LI530: Kubernetes Advanced UPDATE

Training: Linux/Unix

This workshop provides hands-on know-how for secure, scalable operation of production Kubernetes platforms. Focus areas are Security, GitOps, Policy Enforcement, Supply Chain Security, Service Mesh and Cluster Lifecycle Management with Cluster API. The hands-on course targets experienced admins who want to professionally secure, automate and operate Kubernetes environments.

Hybrid event Hybrid event

Start: 2026-04-13 | 10:00 am

End: 2026-04-17 | 01:30 pm

Location: Nuremberg

Price: 2.990,00 € plus VAT.

Hybrid event Hybrid event

Start: 2026-05-18 | 10:00 am

End: 2026-05-22 | 01:30 pm

Location: Nuremberg

Price: 2.990,00 € plus VAT.

Hybrid event Hybrid event

Start: 2026-08-31 | 10:00 am

End: 2026-09-04 | 01:30 pm

Location: Nuremberg

Price: 2.990,00 € plus VAT.

Hybrid event Hybrid event

Start: 2026-11-02 | 10:00 am

End: 2026-11-06 | 01:30 pm

Location: Nuremberg

Price: 2.990,00 € plus VAT.

Request prefered appointment period:

* All fields marked with an asterisk are mandatory fields.

Agenda:

Application deployment in containers

  • Overview of deployment and template engines
  • Helm, charts and repositories
  • Structure of helm charts


Access permissions to the Kubernetes API

  • Overview:
    • Service Account Tokens (JWT)
    • OpenID Connect Tokens (JWT)
    • Webhook Token Authentication
  • Examples and exercises


Security settings for the Kubernetes cluster

  • Securing the Kubernetes server components
  • Policies in the Kubernetes cluster
    • PodSecurityAdmission
    • NetworkPolicies
    • Webhook Admission Controller
    • Examples and exercises
  • Image & container security
    • Container Image CVE Scanning
    • Container image signing


Image & container security

  • Image hardening & scanning
  • CVE scanning
  • Supply chain security


Service Mesh

  • What is a ServiceMesh?
  • Overview
  • ServiceMesh using Istio example


Kubernetes Operators

  • Functionality of operators in Kubernetes
  • Creating an operator

Objectives:

 

At the end of the training LI530 Kubernetes Advanced, participants will be able to effectively implement the presented concepts, particularly the security concept and the ServiceMesh technology built upon it, in their own projects.

Target audience:

The seminar LI530 Kubernetes Advanced is primarily targeted at Linux/Unix administrators.

Prerequisites:

To be able to follow the course content and learning pace of the workshop LI530 Kubernetes Advanced effectively, participants should already have basic Kubernetes knowledge as well as solid Linux system administration skills (RHCE, SCA, LPIC1 or equivalent).

We strongly recommend prior attendance of the following courses:

Description:

The workshop LI530 Kubernetes Advanced provides comprehensive hands-on knowledge for secure, scalable and professional operation of modern Kubernetes platforms.

The focus is on Kubernetes Security at API, cluster and workload level, including Threat Modeling according to the 4C's of Cloud Native Security and practical cluster hardening. Participants learn Advanced Application Delivery with containers, Helm, Kustomize and GitOps with Argo CD for reproducible and auditable deployments. Another focus area is Policy Enforcement and Secure Supply Chain, including Admission Controllers, Policy-as-Code as well as image and container security.

Additionally, Service Mesh concepts with Istio and Linkerd for secure service-to-service communication are covered. Finally, the course teaches Cluster Lifecycle Management with Cluster API, from declarative provisioning to upgrades and scaling. The course is hands-on oriented, security-focused and targets experienced Kubernetes users who are responsible for production platforms.

We recommend as follow-up courses:
- LI560 Kubernetes Security
- LI590 Kubernetes Cluster Management with SUSE™ Rancher

Check Icon

Guaranteed implementation:

from 2 Attendees

Booking information:

Duration:

5 Days

Price:

2.990,00 € plus VAT.

(including lunch & drinks for in-person participation on-site)

Testimonials:

Cheerful male participant, representative of all customers who have provided feedback on qSkills' services.
#Testimonials
If qualification, then qSkills™

Authorized training partner

NetApp Partner Authorized Learning
Commvault Training Partner
CQI | IRCA Approved Training Partner
Veeam Authorized Education Center
Acronis Authorized Training Center
AWS Partner Select Tier Training
ISACA Accredited Partner
iSAQB
CompTIA Authorized Partner
EC-Council Accredited Training Center

Memberships

Allianz für Cyber-Sicherheit
TeleTrust Pioneers in IT security
Bundesverband der IT-Sachverständigen und Gutachter e.V.
Bundesverband mittelständische Wirtschaft (BVMW)
Allianz für Sicherheit in der Wirtschaft
NIK - Netzwerk der Digitalwirtschaft
BVSW
Bayern Innovativ
KH-iT
CAST
IHK Nürnberg für Mittelfranken
eato e.V.
Sicherheitsnetzwerk München e.V.