Project challenges / verified progress
Engineering project paths

The engineering notebook

Beacon: give it somewhere to live

You can run Beacon on a local Kubernetes cluster, explain the controllers that keep it alive, expose it safely, preserve its SQLite state, and debug the common failure modes without guessing.

Your learning trail

0 / 10 complete

Verified project-agent submissions only. Reading or clicking cannot unlock progress.

System design

What you are building

Beacon moves from a signed image to a locally orchestrated service. Kubernetes stores desired state, schedules Pods, rolls workloads, injects configuration, gives Pods stable service discovery, asks health questions, budgets machine resources, preserves SQLite data with a StatefulSet, narrows identity and network access, and finally exposes HTTPS through Ingress and cert-manager.

BEACON / THE CLUSTERYour manifestsdesired state, in GitTHE CLUSTER YOU OWNAPI serverthe only source of truthControllersclose the gap, foreverPodsBeacon, actually runningService, Ingressreachable, with TLSWHAT BOUNDS THE WORKLOADProbesliveness and readinessRBAC, NetworkPolicyleast privilege, twiceobserved state is compared with desired state continuouslyYOU DECLARE WHAT SHOULD BE TRUE; THE CLUSTER KEEPS IT TRUE

Stages

10 stages, in order

Expand any stage to read what it teaches. A stage opens for work once the stage before it passes a verified submission.

Phase 1Stages 1–30 of 3 stages verified

Phase 1 — Learn the control plane

Understand reconciliation, create a local cluster and run Beacon under a Deployment.

  • Trust the loop60 minutes (locked)

    What changes when software is run by a control loop instead of a person?

    You will be able to create a deploy/k8s directory to hold all Kubernetes manifests for Beacon.

    Fork the project repository to start working through the stages.

  • Make a cluster local75 minutes (locked)

    How can a real Kubernetes cluster run on a laptop without renting cloud infrastructure?

    You will be able to create a kind cluster named beacon using a checked-in config file.

    Fork the project repository to start working through the stages.

  • Run the image90 minutes (locked)

    How does Kubernetes keep Beacon running and roll it forward without hand-starting containers?

    You will be able to create a Deployment for Beacon in deploy/k8s/10-deployment.yaml.

    Fork the project repository to start working through the stages.

Phase 2Stages 4–60 of 3 stages verified

Phase 2 — Define the runtime contract

Move configuration outside the image, wire stable service discovery, and let Kubernetes probe Beacon correctly.

  • Move knobs outside90 minutes (locked)

    How does Beacon receive configuration without baking it into the image?

    You will be able to create 20-config.yaml with a ConfigMap for Beacon runtime settings.

    Fork the project repository to start working through the stages.

  • Give pods a name90 minutes (locked)

    How does traffic find the right Beacon Pods when Pod IPs are disposable?

    You will be able to create 30-service.yaml defining a ClusterIP Service named beacon.

    Fork the project repository to start working through the stages.

  • Let the cluster ask90 minutes (locked)

    How should Kubernetes decide whether Beacon is alive, ready and finished starting?

    You will be able to add HTTP startup, readiness and liveness probes to the Beacon container.

    Fork the project repository to start working through the stages.

Phase 3Stages 7–80 of 2 stages verified

Phase 3 — Share machines and keep state

Set resource expectations and move SQLite onto stable StatefulSet storage.

  • Budget the machine90 minutes (locked)

    How does Kubernetes decide where Beacon fits and what happens when it uses too much?

    You will be able to add resource requests for Beacon's container: small CPU, realistic memory.

    Fork the project repository to start working through the stages.

  • Keep the database2 hours (locked)

    How can Beacon keep SQLite data when Pods are disposable?

    You will be able to replace the Beacon Deployment with a StatefulSet for the SQLite-backed local version.

    Fork the project repository to start working through the stages.

Phase 4Stages 9–100 of 2 stages verified

Phase 4 — Lock down and expose

Apply least privilege, restrict network paths, and publish Beacon through local HTTPS it can monitor itself.

  • Limit two blast radii2 hours (locked)

    How do RBAC and NetworkPolicy give Beacon only the access it needs?

    You will be able to create a named ServiceAccount beacon and attach it to the workload.

    Fork the project repository to start working through the stages.

  • Expose it safely2 hours (locked)

    How does Beacon become reachable from outside the cluster with a certificate it can monitor itself?

    You will be able to install or enable ingress-nginx on the kind cluster before applying the Ingress.

    Fork the project repository to start working through the stages.

About this path

A container image is a package, not a platform. Beacon still needs placement, restarts, stable networking, configuration, storage, policy and a safe edge before it behaves like a service someone can rely on.

What you will learn: Kubernetes Deployments and rollouts, Liveness and readiness probes, Requests, limits and QoS classes, Kubernetes RBAC and NetworkPolicy, Ingress and cert-manager TLS. Build the project through cumulative challenges with beginner explanations and local verification.

Level
Complete beginner to independently building and operating the project
Format
10 cumulative stages. Every stage teaches the concept in full before any code, then gives you the thing to build and the run that proves it works
Before you start
You need Docker, kind and kubectl. Everything runs on a local kind cluster and is free: no AWS account, no cloud load balancer, no credit card and no public DNS zone are required.
Official documentation (opens in a new tab)