DevOps
Topic, then cluster, then study. Recently added is the short list at the top.
Recently added
Show more- 1.Build Systems & Monorepos - Graphs, Caching, Hermeticity & Reproducible EnvironmentsConcept hub: a build is a function over a dependency graph; the four properties (correctness, incrementality, caching, hermeticity) and how they stack; task runner vs build system vs package/environment manager; what Turborepo, Nx, Bazel and Nix share and where they differ; runnable mini build function and graph-granularity demo; decision chart.
- 3.Content-Addressed Caching - Cache Keys, Remote Cache, Remote Execution & PoisoningWhat goes into a cache key; undeclared env var wrong-cache-hit demo and the strict-env fix (runnable); local vs remote cache vs remote execution (REAPI CAS + action cache); constructive vs deep traces; cache economics and the critical-path floor (runnable); poisoning table incl. untrusted writers; caching decision chart.
- 2.Dependency Graphs & Incremental Builds - Task DAGs, Topological Scheduling, Content Hashing & Affected DetectionPackage vs task vs action graphs; topological waves and the critical path; mtime vs content hash vs verifying and constructive traces; early cutoff; runnable Python mini build engine (topo sort, three rebuilders, cycle error) and TS monorepo task engine with affected detection; static vs dynamic dependencies and the Build Systems a la Carte grid.
- 6.Dependency Resolution & Dev Environments - SemVer, SAT vs MVS, Lockfiles, Nix Shells & DevcontainersSemVer and range styles per ecosystem; search (PubGrub/SAT) vs MVS vs nested copies with a runnable diamond demo; lockfiles across ecosystems and integrity hashes (runnable); hoisting and phantom deps; Nix shells vs devcontainers vs mise/asdf vs Docker; works-on-my-machine diagnosis; interview Q&A.
- 5.Helm & Kubernetes Packaging - Charts, Values, Releases, Rollback, Hooks vs Kustomize, Operators & GitOpsPackaging: Helm charts, values precedence, rendering, releases stored as Secrets, upgrade/rollback, 3-way merge vs server-side apply (Helm 4), hooks, dependencies, library charts, CRD handling; compared with Kustomize, raw manifests, operators and GitOps (Argo CD, Flux) with a decision chart.
- 4.Hermeticity & Reproducible Builds - Sandboxes, Pinned Toolchains, the Nix Store & Bit-for-Bit OutputPinned vs hermetic vs deterministic vs reproducible; sources of non-reproducibility; SOURCE_DATE_EPOCH archive demo (runnable); the Nix model (derivations, store paths, closures, substituters, input- vs content-addressed) with a store-path demo (runnable); lockfiles vs Docker vs Bazel sandboxes vs Nix/Guix; SBOMs and provenance.
DevOps
Kubernetes workloads, CI/CD pipelines, artifact digests, supply-chain controls, Git rebase, merge, and recovery, and Terraform state, modules, and safe change you can defend in interviews.
Build Systems & Monorepos
6 studies- 1.Build Systems & Monorepos - Graphs, Caching, Hermeticity & Reproducible EnvironmentsConcept hub: a build is a function over a dependency graph; the four properties (correctness, incrementality, caching, hermeticity) and how they stack; task runner vs build system vs package/environment manager; what Turborepo, Nx, Bazel and Nix share and where they differ; runnable mini build function and graph-granularity demo; decision chart.
- 2.Dependency Graphs & Incremental Builds - Task DAGs, Topological Scheduling, Content Hashing & Affected DetectionPackage vs task vs action graphs; topological waves and the critical path; mtime vs content hash vs verifying and constructive traces; early cutoff; runnable Python mini build engine (topo sort, three rebuilders, cycle error) and TS monorepo task engine with affected detection; static vs dynamic dependencies and the Build Systems a la Carte grid.
- 3.Content-Addressed Caching - Cache Keys, Remote Cache, Remote Execution & PoisoningWhat goes into a cache key; undeclared env var wrong-cache-hit demo and the strict-env fix (runnable); local vs remote cache vs remote execution (REAPI CAS + action cache); constructive vs deep traces; cache economics and the critical-path floor (runnable); poisoning table incl. untrusted writers; caching decision chart.
- 4.Hermeticity & Reproducible Builds - Sandboxes, Pinned Toolchains, the Nix Store & Bit-for-Bit OutputPinned vs hermetic vs deterministic vs reproducible; sources of non-reproducibility; SOURCE_DATE_EPOCH archive demo (runnable); the Nix model (derivations, store paths, closures, substituters, input- vs content-addressed) with a store-path demo (runnable); lockfiles vs Docker vs Bazel sandboxes vs Nix/Guix; SBOMs and provenance.
- 5.Monorepo vs Polyrepo - Workspaces, Package Boundaries, Versioning & CI Fan-outMonorepo vs polyrepo trade-offs; workspaces as the base layer and task runners vs build systems on top; boundaries (tags, visibility, exports, CODEOWNERS) with a runnable boundary + CI fan-out + owners demo; fixed vs independent versioning with changesets (runnable); CI fan-out by scale from Turborepo-size repos to Google-scale.
- 6.Dependency Resolution & Dev Environments - SemVer, SAT vs MVS, Lockfiles, Nix Shells & DevcontainersSemVer and range styles per ecosystem; search (PubGrub/SAT) vs MVS vs nested copies with a runnable diamond demo; lockfiles across ecosystems and integrity hashes (runnable); hoisting and phantom deps; Nix shells vs devcontainers vs mise/asdf vs Docker; works-on-my-machine diagnosis; interview Q&A.
CI/CD Pipelines
6 studies- 1.CI/CD Pipelines — Stages, Artifacts, Caching & Supply ChainInterview hub on CI/CD pipeline design: stages/gates, immutable artifacts, CI speed, branching/previews, and supply-chain controls (OIDC/SBOM/signing).
- 2.Pipeline Anatomy — Stages, Gates, Environments & PromotionStages, soft/hard gates, environments, and build-once promotion anatomy with GitHub Actions sketch + promotion helpers.
- 3.Artifacts & Registries — Digests, Provenance & ImmutabilityDigests vs tags, SLSA/provenance, registry immutability, and digest-handoff patterns for staging→prod.
- 4.CI Performance — Caching, Parallelism & Flaky JobsCI caching layers, parallelism/sharding, flake economics, and metrics that actually drive feedback time.
- 5.Branching, Previews & Environment PromotionTrunk-based vs GitFlow, ephemeral PR previews, environment promotion state machine, config vs artifact separation.
- 6.Supply Chain Security — Signing, SBOMs & OIDC FederationOIDC federation, Sigstore/cosign, SBOMs, admit-time policy, and CI permissions hygiene for supply-chain defense.
- 1.Feature Flags — Targeting, Experimentation & Kill SwitchesFeature flags (feature toggles) decouple deploy from release: you ship dark code safely, then turn behavior on for segments, percentages, or experiments, and turn it off instantly when metrics or incidents demand it. This hub teaches release, experiment, ops, and permission toggles, sticky bucketing, targeting, A/B guardrails, progressive delivery, kill switches, and hygiene so flags do not become permanent debt.
- 2.Flag Types & Evaluation — Boolean, Multivariate, Percentage & Sticky BucketsFlag types and evaluation mechanics decide whether your rollout is trustworthy. Booleans gate on or off. Multivariate flags return named variants. Percentage rollouts need a sticky hash so the same subject stays in the same bucket. This lesson implements those sketches, contrasts hash choices, and shows why a fresh random draw breaks experiments and UX.
- 3.Targeting & Context — Attributes, Segments, Rules & PrecedenceTargeting answers who gets a variant: attributes on the evaluation context, reusable segments, and ordered rules with a clear precedence. Bad targeting causes support chaos and biased experiments. This lesson shows a minimal rules engine, how segments are composed, and how exposure differs from authorization.
- 4.Experimentation & A/B — Exposure, Metrics, Guardrails & PeekingAn experiment is a sticky multivariate flag plus exposure logging, a success metric, and guardrail metrics, run with statistical discipline. This lesson covers assignment versus exposure, sample ratio mismatch, peeking, a one-sentence view of CUPED, and when a dedicated experiment platform earns its place next to the flag.
- 5.Progressive Delivery & Kill Switches — Canary, Ramp, Instant RollbackProgressive delivery ramps a feature to a larger audience only while metrics stay healthy. A kill switch forces the safe path the moment they do not. This lesson contrasts flag ramps with Kubernetes traffic canaries, designs soak times and abort gates, and defines who may flip a kill switch and how wide the blast radius is.
- 6.Flag Architecture & Hygiene — SDK Placement, Consistency, Stale Flags & DebtFlags fail quietly when the architecture is wrong, and loudly when hygiene is ignored. This lesson places SDKs so services do not split-brain a decision, adopts an OpenFeature-style seam, and sets a lifecycle from create to ramp to delete so stale flags do not become a permanent settings database.
Git
6 studies- 1.Git — Everyday Commands, Rebase vs Merge & Safe HistoryGit is a content-addressed DAG of commits plus movable refs and a staging index. This hub is the decision matrix for rebase, merge, and squash, and the map to objects, history surgery, recovery, and pull-request hygiene.
- 2.Git Objects, Refs, Index & Working Tree — Mental ModelEverything in Git is an immutable content-addressed object or a mutable ref. The index is the staging area between the working tree and the next commit. Rebase, reset, and reflog stop feeling like magic once those three trees are obvious.
- 3.Rebase vs Merge vs Squash — When, Why & TradeoffsMerge records parallel work with a join commit. Rebase replays commits onto a new base and mints new ids. Squash collapses a branch into one commit. The wrong choice on a shared branch hurts the team. The wrong choice on a private branch mostly wastes review time.
- 4.History Surgery — Amend, Interactive Rebase, Fixup & AutosquashHistory surgery cleans private commits before review. Amend fixes the tip. Interactive rebase reorders, squashes, rewords, or edits. Fixup and autosquash fold review follow-ups into the commit they belong to. Every one of these tools mints new commit ids.
- 5.Cherry-pick, Revert, Reset & Reflog RecoveryCherry-pick copies one commit's changes onto another branch as a new commit. Revert adds an inverse commit. Reset moves a branch pointer. Reflog is the local record of where HEAD used to point, and it is how you get a commit back after a bad rebase or reset.
- 6.Branching, PR Hygiene, Bisect, Worktrees & HooksDay-to-day collaboration is branching policy, pull-request hygiene, bisect, worktrees, and hooks. Trunk-based development keeps main releasable with short branches. Bisect is a binary search over commits. Worktrees are extra checkouts on one object database.
- 1.Infrastructure as Code — Terraform State, Modules & Safe ChangeInfrastructure as code turns console clicks into reviewable change with a known blast radius. This hub is the Terraform decision map for remote state, modules, saved plans, drift, and policy, with a light contrast to Pulumi, CloudFormation, and Crossplane.
- 2.State, Backends, Locking & WorkspacesTerraform state maps configuration addresses to real resource IDs. This page covers remote backends, locking, encryption, and why prod usually gets its own root instead of a workspace.
- 3.Resources, Providers & the Dependency GraphProviders turn HCL into API calls, and resources are the nodes in the graph. This page covers aliases, implicit edges, lifecycle, and why for_each beats count when a set changes shape.
- 4.Modules, Composition & VersioningA Terraform module is a versioned interface, not a dump of the whole account. This page covers composition, pins, registries, and when a root should stay flat.
- 5.Plan, Apply, Drift Detection & ImportSafe Terraform change is a pipeline: a saved plan, a review of replaces, an apply of that file, then drift detection and a deliberate import or recreate.
- 6.Blast Radius — Policy-as-Code, Secrets & CI AppliesTerraform outages are usually applies that were allowed to do too much. This page covers policy on plan JSON, secret hygiene, least-privilege CI roles, and gates sized to blast radius.
Kubernetes Internals
6 studies- 1.Kubernetes Internals - Declarative Reconciliation from kubectl apply to Running PodHub: Kubernetes as a database of intentions plus independent watch-driven loops; imperative vs declarative reconciliation; the full kubectl apply -> running pod path (authn/authz, admission, etcd, Deployment/ReplicaSet controllers, scheduler, kubelet, CRI/CNI/CSI); component contracts, bottlenecks and a layer-picking decision chart. Goes one layer below the existing Workloads series.
- 2.Kubernetes Control Plane - API Server Request Path, etcd, Watches, Informers, Optimistic Concurrency & CRDsControl plane: API server request pipeline (authn, API Priority and Fairness, RBAC, mutating/validating admission, schema validation), etcd limits and compaction, resourceVersion, watches, 410 Gone and relist, 409 optimistic concurrency, shared informers and workqueues, CRDs and operators vs aggregated APIs.
- 3.Scheduler, Controllers & the Kubelet - Filter and Score, Taints, Preemption, Reconcile Loops, Garbage Collection & Pod SyncScheduler, controllers and kubelet: scheduling framework (PreFilter, Filter, Score, Reserve, Permit, Bind), taints/tolerations, affinity and topology spread, priority and preemption; level-triggered reconcile loops, owner references, finalizers and garbage collection; kubelet pod sync, node-pressure eviction and a Pending/ContainerCreating triage chart.
- 4.Kubernetes Storage - Volumes, PV, PVC, StorageClass, CSI, StatefulSets & Failure ModesStorage: volume types, PV/PVC/StorageClass, static vs dynamic provisioning, Immediate vs WaitForFirstConsumer, provision -> bind -> attach -> mount via CSI, access modes (RWO/RWOP/RWX), reclaim policies, StatefulSets with volumeClaimTemplates, expansion and snapshots, zone pinning, Multi-Attach and node-loss failure timelines.
- 5.Helm & Kubernetes Packaging - Charts, Values, Releases, Rollback, Hooks vs Kustomize, Operators & GitOpsPackaging: Helm charts, values precedence, rendering, releases stored as Secrets, upgrade/rollback, 3-way merge vs server-side apply (Helm 4), hooks, dependencies, library charts, CRD handling; compared with Kustomize, raw manifests, operators and GitOps (Argo CD, Flux) with a decision chart.
- 6.Node-Level Scaling - Node Groups, Cluster Autoscaler vs Karpenter, Over-Provisioning, PDBs & DrainsNode scaling: node groups/ASGs/managed node pools, Cluster Autoscaler simulation and expanders, Karpenter NodePools, consolidation and disruption budgets, CA vs Karpenter, scale-up latency budget, over-provisioning with pause pods and CapacityBuffer, PDBs and drains, cost levers. HPA/VPA linked, not re-taught.
Kubernetes Workloads
6 studies- 1.Kubernetes Workloads — Deployments, Probes, Resources & Progressive DeliveryControllers reconcile desired vs actual. Deployments own ReplicaSets that own Pods. Probes gate traffic and restarts. Requests/limits set QoS and scheduling. Rollouts need PDBs and a progressive strategy. This hub maps the cluster; Ingress/Gateway stays in the Private Networking pages.
- 2.Pods, ReplicaSets & Deployments — Desired State & ControllersThe Deployment controller owns ReplicaSets that own Pods. Labels and selectors wire the tree. maxUnavailable/maxSurge and revision history define how a rollout moves. Prefer Deployments over hand-managing ReplicaSets.
- 3.Probes & Pod Lifecycle — Liveness, Readiness, Startup & PreStopStartup probes buy slow boots. Readiness gates Service traffic. Liveness restarts stuck processes — never point it at a dependent database or you restart-storm yourself. PreStop plus terminationGracePeriodSeconds is how you drain cleanly.
- 4.Requests, Limits & QoS — CPU Throttling, Memory OOM & SchedulingRequests drive scheduling; limits cap cgroups. Guaranteed / Burstable / BestEffort decide who dies under pressure. CPU over limit throttles; memory over limit OOMs. Overcommit without quotas is how noisy neighbors win.
- 5.Rolling, Blue-Green & Canary — Strategies, PDBs & Blast RadiusRollingUpdate trades surge capacity for gradual replacement. Blue-green switches a Service between two Deployments. Canary shifts a fraction of traffic (Flagger/Argo Rollouts). PDBs bound voluntary disruption so you do not drain yourself offline.
- 6.HPA, VPA & Autoscaling Gotchas — Metrics, Stabilization & ThrashHPA scales replicas from CPU/memory/custom/external metrics. Stabilization windows stop flap. VPA changes requests/limits and fights HPA if both target the same resource. Queue consumers often need custom metrics, not raw CPU.