination/passthrough.

  • Thực hành: cert-manager cấp cert tự động cho Gateway.

Ngày 189: Lab gateway E2E

  • Mục tiêu: Ghép lại.

  • Lý thuyết: Gateway API + policy + TLS.

  • Thực hành: Expose app đầy đủ auth + rate limit + TLS.

Ngày 190: So sánh gateways

  • Mục tiêu: Chọn đúng.

  • Lý thuyết: Envoy Gateway vs Kong vs APISIX theo bối cảnh.

  • Thực hành: Ma trận quyết định.

KHỐI H - Platform Abstractions + Multi-tenancy (Ngày 191-200)

Ngày 191: Trừu tượng trên k8s

  • Mục tiêu: Vì sao cần lớp platform.

  • Lý thuyết: k8s là "platform for platforms", self-service.

  • Thực hành: Liệt kê thứ cần trừu tượng cho dev.

Ngày 192: Crossplane - nền

  • Mục tiêu: Control plane cho hạ tầng.

  • Lý thuyết: XRD, Composition, Composite Resource, providers.

  • Thực hành: Cài Crossplane; định nghĩa một XRD.

Ngày 193: Crossplane - managed resources

  • Mục tiêu: Điều khiển cloud từ k8s (nối Layer 5).

  • Lý thuyết: provider AWS/GCP, managed resource reconcile.

  • Thực hành: Provision một tài nguyên (mock/local) qua Crossplane.

Ngày 194: Crossplane - compose platform API

  • Mục tiêu: Self-service infra.

  • Lý thuyết: compose nhiều managed resource thành một API cấp cao.

  • Thực hành: Tạo Database XR self-service.

Ngày 195: KCP

  • Mục tiêu: Control plane tách cluster.

  • Lý thuyết: workspaces, transparent multi-cluster, API export.

  • Thực hành: Đọc kiến trúc KCP; use case.

Ngày 196: Mô hình multi-tenancy

  • Mục tiêu: Chạy nhiều tenant.

  • Lý thuyết: namespace vs cluster vs virtual cluster; soft vs hard isolation.

  • Thực hành: Bảng đánh đổi các mô hình.

Ngày 197: vcluster

  • Mục tiêu: Virtual cluster.

  • Lý thuyết: control plane ảo trong namespace, isolation mạnh hơn namespace.

  • Thực hành: Dựng vcluster cho một tenant.

Ngày 198: Capsule & HNC

  • Mục tiêu: Multi-tenancy nhẹ.

  • Lý thuyết: Capsule (tenant), Hierarchical Namespaces.

  • Thực hành: Dựng tenant với HNC; quan sát policy propagation.

Ngày 199: Tenant isolation

  • Mục tiêu: Cách ly thật (nối Layer 8).

  • Lý thuyết: RBAC + NetworkPolicy + ResourceQuota + PSA + node isolation.

  • Thực hành: Áp bộ isolation đầy đủ cho một tenant.

Ngày 200:

  • Mục tiêu: Kiểm kê lớn cận cuối Layer 4.

  • Lý thuyết: Ôn A→H; kiểm kê lớn: OCI runtime + operator + policy + xDS + gateway + platform abstractions; đối chiếu "Sâu".

  • Thực hành: Đề thi #8 tích lũy (toàn cloud-native) + tự chấm theo rubric; blog #52 ("200 ngày cloud-native: container, operator, mesh, platform"); tag layer4-day200; nghỉ nửa ngày. Đã đi 200/210 (95%).

KHỐI I - GitOps + Multi-cluster (Ngày 201-210) → P5 platform capstone

Ngày 201: GitOps - nguyên lý

  • Mục tiêu: Git là nguồn sự thật.

  • Lý thuyết: declarative + Git + pull-based reconcile + drift detection.

  • Thực hành: Sơ đồ vòng GitOps.

Ngày 202: ArgoCD

  • Mục tiêu: GitOps phổ biến.

  • Lý thuyết: Application, sync, app-of-apps, ApplicationSet.

  • Thực hành: Triển khai app qua ArgoCD từ Git.

Ngày 203: Flux

  • Mục tiêu: GitOps kiểu controller.

  • Lý thuyết: source/kustomize/helm controllers, image automation.

  • Thực hành: Triển khai app qua Flux; image update tự động.

Ngày 204: ArgoCD vs Flux + progressive delivery

  • Mục tiêu: Chọn & nối Layer 6.

  • Lý thuyết: so sánh; Argo Rollouts/Flagger (canary, nối Layer 6).

  • Thực hành: Canary qua GitOps (preview).

Ngày 205: Multi-cluster - Cluster API

  • Mục tiêu: Cluster như tài nguyên (nối Metal³ Layer 3).

  • Lý thuyết: Cluster API, declarative cluster lifecycle.

  • Thực hách: Đọc kiến trúc CAPI; tạo cluster khai báo (mock).

Ngày 206: Multi-cluster - fleet

  • Mục tiêu: Quản lý nhiều cluster.

  • Lý thuyết: Karmada/Open Cluster Management, federation, placement.

  • Thực hành: Đọc mô hình fleet; deploy tới nhiều cluster (khái niệm/lab nhỏ).

Ngày 207: P5 - tích hợp platform

  • Mục tiêu: Ghép tất cả thành một platform.

  • Lý thuyết: operator (P2) + Gateway API + GitOps + multi-tenancy.

  • Thực hành: Dựng platform: dev apply CR → operator tạo app + expose + policy.

Ngày 208: P5 - golden path self-service

  • Mục tiêu: Trải nghiệm dev (preview Layer 6 IDP).

  • Lý thuyết: self-service qua CR/Git, guardrails bằng policy.

  • Thực hành: Một golden path: từ Git → app chạy, có mesh + gateway + policy.

Ngày 209: P5 - E2E & docs; ôn Layer 4

  • Mục tiêu: Hoàn thiện.

  • Lý thuyết: rà toàn platform + docs.

  • Thực hành: E2E test platform; viết docs/RFC (nối Layer 6).

Ngày 210: HOÀN THÀNH LAYER 4

  • Mục tiêu: Chốt Cloud Native Engineering ở mức Sâu.

  • Lý thuyết: Ôn toàn layer; kiểm kê tổng: P1 OCI/CRI runtime + P2 Operator + P3 policy controller + P4 xDS control plane + P5 Kubernetes Platform.

  • Thực hành: P5 done; đề thi #9 tích lũy (toàn layer) + tự chấm theo rubric; blog #53 ("Nhìn lại 210 ngày cloud-native: tự xây một Kubernetes Platform"); tag layer4-complete; nghỉ nửa ngày

LAYER 5 - CLOUD PLATFORM ENGINEERING

Tài nguyên: AWS Well-Architected, docs AWS/Azure/GCP, Terraform: Up & Running (Brikman), HashiCorp Vault/Boundary docs, BeyondCorp papers, CIS Benchmarks.

KHỐI A - Public Cloud Core (Ngày 1-36)

Ngày 1: Khởi động Layer 5

  • Mục tiêu: Đặt khung tư duy cloud + lab an toàn.

  • Lý thuyết: shared responsibility model, region/AZ, control plane vs data plane của cloud.

  • Thực hành: Repo cloud-platform/; tạo tài khoản sandbox + billing alert.

Ngày 2: Mô hình tài khoản & tổ chức

  • Mục tiêu: Ranh giới quản trị.

  • Lý thuyết: AWS Account/Organizations/OU · Azure Subscription/Management Group · GCP Project/Folder/Org.

  • Thực hành: Vẽ cây tổ chức mục tiêu cho doanh nghiệp giả định.

Ngày 3: IAM - nguyên lý

  • Mục tiêu: Nền của mọi thứ trong cloud.

  • Lý thuyết: principal, policy, permission, resource; deny-by-default.

  • Thực hành: Đọc một IAM policy JSON; giải thích từng phần.

Ngày 4: AWS IAM (vừa đủ)

  • Mục tiêu: Mô hình IAM chuẩn.

  • Lý thuyết: user/role/policy, STS assume-role, permission boundary, trust policy.

  • Thực hành: Tạo role + trust policy; assume-role bằng STS.

Ngày 5: IAM - policy evaluation

  • Mục tiêu: Vì sao được/không được.

  • Lý thuyết: thứ tự đánh giá (explicit deny > allow), SCP, resource policy, session policy.

  • Thực hành: Debug một "access denied" bằng policy simulator.

Ngày 6: IAM cross-cloud

  • Mục tiêu: Nắm mô hình chung.

  • Lý thuyết: Azure RBAC + Entra ID · GCP IAM (role binding, predefined/custom).

  • Thực hành: Bảng ánh xạ khái niệm IAM giữa 3 cloud.

Ngày 7: Identity federation

  • Mục tiêu: Đăng nhập tập trung.

  • Lý thuyết: SAML/OIDC federation, SSO, IAM Identity Center, workload identity federation.

  • Thực hành: Cấu hình OIDC federation (ví dụ CI → cloud không cần key dài hạn).

Ngày 8: Compute - máy ảo

  • Mục tiêu: Đơn vị compute cơ bản.

  • Lý thuyết: EC2/VM/Compute Engine, instance type, spot/preemptible, autoscaling group.

  • Thực hành: Dựng một VM + user-data; ghi chú spot vs on-demand.

Ngày 9: Compute - image & lifecycle

  • Mục tiêu: Máy chuẩn hoá.

  • Lý thuyết: AMI/image, golden image, immutable infra (preview Packer).

  • Thực hành: Tạo custom image; boot từ image đó.

Ngày 10: Storage - object

  • Mục tiêu: Lưu trữ chủ đạo cloud (nối Layer 3).

  • Lý thuyết: S3/Blob/GCS, class, lifecycle, versioning, consistency.

  • Thực hành: Bucket + lifecycle + versioning; policy truy cập.

Ngày 11: Storage - block & file

  • Mục tiêu: Lưu trữ gắn máy.

  • Lý thuyết: EBS/Managed Disk/PD, snapshot; EFS/Filestore.

  • Thực hành: Gắn volume + snapshot + restore.

Ngày 12: Managed database

  • Mục tiêu: DB không tự vận hành (nối Layer 3 internals).

  • Lý thuyết: RDS/Aurora, Cloud SQL, Cosmos/DynamoDB, backup, read replica.

  • Thực hành: Dựng managed Postgres; test failover/backup.

Ngày 13: Messaging & queue

  • Mục tiêu: Ghép hệ phân tán.

  • Lý thuyết: SQS/SNS, Pub/Sub, Event Grid, at-least-once semantics.

  • Thực hành: Queue + consumer; quan sát retry/DLQ.

Ngày 14: Managed Kubernetes

  • Mục tiêu: K8s trên cloud (nối Layer 4).

  • Lý thuyết: EKS/AKS/GKE, node pool, control plane managed, IAM ↔ RBAC (IRSA/Workload Identity).

  • Thực hành: Dựng cluster managed; map cloud identity → pod.

Ngày 15: Observability của cloud

  • Mục tiêu: Nhìn thấy tài nguyên (nối Layer 7).

  • Lý thuyết: CloudWatch/Monitor/Cloud Logging, metrics/logs/alarms.

  • Thực hành: Dashboard + alarm cho một service.

Ngày 16: Cost model

  • Mục tiêu: Hiểu tiền (nối Layer 11 FinOps).

  • Lý thuyết: on-demand/reserved/savings plan/spot, egress cost, tagging cho cost.

  • Thực hành: Đọc cost explorer; ước tính chi phí một kiến trúc.

Ngày 17: Region & data residency

  • Mục tiêu: Chọn nơi đặt.

  • Lý thuyết: latency, sovereignty/compliance, multi-region tradeoff.

  • Thực hành: Quyết định region cho use case giả định.

Ngày 18: Encryption & KMS

  • Mục tiêu: Mã hoá dữ liệu (nối Layer 8).

  • Lý thuyết: KMS/Key Vault/Cloud KMS, envelope encryption, CMK vs managed key.

  • Thực hành: Tạo CMK; mã hoá bucket/volume bằng CMK.

Ngày 19: Tagging & resource organization

  • Mục tiêu: Quản lý ở quy mô.

  • Lý thuyết: tag strategy, resource group, naming convention.

  • Thực hành: Chuẩn tag (owner/env/cost-center) áp cho tài nguyên.

Ngày 20: Service quotas & limits

  • Mục tiêu: Tránh bất ngờ vận hành.

  • Lý thuyết: quota, throttling, request increase.

  • Thực hành: Kiểm quota quan trọng; xin tăng (khái niệm).

Ngày 21: CLI & SDK

  • Mục tiêu: Tự động hoá tay.

  • Lý thuyết: aws/az/gcloud CLI, SDK, credential chain.

  • Thực hành: Script hoá một tác vụ bằng CLI.

Ngày 22: Billing & account hygiene

  • Mục tiêu: Tài khoản sạch, an toàn.

  • Lý thuyết: root account, MFA, budget, break-glass.

  • Thực hành: Bật MFA root, tạo budget, tách admin khỏi root.

Ngày 23: Well-Architected Framework

  • Mục tiêu: Khung đánh giá kiến trúc.

  • Lý thuyết: 6 trụ (operational/security/reliability/performance/cost/sustainability).

  • Thực hành: Review một kiến trúc theo 6 trụ.

Ngày 24: AWS core tổng hợp

  • Mục tiêu: Ghép dịch vụ AWS.

  • Lý thuyết: map compute/storage/db/network/iam thành một app 3 lớp.

  • Thực hành: Vẽ + dựng tay một web app 3 lớp.

Ngày 25: Azure core (đối chiếu)

  • Mục tiêu: Nắm khác biệt Azure.

  • Lý thuyết: Resource Manager, Management Group, Entra ID, VNet, Azure Policy.

  • Thực hành: Dựng tương đương app 3 lớp trên Azure (khái niệm/lab nhỏ).

Ngày 26: GCP core (đối chiếu)

  • Mục tiêu: Nắm khác biệt GCP.

  • Lý thuyết: project/folder/org, VPC global, IAM, Org Policy.

  • Thực hành: Dựng tương đương trên GCP (khái niệm/lab nhỏ).

Ngày 27: So sánh 3 cloud

  • Mục tiêu: Chọn cloud/multi-cloud.

  • Lý thuyết: mô hình mạng, IAM, quản trị tổ chức khác nhau ra sao.

  • Thực hành: Bảng đối chiếu 3 cloud theo từng mảng.

Ngày 28: Managed identity cho workload

  • Mục tiêu: App lấy quyền không cần secret.

  • Lý thuyết: instance profile/IRSA · Managed Identity · Workload Identity.

  • Thực hành: Cho một app đọc bucket qua managed identity (không key).

Ngày 29: Cloud networking preview

  • Mục tiêu: Bắc cầu Khối B.

  • Lý thuyết: VPC/VNet, subnet, security group, route.

  • Thực hành: Dựng VPC + subnet public/private cơ bản.

Ngày 30: CỘT MỐC 30

  • Mục tiêu: Chốt nền cloud core.

  • Lý thuyết: Ôn A; kiểm kê: IAM + compute/storage/db + tổ chức tài khoản + Well-Architected.

  • Thực hành: Đề thi #1 (IAM/core services/account model) + tự chấm; blog #54 ("Mô hình cloud: IAM, tổ chức tài khoản, và dịch vụ lõi"); tag layer5-day030; nghỉ nửa ngày. Đã đi 30/150 (20%).

Ngày 31: Public cloud edge

  • Mục tiêu: Đưa dịch vụ ra biên.

  • Lý thuyết: CDN (CloudFront), edge, global vs regional.

  • Thực hành: Đặt CDN trước bucket/app.

Ngày 32: Serverless preview

  • Mục tiêu: Bắc cầu Khối C.

  • Lý thuyết: managed vs serverless, khi nào dùng.

  • Thực hành: Liệt kê workload phù hợp serverless.

Ngày 33: Account provisioning tự động

  • Mục tiêu: Tạo account có kiểm soát.

  • Lý thuyết: Control Tower/Account Factory, vending machine.

  • Thực hành: Đọc mô hình account vending (chuẩn bị landing zone).

Ngày 34: Guardrails preview

  • Mục tiêu: Ràng buộc tổ chức.

  • Lý thuyết: SCP (AWS), Azure Policy, Org Policy (GCP) - deny toàn org.

  • Thực hành: Viết một SCP cấm region/hành vi nguy hiểm.

Ngày 35: Centralized logging preview

  • Mục tiêu: Audit tập trung.

  • Lý thuyết: CloudTrail/Activity Log/Audit Logs, log archive account.

  • Thực hành: Bật audit log; gom về một nơi (khái niệm).

Ngày 36: Ôn Khối A

  • Mục tiêu: Sẵn sàng đi networking.

  • Lý thuyết: rà cloud core + các preview cho landing zone.

  • Thực hành: Chuẩn bị lab networking.

KHỐI B - Cloud Networking (Ngày 37-58)

Ngày 37: VPC/VNet nền

  • Mục tiêu: Mạng ảo trong cloud.

  • Lý thuyết: CIDR, subnet, public/private, IGW/NAT (nối Layer 3).

  • Thực hành: VPC nhiều subnet + NAT gateway.

Ngày 38: Routing & gateways

  • Mục tiêu: Đường đi trong/ra.

  • Lý thuyết: route table, internet/NAT/egress-only gateway.

  • Thực hành: Cấu hình routing public/private đúng.

Ngày 39: Security group & NACL

  • Mục tiêu: Firewall cloud.

  • Lý thuyết: stateful SG vs stateless NACL, least-privilege network.

  • Thực hành: Siết SG chỉ mở cổng cần thiết.

Ngày 40: VPC peering

  • Mục tiêu: Nối hai mạng.

  • Lý thuyết: peering, non-transitive, CIDR overlap.

  • Thực hành: Peer hai VPC; test kết nối.

Ngày 41: Transit/hub-spoke

  • Mục tiêu: Mạng quy mô lớn.

  • Lý thuyết: Transit Gateway/vWAN/NCC, hub-spoke topology.

  • Thực hành: Vẽ + dựng hub-spoke với transit.

Ngày 42: Private connectivity tới service

  • Mục tiêu: Không đi Internet.

  • Lý thuyết: VPC endpoint/Private Link/Private Service Connect.

  • Thực hành: Truy cập S3/service qua private endpoint.

Ngày 43: Hybrid connectivity

  • Mục tiêu: Nối on-prem.

  • Lý thuyết: VPN, Direct Connect/ExpressRoute/Interconnect, BGP (nối Layer 3).

  • Thực hành: Dựng VPN site-to-site (lab/mô phỏng).

Ngày 44: Cloud DNS

  • Mục tiêu: Phân giải trong cloud (nối Layer 3).

  • Lý thuyết: Route53/Azure DNS/Cloud DNS, private zone, split-horizon.

  • Thực hành: Private + public zone; resolution routing.

Ngày 45: Cloud load balancing

  • Mục tiêu: Phân phối tải managed (nối Layer 3 L4/L7).

  • Lý thuyết: NLB (L4) vs ALB (L7), global LB, health check.

  • Thực hành: Dựng ALB + target group + health check.

Ngày 46: Global traffic management

  • Mục tiêu: Đa vùng.

  • Lý thuyết: anycast (nối Layer 3), latency/geo routing, failover.

  • Thực hành: DNS/global LB failover giữa 2 region.

Ngày 47: DDoS & WAF

  • Mục tiêu: Bảo vệ biên (nối Layer 8).

  • Lý thuyết: Shield/DDoS Protection, WAF rules.

  • Thực hành: Áp WAF rule cơ bản trước app.

Ngày 48: Network security posture

  • Mục tiêu: Mạng an toàn.

  • Lý thuyết: flow logs, network firewall, egress control.

  • Thực hành: Bật flow logs; phát hiện traffic bất thường.

Ngày 49: IPv6 & dual-stack

  • Mục tiêu: Địa chỉ hiện đại.

  • Lý thuyết: IPv6 trong VPC, dual-stack.

  • Thực hành: Bật IPv6 cho một subnet.

Ngày 50: Multi-region networking

  • Mục tiêu: Mạng xuyên vùng.

  • Lý thuyết: inter-region peering, egress cost, latency.

  • Thực hành: Nối 2 region qua transit; đo latency.

Ngày 51: k8s networking trên cloud

  • Mục tiêu: Nối Layer 4.

  • Lý thuyết: CNI cloud (VPC CNI), LoadBalancer service → cloud LB, Ingress.

  • Thực hành: Expose service EKS qua cloud LB.

Ngày 52: Service discovery & mesh trên cloud

  • Mục tiêu: Kết nối service.

  • Lý thuyết: Cloud Map/private DNS, mesh managed (App Mesh) (nối Layer 4).

  • Thực hành: Đăng ký service discovery.

Ngày 53: Network baseline cho landing zone

  • Mục tiêu: Chuẩn mạng doanh nghiệp.

  • Lý thuyết: shared network account, hub-spoke, centralized egress/firewall.

  • Thực hành: Thiết kế network baseline (dùng lại ở P3).

Ngày 54: Debug mạng cloud

  • Mục tiêu: Chẩn đoán thực chiến.

  • Lý thuyết: reachability analyzer, flow logs, common failure (SG/route/NAT).

  • Thực hành: Sửa một sự cố "không kết nối được".

Ngày 55: Đo & tối ưu mạng

  • Mục tiêu: Hiệu năng & chi phí.

  • Lý thuyết: egress cost, cross-AZ traffic, placement.

  • Thực hành: Giảm cross-AZ/egress cho một kiến trúc.

Ngày 56: Cloud networking cross-provider

  • Mục tiêu: Nắm khác biệt.

  • Lý thuyết: VPC global (GCP) vs regional (AWS), Azure VNet.

  • Thực hành: Bảng đối chiếu networking 3 cloud.

Ngày 57: Ôn Khối B

  • Mục tiêu: Khâu networking.

  • Lý thuyết: rà VPC → transit → hybrid → DNS → LB → security.

  • Thực hành: Chuẩn bị baseline mạng.

Ngày 58: Chuẩn bị Serverless

  • Mục tiêu: Bắc cầu Khối C.

  • Lý thuyết: networking cho serverless (VPC-attached functions).

  • Thực hành: Ghi chú ràng buộc mạng của FaaS.

KHỐI C - Serverless/FaaS (Ngày 59-70)

Ngày 59: Serverless - nguyên lý

  • Mục tiêu: Không quản server.

  • Lý thuyết: event-driven, pay-per-use, scale-to-zero, statelessness.

  • Thực hành: Deploy một function "hello".

Ngày 60: CỘT MỐC 60

  • Mục tiêu: Chốt cloud networking.

  • Lý thuyết: Ôn B; kiểm kê: VPC/transit/hybrid/DNS/LB + network baseline.

  • Thực hành: Đề thi #2 (VPC/routing/LB/hybrid) + tự chấm; blog #55 ("Cloud networking: VPC, transit, hybrid, và một network baseline doanh nghiệp"); tag layer5-day060; nghỉ nửa ngày. Đã đi 60/150 (40%).

Ngày 61: FaaS internals

  • Mục tiêu: Hiểu để tối ưu.

  • Lý thuyết: cold start, execution model, concurrency, memory/CPU coupling; microVM (nối Layer 2 Firecracker).

  • Thực hành: Đo cold vs warm; giảm cold start.

Ngày 62: Triggers & integration

  • Mục tiêu: Nối sự kiện.

  • Lý thuyết: HTTP/queue/storage/schedule triggers, event source mapping.

  • Thực hành: Function chạy khi có object mới trong bucket.

Ngày 63: API tầng serverless

  • Mục tiêu: Expose function.

  • Lý thuyết: API Gateway (managed), auth, throttling.

  • Thực hành: Expose function qua API Gateway + auth.

Ngày 64: State cho serverless

  • Mục tiêu: Lưu trạng thái.

  • Lý thuyết: managed DB/KV, idempotency, step functions/workflows.

  • Thực hành: Orchestrate nhiều function bằng workflow.

Ngày 65: Serverless containers

  • Mục tiêu: Ngoài function.

  • Lý thuyết: Fargate/Cloud Run/Container Apps, scale-to-zero cho container.

  • Thực hành: Deploy container serverless.

Ngày 66: Serverless observability

  • Mục tiêu: Debug hàm (nối Layer 7).

  • Lý thuyết: structured logs, tracing, cold start metrics.

  • Thực hành: Trace một invocation xuyên nhiều function.

Ngày 67: Serverless security & IAM

  • Mục tiêu: Ít quyền, an toàn.

  • Lý thuyết: function role least-privilege, secret injection.

  • Thực hành: Siết quyền function; inject secret an toàn.

Ngày 68: Serverless cost & limits

  • Mục tiêu: Kinh tế FaaS.

  • Lý thuyết: billing per-invocation, concurrency limit, khi nào KHÔNG dùng serverless.

  • Thực hành: So chi phí serverless vs container cho một tải.

Ngày 69: Serverless cross-provider

  • Mục tiêu: Nắm khác biệt.

  • Lý thuyết: Lambda vs Functions vs Cloud Functions/Run.

  • Thực hành: Bảng đối chiếu.

Ngày 70: Ôn Khối C

  • Mục tiêu: Chốt serverless.

  • Lý thuyết: rà FaaS + serverless container + integration.

  • Thực hành: Chuẩn bị IaC (sẽ IaC hoá tất cả).

KHỐI D - Infrastructure as Code (Ngày 71-100) → P1

Ngày 71: IaC - nguyên lý

  • Mục tiêu: Hạ tầng khai báo, versioned.

  • Lý thuyết: declarative vs imperative, idempotency, drift (nối reconcile Layer 4).

  • Thực hành: So tay-vs-IaC cho một tài nguyên.

Ngày 72: Terraform/OpenTofu nền

  • Mục tiêu: Công cụ IaC chủ đạo.

  • Lý thuyết: HCL, provider, resource, plan/apply/destroy.

  • Thực hành: Provision VPC + VM bằng Terraform/OpenTofu.

Ngày 73: State

  • Mục tiêu: Nguồn sự thật của IaC.

  • Lý thuyết: state file, remote backend, locking, sensitive data.

  • Thực hành: Dùng remote backend (S3+lock) an toàn.

Ngày 74: Variables & outputs

  • Mục tiêu: Cấu hình linh hoạt.

  • Lý thuyết: variable/locals/output, tfvars, precedence.

  • Thực hành: Tham số hoá một config.

Ngày 75: Modules

  • Mục tiêu: Tái sử dụng.

  • Lý thuyết: module input/output, versioning, registry.

  • Thực hành: Viết một module network tái dùng.

Ngày 76: Workspaces & environments

  • Mục tiêu: dev/stg/prod.

  • Lý thuyết: workspace vs thư mục env, tránh nhầm prod.

  • Thực hành: Tách môi trường an toàn.

Ngày 77: Dependency & graph

  • Mục tiêu: Thứ tự đúng.

  • Lý thuyết: implicit/explicit depends_on, resource graph, apply ordering.

  • Thực hành: Đọc terraform graph.

Ngày 78: Data sources & imports

  • Mục tiêu: Làm việc với hạ tầng có sẵn.

  • Lý thuyết: data source, import, brownfield.

  • Thực hành: Import một tài nguyên tạo tay vào state.

Ngày 79: Provisioners & lifecycle

  • Mục tiêu: Kiểm soát vòng đời.

  • Lý thuyết: lifecycle (prevent_destroy, create_before_destroy), khi nào tránh provisioner.

  • Thực hành: Zero-downtime replace bằng create_before_destroy.

Ngày 80: Terragrunt & DRY

  • Mục tiêu: Quản lý nhiều env/account.

  • Lý thuyết: Terragrunt, DRY backend/provider, dependency giữa stacks.

  • Thực hành: Cấu trúc repo đa account bằng Terragrunt (khái niệm/thử).

Ngày 81: Packer

  • Mục tiêu: Golden image as code.

  • Lý thuyết: Packer build, provisioner, image pipeline (nối immutable infra).

  • Thực hành: Build golden image bằng Packer.

Ngày 82: IaC testing

  • Mục tiêu: Đảm bảo đúng trước apply.

  • Lý thuyết: validate/fmt/plan review, terratest, checkov/tfsec (nối Layer 8).

  • Thực hành: Chạy static scan + một test terratest nhỏ.

Ngày 83: IaC CI/CD

  • Mục tiêu: Apply có kiểm soát.

  • Lý thuyết: plan trên PR, approval, apply pipeline, OIDC (không key).

  • Thực hành: Pipeline: PR → plan → review → apply.

Ngày 84: Policy-as-code cho IaC

  • Mục tiêu: Guardrail trước khi tạo (nối Khối F).

  • Lý thuyết: OPA/conftest, Sentinel, chặn config vi phạm.

  • Thực hành: Chặn resource public/không mã hoá bằng policy.

Ngày 85: Secrets trong IaC

  • Mục tiêu: Không lộ secret.

  • Lý thuyết: không hardcode, tham chiếu secret manager, state sensitivity.

  • Thực hành: Lấy secret runtime thay vì để trong code/state.

Ngày 86: Multi-account IaC

  • Mục tiêu: Quy mô tổ chức.

  • Lý thuyết: provider alias/assume-role, cấu trúc account.

  • Thực hành: Apply xuyên nhiều account bằng assume-role.

Ngày 87: Drift & reconciliation

  • Mục tiêu: Giữ thực tế = code.

  • Lý thuyết: drift detection, refresh, GitOps cho infra (Crossplane, nối Layer 4).

  • Thực hành: Gây drift; phát hiện + hoà giải.

Ngày 88: CDK/Pulumi

  • Mục tiêu: IaC bằng ngôn ngữ lập trình.

  • Lý thuyết: CDK/Pulumi vs HCL, khi nào chọn.

  • Thực hành: Đọc một ví dụ CDK; so với Terraform.

Ngày 89: Crossplane vs Terraform

  • Mục tiêu: Control-plane IaC (nối Layer 4).

  • Lý thuyết: push (Terraform) vs continuous reconcile (Crossplane).

  • Thực hành: Provision cùng tài nguyên bằng Crossplane; so sánh.

Ngày 90: CỘT MỐC 90

  • Mục tiêu: Chốt IaC nền.

  • Lý thuyết: Ôn D tới giờ; kiểm kê: module + state + CI/CD + policy-as-code.

  • Thực hành: Đề thi #3 (Terraform/state/module/pipeline) + tự chấm; blog #56 ("IaC nghiêm túc: module, state, CI/CD, policy-as-code"); tag layer5-day090; nghỉ nửa ngày. Đã đi 90/150 (60%).

Ngày 91: P1 - thiết kế module library

  • Mục tiêu: Đóng khung P1.

  • Lý thuyết: module cần có (network/compute/iam/data/observability), convention.

  • Thực hách: module-library-design.md.

Ngày 92: P1 - module network

  • Mục tiêu: Nền mạng tái dùng.

  • Lý thuyết: VPC/subnet/routing/endpoints tham số hoá.

  • Thực hành: Module network hoàn chỉnh + ví dụ.

Ngày 93: P1 - module compute/k8s

  • Mục tiêu: Compute chuẩn.

  • Lý thuyết: ASG/managed k8s node pool tham số hoá.

  • Thực hành: Module compute/EKS.

Ngày 94: P1 - module IAM/security

  • Mục tiêu: Quyền tái dùng an toàn.

  • Lý thuyết: role/policy chuẩn least-privilege.

  • Thực hành: Module IAM baseline.

Ngày 95: P1 - module data

  • Mục tiêu: DB/bucket chuẩn.

  • Lý thuyết: encryption/backup mặc định bật.

  • Thực hành: Module database + object storage an toàn mặc định.

Ngày 96: P1 - composition

  • Mục tiêu: Ghép module thành stack.

  • Lý thuyết: root module gọi child, env layering.

  • Thực hành: Stack dev/prod từ module library.

Ngày 97: P1 - testing & scan

  • Mục tiêu: Chất lượng.

  • Lý thuyết: terratest + tfsec/checkov + policy.

  • Thực hành: Test + scan toàn bộ module.

Ngày 98: P1 - CI/CD

  • Mục tiêu: Vận hành module.

  • Lý thuyết: versioned modules, release, plan/apply pipeline.

  • Thực hành: Pipeline hoàn chỉnh cho module library.

Ngày 99: P1 - docs

  • Mục tiêu: Dùng lại được.

  • Lý thuyết: README/examples/terraform-docs.

  • Thực hành: Sinh docs tự động; ví dụ sử dụng.

Ngày 100:

  • Mục tiêu: Kiểm kê lớn; release P1.

  • Lý thuyết: Ôn A→D; kiểm kê lớn: cloud core + networking + serverless + IaC library; đối chiếu "biết dùng tốt".

  • Thực hành: P1 done; đề thi #4 tích lũy (core+network+serverless+IaC) + tự chấm theo rubric; blog #57 ("100 ngày cloud platform: từ IAM tới một thư viện IaC dùng chung"); tag layer5-day100; nghỉ nửa ngày. Đã đi 100/150 (67%).

KHỐI E - Secrets & Identity (Ngày 101-124) → P2

Ngày 101: Secret management - nguyên lý

  • Mục tiêu: Không để secret rải rác.

  • Lý thuyết: static vs dynamic secret, rotation, least exposure.

  • Thực hành: Kiểm kê nơi secret đang nằm; điểm rủi ro.

Ngày 102: Cloud secret managers

  • Mục tiêu: Dùng managed trước.

  • Lý thuyết: Secrets Manager/Key Vault/Secret Manager, rotation, IAM access.

  • Thực hành: Lưu + truy cập secret qua managed service + IAM.

Ngày 103: Vault - kiến trúc

  • Mục tiêu: Secret engine trung tâm.

  • Lý thuyết: seal/unseal, storage backend, auth methods, secret engines, lease.

  • Thực hành: Dựng Vault dev + KV engine.

Ngày 104: Vault - auth methods

  • Mục tiêu: Ai được lấy secret.

  • Lý thuyết: token, AppRole, k8s auth, cloud IAM auth.

  • Thực hành: k8s/cloud auth → pod lấy secret không cần key tĩnh.

Ngày 105: Vault - dynamic secrets

  • Mục tiêu: Secret ngắn hạn.

  • Lý thuyết: dynamic DB/cloud credentials, TTL, revoke.

  • Thực hành: Cấp credential DB động, tự hết hạn.

Ngày 106: Vault - transit & encryption

  • Mục tiêu: Encryption-as-a-service.

  • Lý thuyết: transit engine, encrypt/decrypt không lộ key.

  • Thực hành: App mã hoá field qua transit.

Ngày 107: PKI - nền

  • Mục tiêu: Chứng chỉ & tin cậy (nối Layer 8).

  • Lý thuyết: CA hierarchy (root/intermediate), cert lifecycle, CRL/OCSP.

  • Thực hành: Vẽ chuỗi tin cậy mục tiêu.

Ngày 108: Vault PKI engine

  • Mục tiêu: Cấp cert tự động.

  • Lý thuyết: PKI secret engine, short-lived cert, mTLS.

  • Thực hành: Cấp cert ngắn hạn cho service; auto-rotate.

Ngày 109: cert-manager tích hợp

  • Mục tiêu: Cert trong k8s (nối Layer 4).

  • Lý thuyết: cert-manager + Vault/ACME issuer.

  • Thực hành: Cấp cert cho Gateway qua cert-manager+Vault.

Ngày 110: Secret injection cho workload

  • Mục tiêu: App nhận secret an toàn.

  • Lý thuyết: sidecar/agent injector, CSI secret driver, tránh env leak.

  • Thực hành: Inject secret vào pod qua agent/CSI.

Ngày 111: Boundary - access

  • Mục tiêu: Truy cập hạ tầng theo identity.

  • Lý thuyết: identity-based access, session brokering, không lộ credential/host.

  • Thực hành: Truy cập một target qua Boundary.

Ngày 112: Just-in-time access

  • Mục tiêu: Quyền tạm thời.

  • Lý thuyết: JIT elevation, approval, session recording.

  • Thực hành: Cấp quyền admin tạm có hết hạn.

Ngày 113: Identity governance

  • Mục tiêu: Quản trị danh tính.

  • Lý thuyết: least privilege, access review, permission boundary, SoD.

  • Thực hành: Access review một role; siết quyền thừa.

Ngày 114: Machine & workload identity

  • Mục tiêu: Máy có danh tính.

  • Lý thuyết: SPIFFE/SPIRE (workload identity), mTLS identity (nối Layer 4 mesh).

  • Thực hành: Cấp SVID cho workload; xác thực mTLS.

Ngày 115: Key management

  • Mục tiêu: Quản khoá đúng.

  • Lý thuyết: KMS/HSM (nối Layer 8), key rotation, envelope encryption.

  • Thực hành: Rotate CMK; kiểm tác động.

Ngày 116: Audit & secret hygiene

  • Mục tiêu: Kiểm soát rò rỉ.

  • Lý thuyết: audit log Vault, secret scanning (git), rotation policy.

  • Thực hành: Bật audit; scan repo tìm secret lộ.

Ngày 117: P2 - thiết kế baseline

  • Mục tiêu: Đóng khung P2.

  • Lý thuyết: Vault + PKI + dynamic secret + Boundary + injection.

  • Thực hách: secrets-identity-design.md.

Ngày 118: P2 - Vault + auth

  • Mục tiêu: Nền secret.

  • Lý thuyết: HA Vault, auth cloud/k8s.

  • Thực hành: Dựng Vault + auth methods.

Ngày 119: P2 - dynamic secrets + PKI

  • Mục tiêu: Secret ngắn hạn + cert.

  • Lý thuyết: DB dynamic creds + PKI mTLS.

  • Thực hành: Cấp dynamic DB creds + short-lived cert.

Ngày 120: CỘT MỐC 120

  • Mục tiêu: Chốt phần chính secrets/identity.

  • Lý thuyết: Ôn E tới giờ; kiểm kê: Vault/PKI/dynamic secret/Boundary.

  • Thực hành: Đề thi #5 (Vault/PKI/identity) + tự chấm; blog #58 ("Secrets & identity: Vault, PKI động, và truy cập theo danh tính"); tag layer5-day120; nghỉ nửa ngày. Đã đi 120/150 (80%).

Ngày 121: P2 - Boundary access

  • Mục tiêu: Truy cập an toàn.

  • Lý thuyết: target/host set, session brokering.

  • Thực hành: Truy cập DB/host qua Boundary, không lộ credential.

Ngày 122: P2 - workload injection

  • Mục tiêu: App nhận secret.

  • Lý thuyết: injector + CSI + auto-rotate.

  • Thực hành: Inject dynamic secret vào app k8s.

Ngày 123: P2 - audit & rotation

  • Mục tiêu: Vận hành bền.

  • Lý thuyết: rotation policy, audit, revoke.

  • Thực hành: Thiết lập rotation + audit; test revoke.

Ngày 124: P2 - Secrets & Identity baseline

  • Mục tiêu: Release P2.

  • Lý thuyết: rà "done": Vault+PKI+dynamic+Boundary+injection+audit.

  • Thực hành: Đóng gói + writeup. P2 done.

KHỐI F - Policy (Ngày 125-136)

Ngày 125: Policy - nguyên lý

  • Mục tiêu: Guardrail nhất quán.

  • Lý thuyết: preventive vs detective, policy-as-code, shift-left.

  • Thực hành: Phân loại policy cần có cho tổ chức.

Ngày 126: OPA/Rego

  • Mục tiêu: Policy engine đa dụng (nối Layer 4).

  • Lý thuyết: Rego, decision, data, input.

  • Thực hành: Viết policy Rego cho một quyết định.

Ngày 127: conftest cho IaC

  • Mục tiêu: Chặn hạ tầng xấu trước apply.

  • Lý thuyết: conftest trên Terraform plan JSON.

  • Thực hành: Chặn resource public/không mã hoá ở CI.

Ngày 128: Kyverno (k8s)

  • Mục tiêu: Policy cluster (nối Layer 4).

  • Lý thuyết: validate/mutate/generate, PolicyReport.

  • Thực hành: Áp policy k8s (đối chiếu Layer 4 P3).

Ngày 129: Cloud org guardrails

  • Mục tiêu: Ràng buộc cấp tổ chức.

  • Lý thuyết: SCP (AWS) · Azure Policy · Org Policy (GCP), preventive.

  • Thực hành: Viết SCP/Azure Policy cấm hành vi nguy hiểm toàn org.

Ngày 130: Compliance-as-code

  • Mục tiêu: Ánh xạ chuẩn.

  • Lý thuyết: CIS/NIST → policy, config rules, drift compliance (nối Layer 8).

  • Thực hành: Map một CIS control thành rule tự động.

Ngày 131: Detective controls

  • Mục tiêu: Phát hiện vi phạm đang tồn tại.

  • Lý thuyết: Config/Policy compliance scan, remediation.

  • Thực hành: Scan tài khoản; sinh báo cáo non-compliant.

Ngày 132: Auto-remediation

  • Mục tiêu: Tự sửa vi phạm.

  • Lý thuyết: event → function → remediate, hoặc reconcile.

  • Thực hành: Auto-remediate một vi phạm (ví dụ bucket public).

Ngày 133: Policy testing & rollout

  • Mục tiêu: Không phá vỡ prod.

  • Lý thuyết: audit/dry-run trước enforce, exception process.

  • Thực hành: Rollout policy theo audit → warn → enforce.

Ngày 134: Policy cho landing zone

  • Mục tiêu: Guardrail nền tảng.

  • Lý thuyết: bộ guardrail chuẩn cho org (region/encryption/public/tagging).

  • Thực hành: Soạn bộ guardrail dùng ở P3.

Ngày 135: Policy cross-provider

  • Mục tiêu: Nắm khác biệt.

  • Lý thuyết: SCP vs Azure Policy vs Org Policy.

  • Thực hành: Bảng đối chiếu guardrail 3 cloud.

Ngày 136: Ôn Khối F

  • Mục tiêu: Chốt policy.

  • Lý thuyết: rà OPA/Kyverno/org guardrail/compliance.

  • Thực hành: Chuẩn bị Zero Trust + landing zone.

KHỐI G - Zero Trust + Enterprise Landing Zone (Ngày 137-150) → P3 flagship

Ngày 137: Zero Trust - nguyên lý

  • Mục tiêu: Không tin ngầm.

  • Lý thuyết: "never trust, always verify", identity-centric, giả định breach; BeyondCorp.

  • Thực hành: Đối chiếu perimeter vs zero-trust cho một hệ thống.

Ngày 138: Zero Trust - identity & device

  • Mục tiêu: Xác thực liên tục.

  • Lý thuyết: strong identity, device trust, context-aware access.

  • Thực hành: Thiết kế access policy theo identity+context.

Ngày 139: Zero Trust - network

  • Mục tiêu: Bỏ tin cậy theo vị trí mạng.

  • Lý thuyết: microsegmentation, identity-aware proxy, mTLS mọi nơi (nối Layer 4 mesh).

  • Thực hành: Segment + IAP cho một app nội bộ.

Ngày 140: Zero Trust - data & workload

  • Mục tiêu: Bảo vệ tận lõi.

  • Lý thuyết: least privilege, encryption everywhere, workload identity (SPIFFE).

  • Thực hành: Áp least-privilege + workload identity cho một service.

Ngày 141: Landing Zone - kiến trúc

  • Mục tiêu: Đóng khung P3.

  • Lý thuyết: multi-account org, core accounts (management/log-archive/security/network/shared-services).

  • Thực hách: landing-zone-design.md.

Ngày 142: LZ - org & account vending

  • Mục tiêu: Cấu trúc tổ chức.

  • Lý thuyết: OU/folder, account factory, baseline mỗi account.

  • Thực hành: Dựng org + OU + account vending (IaC, dùng P1 modules).

Ngày 143: LZ - guardrails

  • Mục tiêu: Ràng buộc toàn org.

  • Lý thuyết: SCP/Policy preventive + detective (Khối F).

  • Thực hành: Áp bộ guardrail (region/encryption/public/tag) toàn org.

Ngày 144: LZ - network baseline

  • Mục tiêu: Mạng chuẩn doanh nghiệp.

  • Lý thuyết: shared network account, hub-spoke/transit, centralized egress/firewall (Khối B).

  • Thực hành: Dựng network baseline bằng IaC.

Ngày 145: LZ - identity baseline

  • Mục tiêu: Đăng nhập & quyền tập trung.

  • Lý thuyết: SSO/IdP, permission set, cross-account role, break-glass.

  • Thực hành: SSO + permission set cho các account.

Ngày 146: LZ - security & logging baseline

  • Mục tiêu: Audit + phát hiện tập trung.

  • Lý thuyết: centralized CloudTrail/audit → log archive, GuardDuty/Defender, config rules.

  • Thực hành: Bật audit + threat detection tập trung.

Ngày 147: LZ - secrets & PKI baseline

  • Mục tiêu: Ghép P2 vào nền tảng.

  • Lý thuyết: Vault/secret manager + PKI dùng chung toàn org.

  • Thực hành: Tích hợp baseline secrets/identity (P2) vào LZ.

Ngày 148: LZ - self-service & provisioning

  • Mục tiêu: Trao nền tảng cho team (nối Layer 4/6).

  • Lý thuyết: account/app vending self-service, guardrail tự động áp.

  • Thực hành: Team mới xin account → tự động có baseline + guardrail.

Ngày 149: LZ - validate & docs; ôn Layer 5

  • Mục tiêu: Hoàn thiện.

  • Lý thuyết: kiểm tra guardrail hiệu lực, drift, chi phí; rà toàn layer.

  • Thực hành: Test tuân thủ toàn org; viết runbook/docs (nối Layer 6/11).

Ngày 150: HOÀN THÀNH LAYER 5

  • Mục tiêu: Chốt Cloud Platform Engineering ở mức "biết dùng vững".

  • Lý thuyết: Ôn toàn layer; kiểm kê tổng: cloud core + networking + serverless + IaC library (P1) + secrets/identity (P2) + Enterprise Landing Zone (P3).

  • Thực hành: P3 done; đề thi #6 tích lũy (toàn layer) + tự chấm theo rubric; blog #59 ("Nhìn lại 150 ngày cloud platform: một Enterprise Landing Zone an toàn từ số 0"); tag layer5-complete; nghỉ nửa ngày.