Hands-on Projects cheat sheet
43 commands from every lesson of Hands-on Projects — Build It End to End, on one page.
AWS
aws ssm get-parameters --names /aws/service/canonical/ubuntu/server/24.04/stable/current/amd64/hvm/ebs-gp3/ami-id --query 'Parameters[0].Value' --output text | Latest Ubuntu 24.04 AMI |
aws ec2 run-instances --image-id $AMI --instance-type t3.medium --key-name lab-key --security-group-ids $SG --subnet-id $SUBNET … | Create a VM |
aws ec2 terminate-instances --instance-ids … | Clean up (stop paying) |
Cluster
sudo kubeadm init --pod-network-cidr=10.244.0.0/16 --apiserver-cert-extra-sans=$CP_PUBLIC_IP | Control plane |
cilium install --set ipam.mode=kubernetes && cilium status --wait | CNI |
kubectl -n demo create secret docker-registry regcred --docker-server=ghcr.io … | Pull credentials |
Pipeline & checks
http://<jenkins-ip>:8080/github-webhook/ | GitHub webhook URL |
kubectl -n demo rollout status deploy/hello | Did the deploy finish? |
curl http://<node-public-ip>:30080 | Check the app |
Argo CD
kubectl create namespace argocd && kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml | Install (pin a version for real use) |
argocd admin initial-password -n argocd | First login password |
argocd repo add git@github.com:<you>/hello-gitops.git --ssh-private-key-path ./argocd_ro | Private GitOps repo (read-only key) |
argocd app get hello / argocd app history hello | Status and history |
CI update step
kustomize edit set image hello=ghcr.io/<you>/hello-k8s:$TAG | Bump the tag in the overlay |
git commit -am "hello: $TAG" && git push | Hand over to Argo CD |
git revert <sha> && git push (GitOps repo) | Roll back |
Control plane HA
kube-vip manifest pod --interface enp1s0 --address 192.168.122.100 --controlplane --arp --leaderElection | Generate the kube-vip static pod (see kube-vip docs) |
sudo kubeadm init --control-plane-endpoint 192.168.122.100:6443 --upload-certs --pod-network-cidr 10.244.0.0/16 | First control plane |
sudo kubeadm join 192.168.122.100:6443 … --control-plane --certificate-key <key> | cp2, cp3 |
Services & HTTPS
IPAddressPool 192.168.122.200-192.168.122.220 + L2Advertisement | MetalLB |
helm upgrade --install ingress-nginx ingress-nginx --repo https://kubernetes.github.io/ingress-nginx -n ingress-nginx --create-namespace | Ingress controller (gets a MetalLB IP) |
cert-manager.io/cluster-issuer: lab-ca (Ingress annotation) | Automatic TLS |
virsh shutdown cp1 && kubectl get nodes | Failover test |
Terraform & access
terraform init && terraform plan -out tfplan && terraform apply tfplan | Create VPC + EKS |
aws eks update-kubeconfig --name hello-eks --region eu-west-1 | kubectl access |
kubectl delete ingress hello -n demo (before destroy) | Let the controller delete the ALB |
terraform destroy | Remove everything |
Image & load balancer
aws ecr get-login-password | docker login --username AWS --password-stdin <acct>.dkr.ecr.<region>.amazonaws.com | Log in to ECR |
helm install aws-load-balancer-controller eks/aws-load-balancer-controller -n kube-system --set clusterName=hello-eks --set serviceAccount.create=false --set serviceAccount.name=aws-load-balancer-controller | Install the controller |
kubectl get ingress -n demo (ADDRESS = ALB DNS name) | Find the app URL |
Install
helm install kps prometheus-community/kube-prometheus-stack -n monitoring --create-namespace --set prometheus.prometheusSpec.serviceMonitorSelectorNilUsesHelmValues=false --set prometheus.prometheusSpec.ruleSelectorNilUsesHelmValues=false | Prometheus, Alertmanager, Grafana (select all monitors/rules) |
helm install podinfo podinfo/podinfo -n demo --create-namespace --set serviceMonitor.enabled=true | Demo app with metrics |
Traffic & checks
kubectl -n demo port-forward svc/podinfo 9898 | Reach podinfo locally |
hey -z 10m -q 20 http://localhost:9898/ + …/status/500 | Good and bad traffic |
kubectl -n monitoring port-forward svc/kps-kube-prometheus-stack-prometheus 9090 | Prometheus UI (name depends on release) |
kubectl -n monitoring port-forward svc/kps-kube-prometheus-stack-alertmanager 9093 | Alertmanager UI |
Clusters
kind create cluster --name mgmt (and edge-01, edge-02, edge-03) | Four local clusters |
docker inspect -f '{{.NetworkSettings.Networks.kind.IPAddress}}' edge-01-control-plane | Address Argo CD can reach |
argocd cluster add kind-edge-01 --name edge-01 --kubeconfig ./edge-01.kubeconfig | Register a cluster |
kubectl -n argocd label secret <cluster-secret> wave=canary | Label clusters for targeting |
Fleet
ApplicationSet with generators: clusters: selector: matchLabels | One app per matching cluster |
argocd app list | Generated Applications |
targetRevision per wave (e.g. canary → main, stable → a tag) | Staged rollout |