Cheat Sheets / Hands-on Projects

Hands-on Projects cheat sheet

43 commands from every lesson of Hands-on Projects — Build It End to End, on one page.

01 · AWS VMs → kubeadm → Cilium → Jenkins deploys from Git

AWS

aws ssm get-parameters --names /aws/service/canonical/ubuntu/server/24.04/stable/current/amd64/hvm/ebs-gp3/ami-id --query 'Parameters[0].Value' --output textLatest Ubuntu 24.04 AMI
aws ec2 run-instances --image-id $AMI --instance-type t3.medium --key-name lab-key --security-group-ids $SG --subnet-id $SUBNET …Create a VM
aws ec2 terminate-instances --instance-ids …Clean up (stop paying)

Cluster

sudo kubeadm init --pod-network-cidr=10.244.0.0/16 --apiserver-cert-extra-sans=$CP_PUBLIC_IPControl plane
cilium install --set ipam.mode=kubernetes && cilium status --waitCNI
kubectl -n demo create secret docker-registry regcred --docker-server=ghcr.io …Pull credentials

Pipeline & checks

http://<jenkins-ip>:8080/github-webhook/GitHub webhook URL
kubectl -n demo rollout status deploy/helloDid the deploy finish?
curl http://<node-public-ip>:30080Check the app

02 · The same pipeline, GitOps style with Argo CD

Argo CD

kubectl create namespace argocd && kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yamlInstall (pin a version for real use)
argocd admin initial-password -n argocdFirst login password
argocd repo add git@github.com:<you>/hello-gitops.git --ssh-private-key-path ./argocd_roPrivate GitOps repo (read-only key)
argocd app get hello / argocd app history helloStatus and history

CI update step

kustomize edit set image hello=ghcr.io/<you>/hello-k8s:$TAGBump the tag in the overlay
git commit -am "hello: $TAG" && git pushHand over to Argo CD
git revert <sha> && git push (GitOps repo)Roll back

03 · Bare-metal HA lab: kube-vip, MetalLB, ingress, TLS

Control plane HA

kube-vip manifest pod --interface enp1s0 --address 192.168.122.100 --controlplane --arp --leaderElectionGenerate the kube-vip static pod (see kube-vip docs)
sudo kubeadm init --control-plane-endpoint 192.168.122.100:6443 --upload-certs --pod-network-cidr 10.244.0.0/16First control plane
sudo kubeadm join 192.168.122.100:6443 … --control-plane --certificate-key <key>cp2, cp3

Services & HTTPS

IPAddressPool 192.168.122.200-192.168.122.220 + L2AdvertisementMetalLB
helm upgrade --install ingress-nginx ingress-nginx --repo https://kubernetes.github.io/ingress-nginx -n ingress-nginx --create-namespaceIngress controller (gets a MetalLB IP)
cert-manager.io/cluster-issuer: lab-ca (Ingress annotation)Automatic TLS
virsh shutdown cp1 && kubectl get nodesFailover test

04 · EKS with Terraform and an ALB

Terraform & access

terraform init && terraform plan -out tfplan && terraform apply tfplanCreate VPC + EKS
aws eks update-kubeconfig --name hello-eks --region eu-west-1kubectl access
kubectl delete ingress hello -n demo (before destroy)Let the controller delete the ALB
terraform destroyRemove everything

Image & load balancer

aws ecr get-login-password | docker login --username AWS --password-stdin <acct>.dkr.ecr.<region>.amazonaws.comLog in to ECR
helm install aws-load-balancer-controller eks/aws-load-balancer-controller -n kube-system --set clusterName=hello-eks --set serviceAccount.create=false --set serviceAccount.name=aws-load-balancer-controllerInstall the controller
kubectl get ingress -n demo (ADDRESS = ALB DNS name)Find the app URL

05 · Observability stack with SLO alerts

Install

helm install kps prometheus-community/kube-prometheus-stack -n monitoring --create-namespace --set prometheus.prometheusSpec.serviceMonitorSelectorNilUsesHelmValues=false --set prometheus.prometheusSpec.ruleSelectorNilUsesHelmValues=falsePrometheus, Alertmanager, Grafana (select all monitors/rules)
helm install podinfo podinfo/podinfo -n demo --create-namespace --set serviceMonitor.enabled=trueDemo app with metrics

Traffic & checks

kubectl -n demo port-forward svc/podinfo 9898Reach podinfo locally
hey -z 10m -q 20 http://localhost:9898/ + …/status/500Good and bad traffic
kubectl -n monitoring port-forward svc/kps-kube-prometheus-stack-prometheus 9090Prometheus UI (name depends on release)
kubectl -n monitoring port-forward svc/kps-kube-prometheus-stack-alertmanager 9093Alertmanager UI

06 · A GitOps fleet on kind

Clusters

kind create cluster --name mgmt (and edge-01, edge-02, edge-03)Four local clusters
docker inspect -f '{{.NetworkSettings.Networks.kind.IPAddress}}' edge-01-control-planeAddress Argo CD can reach
argocd cluster add kind-edge-01 --name edge-01 --kubeconfig ./edge-01.kubeconfigRegister a cluster
kubectl -n argocd label secret <cluster-secret> wave=canaryLabel clusters for targeting

Fleet

ApplicationSet with generators: clusters: selector: matchLabelsOne app per matching cluster
argocd app listGenerated Applications
targetRevision per wave (e.g. canary → main, stable → a tag)Staged rollout