πŸ“šBook Signing at KubeCon EU 2026Meet us at Booking.com HQ (Mon 18:30-21:00) & vCluster booth #521 (Tue 24 Mar, 12:30-1:30pm) β€” free book giveaway!RSVP Booking.com Event

🌐 Networking

Kubernetes networking recipes: Services, Ingress, Network Policies, DNS, load balancing, SR-IOV, NNCP, InfiniBand, and multi-NIC configs.

157 recipes 🟒 14 beginner 🟑 79 intermediate πŸ”΄ 64 advanced
advanced ⏱ 15 minutes

RDMA Configuration with NVIDIA Network Operator

Deploy and configure RDMA for GPU clusters using the NVIDIA Network Operator. NicClusterPolicy setup, MLNX_OFED driver container, shared and SR-IOV RDMA device

rdmanvidianetwork-operatormellanox
advanced ⏱ 15 minutes

OpenShift SR-IOV Network with NVIDIA IPAM for GPU Fabric

Configure SriovNetwork resources on OpenShift with nv-ipam for GPU fabric IP allocation. SR-IOV Network Operator setup, Mellanox NIC resource targeting, IPAM

sriovopenshiftnv-ipamnvidia
advanced ⏱ 15 minutes

Shared RDMA Device Plugin for Kubernetes GPU Pods

Configure the RDMA shared device plugin to allow multiple pods to share RDMA-capable NICs on Kubernetes. K8s-rdma-shared-dev-plugin setup, resource

rdmadevice-pluginsharedgpu
advanced ⏱ 15 minutes

SR-IOV Multus Network Attachment for GPU RDMA Pods

Configure Multus CNI NetworkAttachmentDefinition for SR-IOV RDMA in Kubernetes GPU workloads. Covers k8s.v1.cni.cncf.io/networks annotation, IPAM

networkingsriovrdmaopenshift
intermediate ⏱ 15 minutes

Kubernetes Ingress TLS Certificate with cert-manager

Automate TLS certificate management on Kubernetes with cert-manager. Let's Encrypt integration, ClusterIssuer configuration, automatic renewal, wildcard

cert-managertlscertificatesletsencrypt
intermediate ⏱ 15 minutes

Kubernetes Rate Limiting with Gateway API

Implement rate limiting for Kubernetes services using Gateway API, Istio, Kong, NGINX, and Envoy. Protect APIs from abuse

rate-limitinggateway-apiingresssecurity
beginner ⏱ 15 minutes

Kubernetes Service Types LoadBalancer ClusterIP NodePort

Understand Kubernetes Service types: ClusterIP, NodePort, LoadBalancer, and ExternalName. When to use each type, configuration examples, and traffic routing

servicesnetworkingloadbalancerclusterip
intermediate ⏱ 15 minutes

Kubernetes Linkerd Service Mesh mTLS Guide

Deploy Linkerd service mesh on Kubernetes for automatic mTLS, traffic observability, and reliability features. Zero-config encryption, per-route

linkerdservice-meshmtlsobservability
advanced ⏱ 15 minutes

InfiniBand Subnet Manager OpenSM on Kubernetes

Deploy and manage InfiniBand Subnet Manager (OpenSM) on Kubernetes for GPU cluster fabric management. Covers SM architecture, UFM integration, partition

infinibandopensmsubnet-managerfabric
intermediate ⏱ 15 minutes

NMState Network Config for GPU Worker Nodes

Declaratively configure Ethernet bonding, VLANs, MTU, and static routes on GPU worker nodes using NMState on OpenShift. Covers bonding modes, LACP

nmstatebondingvlanopenshift
intermediate ⏱ 15 minutes

OpenShift Multus CNI Multiple Network Interfaces

Attach multiple network interfaces to Pods using Multus CNI on OpenShift. Covers NetworkAttachmentDefinitions, SR-IOV, macvlan, IPVLAN, traffic separation

multuscniopenshiftnetworking
advanced ⏱ 15 minutes

RoCE PFC and ECN Lossless Ethernet for GPU Clusters

Configure RoCE v2 with Priority Flow Control (PFC) and ECN for lossless Ethernet RDMA on GPU clusters. Covers DSCP mapping, switch configuration, NIC

rocepfcecnrdma
advanced ⏱ 15 minutes

Dual-Fabric Mellanox: GPU InfiniBand + Storage Ethernet

Design and configure dual-fabric network architecture with separate Mellanox NICs for GPU communication (InfiniBand) and storage traffic (Ethernet). Covers

infinibandethernetmellanoxdual-fabric
advanced ⏱ 15 minutes

NVIDIA IPAM for GPU Fabric IP Address Allocation

Configure nv-ipam (NVIDIA IPAM) to assign IP addresses on GPU fabric SR-IOV networks in Kubernetes. Covers IPPool CRDs, per-node allocation, InfiniBand IPoIB

nv-ipamipamgpu-fabricsriov
advanced ⏱ 15 minutes

Fix SR-IOV 'Not Enough MMIO Resources' Error

Resolve the mlx5_core 'not enough MMIO resources for SR-IOV' error on OpenShift nodes with Mellanox ConnectX NICs. Covers BIOS settings, PCIe BAR

sriovmmiomellanoxbios
intermediate ⏱ 15 minutes

SR-IOV VF to Container Mapping and Lifecycle

How SR-IOV Virtual Functions are mapped to containers in Kubernetes. Covers VF allocation flow, link state management (VFs are down when unassigned), device

sriovvirtual-functioncontainersdevice-plugin
intermediate ⏱ 15 minutes

VT-x vs VT-d vs SR-IOV Explained

Understand the difference between CPU virtualization (VT-x/SVM), I/O virtualization (VT-d/AMD-Vi/IOMMU), and SR-IOV. Which to enable or disable for GPU

virtualizationiommusriovbios
advanced ⏱ 15 minutes

OpenShift SR-IOV RDMA InfiniBand Device Plugin

Configure and troubleshoot SR-IOV Network Operator with Mellanox ConnectX RDMA InfiniBand devices on OpenShift. Covers SriovNetworkNodePolicy, device

sriovrdmainfinibandmellanox
advanced ⏱ 15 minutes

NVIDIA Network Operator NicClusterPolicy

Deploy NVIDIA Network Operator on OpenShift with NicClusterPolicy for DOCA telemetry, NIC feature discovery, RDMA IPAM, and OFED drivers. GitOps-managed

nvidianetwork-operatorrdmamellanox
intermediate ⏱ 15 minutes

Migrate from externalIPs in Kubernetes 1.36

Service externalIPs are deprecated in Kubernetes 1.36 due to CVE-2020-8554. Migrate to Gateway API, LoadBalancer services, or MetalLB for external access.

kubernetes-1.36deprecationnetworkinggateway-api
intermediate ⏱ 15 minutes

Kubernetes 1.36 SPDY to WebSocket Migration

Kubernetes 1.36 continues migrating kubectl exec/attach/port-forward from SPDY to WebSockets. Understand the changes and troubleshoot connection issues.

kubernetes-1.36kubectlwebsocketsnetworking
advanced ⏱ 15 minutes

Cilium: eBPF-Powered K8s Networking

Deploy Cilium CNI in Kubernetes for eBPF-based networking, network policies, service mesh, and observability with Hubble.

ciliumebpfcninetworking
intermediate ⏱ 10 minutes

K8s DNS for Services: Resolution Guide

Understand Kubernetes DNS for Services and Pods. Service discovery patterns, FQDN format, headless services, DNS policies, ndots configuration.

dnsservicesnetworkingservice-discovery
intermediate ⏱ 10 minutes

K8s EndpointSlice and Service Discovery

Understand Kubernetes EndpointSlice for scalable service discovery. DNS resolution, headless services, external services, and endpoint conditions.

endpointsliceservice-discoverydnsnetworking
intermediate ⏱ 12 minutes

Gateway API: Next-Gen K8s Ingress

Replace Kubernetes Ingress with Gateway API. HTTPRoute, GRPCRoute, TLSRoute configuration. Multi-tenant gateways, traffic splitting, and header-based routing.

gateway-apinetworkingingressrouting
intermediate ⏱ 12 minutes

K8s Ingress NGINX: Routing and TLS

Configure Kubernetes Ingress with NGINX controller. Path-based routing, TLS termination, annotations, rate limiting, and multiple hosts with examples.

ingressnginxtlsrouting
intermediate ⏱ 12 minutes

Linkerd: Lightweight K8s Service Mesh

Deploy Linkerd service mesh in Kubernetes for mTLS, traffic splitting, retries, and observability. Lighter alternative to Istio with zero-config mTLS and min...

linkerdservice-meshnetworkingmtls
intermediate ⏱ 10 minutes

K8s NetworkPolicy: Allow and Deny Rules

Configure Kubernetes NetworkPolicy for pod-to-pod traffic control. Default deny, allow by label, namespace selectors, egress rules, and CIDR blocks.

networkpolicysecuritynetworkingcka
intermediate ⏱ 15 minutes

Kubernetes Rate Limiting Guide

Implement rate limiting in Kubernetes with Ingress annotations, Gateway API, Envoy filters, and application-level middleware. Protect APIs from abuse.

rate-limitingingressgateway-apienvoy
advanced ⏱ 15 minutes

Istio Service Mesh: Traffic Management

Deploy Istio service mesh in Kubernetes for traffic management, mTLS, observability, and canary deployments. VirtualService, DestinationRule.

istioservice-meshnetworkingtraffic-management
beginner ⏱ 10 minutes

K8s Service Types: ClusterIP NodePort LB

Kubernetes Service types explained: ClusterIP, NodePort, LoadBalancer, and ExternalName. When to use each type with YAML examples and traffic flow diagrams.

servicesnetworkingload-balancernodeport
intermediate ⏱ 10 minutes

NGINX Ingress limit-burst-multiplier

Configure nginx.ingress.kubernetes.io/limit-burst-multiplier for rate limiting burst control. Tune burst size, rate limits, and 429 response handling.

nginxingressrate-limitingnetworking
advanced ⏱ 20 minutes

NMState Bond LACP Configuration OpenShift

Configure LACP bonding with NMState on OpenShift. NodeNetworkConfigurationPolicy for 802.3ad bonds, VLAN tagging, and storage network bonds.

nmstatebondinglacpopenshift
beginner ⏱ 15 minutes

Kubernetes Ingress Fundamentals

Configure Kubernetes Ingress for HTTP routing, TLS termination, and path-based routing. NGINX Ingress Controller setup, annotations, and multi-service routing.

ingressnginxtlsrouting
intermediate ⏱ 20 minutes

Kubernetes IPPool Management Guide

Configure IP address pools in Kubernetes with Whereabouts, NV-IPAM, MetalLB, and Calico IPPool for secondary networks and LoadBalancer IPs.

ippoolipamnetworkingwhereabouts
advanced ⏱ 25 minutes

MOFED Driver for Kubernetes: Setup Guide

Install and manage MOFED drivers in Kubernetes. Network Operator integration, NicClusterPolicy, driver versions, and RDMA troubleshooting.

mofedmellanoxnvidiardma
advanced ⏱ 20 minutes

MOFED Driver Operator Build Kubernetes

Let the NVIDIA Network Operator build MOFED drivers on-node via DKMS. Kernel header detection, compile flags, and DTK integration for OpenShift.

mofednvidianetwork-operatordrivers
advanced ⏱ 20 minutes

SR-IOV Device Plugin PF Flag on Kubernetes

Configure SR-IOV device plugin PF flag in Kubernetes. Expose physical functions as allocatable resources for exclusive RDMA access.

sriovdevice-pluginrdmanetworking
beginner ⏱ 15 minutes

cert-manager Cloudflare DNS01 K8s

Configure cert-manager with Cloudflare DNS01 challenge for wildcard TLS certificates on Kubernetes. API token secret, ClusterIssuer, and auto-renewal.

cert-managercloudflaredns01wildcard-tls
intermediate ⏱ 15 minutes

K8s Ingress Rate Limit NGINX Config

Configure rate limiting on Kubernetes NGINX Ingress. limit-rps, limit-burst-multiplier annotations, per-client limits, and webhook protection patterns.

ingressrate-limitnginxannotations
advanced ⏱ 30 minutes

LACP Storage Switch Kubernetes Guide

Configure LACP bond aggregation for NFS and iSCSI storage switches in Kubernetes clusters. 802.3ad setup, hash policies, switch config, and failure handling.

lacpbondingstoragenetworking
beginner ⏱ 15 minutes

NMState Operator Install OpenShift K8s

Install and configure the NMState operator on OpenShift and Kubernetes. Enable declarative node networking with NNCP, NodeNetworkState, and enactments.

nmstateoperatoropenshiftnncp
intermediate ⏱ 25 minutes

NNCP NodeNetworkConfigurationPolicy

Master NodeNetworkConfigurationPolicy (NNCP) on OpenShift and Kubernetes. Configure VLANs, bonds, bridges, SR-IOV, MTU, static IPs, and DNS with NMState.

nncpnmstateopenshiftnetworking
advanced ⏱ 15 minutes

Cilium ClusterMesh Multi-Cluster

Connect multiple K8s clusters with Cilium ClusterMesh. Shared services, global service discovery, and cross-cluster network policies.

ciliumclustermeshmulti-clusterservice-discovery
intermediate ⏱ 15 minutes

Calico NetworkPolicy K8s Guide

Configure Calico NetworkPolicy for K8s. GlobalNetworkPolicy, host endpoints, application layer policies, and DNS policy rules.

caliconetworkpolicyglobalhost-endpoints
intermediate ⏱ 15 minutes

CNI Comparison 2026 Kubernetes

Compare Kubernetes CNI plugins: Calico, Cilium, Flannel, Multus, and OVN-Kubernetes. Performance benchmarks, features, and selection guidance.

cnicalicociliumflannel
intermediate ⏱ 15 minutes

CoreDNS Custom Config Kubernetes

Customize CoreDNS on Kubernetes for advanced DNS needs. Forward zones, stub domains, custom records, caching tuning, and DNS debugging.

corednsdnscustom-configforwarding
intermediate ⏱ 15 minutes

DNS Policy Configuration Kubernetes

Configure Kubernetes DNS policies: Default, ClusterFirst, ClusterFirstWithHostNet, and None. Custom resolv.conf, ndots tuning, and DNS performance.

dnsdns-policycorednsresolv-conf
beginner ⏱ 15 minutes

Ingress Path Routing Kubernetes

Configure Kubernetes Ingress for path-based and host-based routing. PathType Prefix vs Exact, rewrite rules, and multi-service routing patterns.

ingressroutingpath-basedhost-based
beginner ⏱ 10 minutes

Let's Encrypt Ingress Kubernetes

Set up Let's Encrypt TLS certificates for Kubernetes Ingress with cert-manager. HTTP-01 challenge, automatic renewal, and HTTPS redirect configuration.

letsencryptingresstlscert-manager
beginner ⏱ 10 minutes

Service DNS Discovery Kubernetes

How Kubernetes DNS service discovery works. Service FQDN format, headless services, SRV records, and cross-namespace DNS resolution patterns.

dnsservice-discoveryfqdnheadless
beginner ⏱ 15 minutes

OpenShift Routes vs Ingress Guide

Compare OpenShift Routes and Kubernetes Ingress. Covers edge, passthrough, and re-encrypt TLS termination, and when to use each option.

openshiftroutesingresstls
advanced ⏱ 20 minutes

Dell Switch RoCEv2 PFC ECN DSCP

Configure Dell OS10 switches for lossless RoCEv2 with PFC, ECN, WRED, and DSCP-to-traffic-class mapping. Priority 3 for RDMA traffic classes 24 and 26.

dellswitchrocev2pfc
advanced ⏱ 15 minutes

ECN MachineConfig OpenShift Nodes

Enable ECN (Explicit Congestion Notification) on OpenShift nodes via MachineConfig for lossless RoCEv2 RDMA networking. Sysctl and Mellanox NIC configuration.

ecnmachineconfigopenshiftrdma
intermediate ⏱ 15 minutes

CoreDNS Customization Guide Kubernetes

Customize CoreDNS with forward zones, rewrite rules, cache tuning, and stub domains. Troubleshoot DNS resolution failures and optimize query performance in.

corednsdnsnetworkingtroubleshooting
advanced ⏱ 15 minutes

EndpointSlices and Service Topology

Understand EndpointSlices for scalable service discovery in Kubernetes. Covers topology-aware routing and traffic localization for large clusters.

endpointsliceservice-topologyroutingtraffic-localization
intermediate ⏱ 20 minutes

ExternalDNS Automation Kubernetes

Automate DNS record management with ExternalDNS on Kubernetes. Route53, CloudDNS, and Azure DNS integration for Ingress, Service, and Gateway resources.

external-dnsdnsautomationroute53
intermediate ⏱ 15 minutes

Gateway API HTTPRoute Kubernetes

Configure HTTPRoute for Kubernetes Gateway API. Path matching, header-based routing, traffic splitting, URL rewriting, and request mirroring.

gateway-apihttprouteroutingtraffic-splitting
advanced ⏱ 15 minutes

DNS Autoscaling and CoreDNS Scaling

Scale CoreDNS horizontally with dns-autoscaler and proportional autoscaling. Tune cache size, configure node-local DNS cache.

dnscorednsautoscalingnode-local-dns
advanced ⏱ 15 minutes

Istio Traffic Management Kubernetes

Advanced Istio traffic management on Kubernetes. VirtualService routing, DestinationRule load balancing, traffic mirroring, fault injection.

istiotraffic-managementvirtual-servicecircuit-breaker
intermediate ⏱ 20 minutes

MetalLB Bare Metal Load Balancer

Deploy MetalLB for LoadBalancer services on bare-metal Kubernetes. L2 mode, BGP mode, IP address pools, and integration with Cilium and Gateway API.

metallbload-balancerbare-metalbgp
advanced ⏱ 20 minutes

Multi-Cluster Service Mesh Kubernetes

Connect multiple Kubernetes clusters with service mesh federation. Istio multi-cluster, Linkerd multi-cluster, cross-cluster service discovery.

multi-clusterservice-meshistiolinkerd
intermediate ⏱ 15 minutes

Service Mesh Comparison Kubernetes

Compare Istio, Linkerd, and Cilium service mesh for Kubernetes. mTLS, observability, traffic management, resource overhead.

service-meshistiolinkerdcilium
intermediate ⏱ 15 minutes

Topology-Aware Routing Kubernetes

Enable topology-aware routing for cost optimization on Kubernetes. Zone-local traffic, EndpointSlice hints, and reducing cross-zone data transfer costs.

topologyroutingzone-awarecost-optimization
advanced ⏱ 15 minutes

Mellanox RoCE DSCP QoS DaemonSet

Deploy a DaemonSet that configures DSCP trust, PFC priority 3, and RoCE ToS 106 on all Mellanox PFs. Uses DOCA driver image with ibdev2netdev, mlnx_qos.

mellanoxrocedscppfc
advanced ⏱ 20 minutes

RDMA Network QoS Traffic Classes DCQCN

Complete RDMA network QoS architecture with traffic classes TC0-TC6, DSCP and dot1p mappings, PFC, ECN, WRED, and DCQCN congestion control for lossless RoC.

rdmaqostraffic-classdcqcn
advanced ⏱ 30 minutes

RoCEv2 End-to-End Lossless Stack

Complete RoCEv2 lossless fabric configuration from GPU node to switch and back. Dell OS10 switches, Mellanox NICs, OpenShift MachineConfig, PFC, ECN.

rocev2losslesspfcecn
advanced ⏱ 18 minutes

ib_write_bw RDMA Bandwidth Testing

Run ib_write_bw from perftest on Kubernetes to measure RDMA write bandwidth between GPU nodes. Full CLI reference, bidirectional tests, HugePages.

ib-write-bwperftestrdmainfiniband
advanced ⏱ 20 minutes

mlnx_qos QoS on MOFED Containers

Configure RDMA QoS with mlnx_qos from MOFED containers on Kubernetes. Set PFC, ETS, DSCP trust mode, and validate lossless RoCE traffic classes on ConnectX.

mlnx-qosmofedpfcets
intermediate ⏱ 10 minutes

EndpointSlice Service Discovery

Understand Kubernetes EndpointSlices for scalable service discovery. Compare with legacy Endpoints and configure topology-aware routing.

endpointsliceservice-discoverynetworkingtopology
intermediate ⏱ 12 minutes

Kubernetes Egress Network Policies

Control outbound traffic from pods with egress NetworkPolicies. Allow DNS, block internet access, and restrict pod-to-pod communication by namespace.

network-policyegresssecurityzero-trust
advanced ⏱ 12 minutes

Topology-Aware Service Routing

Enable zone-aware traffic routing in Kubernetes to reduce cross-zone latency and egress costs. Configure topology hints and traffic distribution.

topology-routingzone-awaretraffic-distributionnetworking
advanced ⏱ 20 minutes

SR-IOV NetworkNodePolicy for RDMA

Configure SriovNetworkNodePolicy on OpenShift to create RDMA-capable VFs on Mellanox ConnectX NICs for GPUDirect RDMA and high-performance AI networking.

sriovrdmamellanoxgpudirect
intermediate ⏱ 30 minutes

Cilium eBPF Gateway API Hubble k3s

Install Cilium with eBPF dataplane, Gateway API support, and Hubble observability on k3s. Replace kube-proxy with eBPF, configure GatewayClass.

ciliumebpfgateway-apihubble
intermediate ⏱ 20 minutes

Gateway API HTTPRoutes TLS on k3s

Configure Gateway API HTTPRoutes with TLS termination on k3s using Cilium. Route traffic to multiple services with wildcard certificates and HTTP-to-HTTPS .

gateway-apihttproutetlscilium
intermediate ⏱ 10 minutes

Kubernetes DNS Policy ClusterFirstWithHostNet

Configure Kubernetes DNS policies: ClusterFirst, ClusterFirstWithHostNet, Default, and None. Fix DNS resolution for hostNetwork pods and custom nameservers.

dnsdnspolicyhostnetworkresolv-conf
advanced ⏱ 15 minutes

Gateway API gRPC Routes on Kubernetes

Configure Kubernetes Gateway API GRPCRoute for gRPC traffic routing. Service-level matching, header-based routing, and traffic splitting for gRPC services.

gateway-apigrpcnetworkingrouting
beginner ⏱ 10 minutes

Kubernetes Service DNS Resolution

How Kubernetes Service DNS works: naming conventions, FQDN format, headless services, cross-namespace resolution, and DNS debugging with nslookup.

dnsservicecorednsnetworking
advanced ⏱ 30 minutes

DCB on Mellanox ConnectX: Lossless Ethernet...

Configure Data Center Bridging (DCB) on Mellanox ConnectX NICs. DCBX negotiation, PFC, ETS, and CN for lossless RoCE Ethernet in Kubernetes AI clusters.

dcbdcbxpfcets
intermediate ⏱ 10 minutes

ETS Queue, PFC, DSCP Trust on Mellanox Quic...

Quick reference for enabling ETS queues, PFC, DSCP trust, and DSCP-to-priority mapping on Mellanox ConnectX NICs. Three commands for lossless RoCE Ethernet.

etspfcdscpmellanox
intermediate ⏱ 20 minutes

NMState & nmstatectl: Node Network Management

Manage node networking with NMState declarative API and nmstatectl CLI. Create NodeNetworkConfigurationPolicy manifests, verify with nmstatectl.

nmstatenmstatectlnncpnode-networking
advanced ⏱ 25 minutes

PFC Configuration on Mellanox ConnectX NICs

Enable Priority Flow Control on Mellanox ConnectX-6/7 NICs for lossless RoCE. mlnx_qos, cma_roce_mode, DSCP trust, ECN, and firmware-level PFC verification.

pfcmellanoxconnectxroce
advanced ⏱ 25 minutes

Extended Resources & RDMA Shared Device Plugin

Kubernetes extended resources for RDMA devices using the shared device plugin. Advertise and schedule InfiniBand and RoCE NICs without SR-IOV using k8s-rdm.

extended-resourcesrdmashared-device-plugininfiniband
advanced ⏱ 25 minutes

Kubernetes Route and Ingress Management Guide

Manage OpenShift Routes and Kubernetes Ingress resources. TLS termination, path-based routing, weighted traffic splitting.

routeingressopenshift-routegateway-api
advanced ⏱ 40 minutes

Configure PFC with NMState on Kubernetes

Enable Priority Flow Control (PFC) for lossless RDMA using NMState and NodeNetworkConfigurationPolicy. Configure DSCP-to-priority mapping, ECN, and RoCEv2 QoS.

pfcnmstatenncprdma
advanced ⏱ 25 minutes

Cilium Service Mesh: eBPF-Powered Kubernetes

Deploy Cilium service mesh on Kubernetes with eBPF. Sidecar-free mTLS, L7 traffic management, network policies, Hubble observability, and Gateway API support.

ciliumservice-meshebpfmtls
intermediate ⏱ 10 minutes

Kubernetes dnsPolicy and dnsConfig Explained

Configure Kubernetes dnsPolicy: ClusterFirst, Default, None, ClusterFirstWithHostNet. Custom dnsConfig with nameservers, searches, and ndots options.

dnsdnspolicycorednsnetworking
beginner ⏱ 10 minutes

Kubernetes Service Types Comparison

Compare Kubernetes Service types: ClusterIP for internal access, NodePort for direct port exposure, LoadBalancer for external traffic.

servicesclusteripnodeportloadbalancer
advanced ⏱ 15 minutes

NCCL_SOCKET_IFNAME Environment Variable Guide

Configure NCCL_SOCKET_IFNAME for multi-node GPU training on Kubernetes. Network interface selection, bonding, InfiniBand, and troubleshooting NCCL timeouts.

ncclgpu-trainingdistributed-trainingenvironment-variables
advanced ⏱ 50 minutes

Enterprise Service Mesh mTLS & Observability

Deploy Istio service mesh for enterprise mTLS, traffic management, circuit breaking, and distributed tracing across microservices on Kubernetes.

istioservice-meshmtlstraffic-management
intermediate ⏱ 15 minutes

External DNS for Kubernetes: Setup Guide

Automate DNS record management with ExternalDNS for Kubernetes. Sync Service and Ingress hostnames to Route53, CloudFlare, Google Cloud DNS, and 30+ providers.

external-dnsdnsroute53cloudflare
intermediate ⏱ 15 minutes

Kubernetes ClusterIP Service Explained

Understand Kubernetes ClusterIP services for internal communication. How kube-proxy routes traffic, DNS resolution, and when ClusterIP is the right service

clusteripserviceinternaldns
intermediate ⏱ 15 minutes

Kubernetes DNS and CoreDNS Guide

Understand Kubernetes DNS resolution with CoreDNS. Debug DNS issues, configure custom DNS, and optimize DNS performance for large clusters.

dnscorednsservice-discoverynetworking
intermediate ⏱ 15 minutes

Kubernetes Ingress Complete Guide

Configure Kubernetes Ingress for HTTP routing, TLS termination, and path-based routing. Covers NGINX Ingress Controller, cert-manager, and Ingress vs Gateway

ingressnginx-ingresstlsrouting
intermediate ⏱ 15 minutes

Kubernetes LoadBalancer Service Guide

Expose Kubernetes services with LoadBalancer type for production traffic. Covers cloud providers, MetalLB for bare-metal, health checks, and cost optimization.

loadbalancerserviceexternal-accessmetallb
intermediate ⏱ 15 minutes

Kubernetes NodePort Service Explained

Expose Kubernetes services externally with NodePort. Understand port ranges, security implications, and when to use NodePort vs LoadBalancer vs Ingress.

nodeportserviceexternal-accessnetworking
intermediate ⏱ 15 minutes

Kubernetes Service Types Explained

Compare all Kubernetes service types: ClusterIP, NodePort, LoadBalancer, ExternalName, and headless. Choose the right type for internal, external, and hybrid

service-typesclusteripnodeportloadbalancer
intermediate ⏱ 15 minutes

Kubernetes EndpointSlices Explained

Understand Kubernetes EndpointSlices for scalable service endpoint management. How they improve on Endpoints objects for large clusters with thousands of pods.

endpointslicesendpointsservice-discoverynetworking
intermediate ⏱ 15 minutes

Kubernetes Headless Service Explained

Create Kubernetes headless services for StatefulSet DNS, direct pod addressing, and service discovery. Understand when clusterIP None is the right choice.

headless-servicestatefulsetdnsservice-discovery
intermediate ⏱ 15 minutes

Kubernetes DNS: How Service Discovery Works

Understand Kubernetes DNS resolution with CoreDNS. Service discovery, pod DNS, headless services, custom DNS policies, and troubleshooting DNS failures.

dnscorednsservice-discoverynetworking
beginner ⏱ 15 minutes

K8s Ingress: Routing, TLS, and Controllers

Configure Kubernetes Ingress for HTTP routing, TLS termination, and path-based routing. Covers NGINX, Traefik, and HAProxy ingress controllers.

ingressroutingtlsnginx
intermediate ⏱ 15 minutes

Kubernetes Load Balancing Strategies

Configure Kubernetes load balancing with Services, Ingress, and Gateway API. Round-robin, session affinity, weighted routing, and traffic policy.

load-balancingserviceingressgateway-api
intermediate ⏱ 15 minutes

Fix Ingress 502 and 503 Gateway Errors

Debug 502 Bad Gateway and 503 Service Unavailable from Kubernetes ingress controllers. Fix backend health and timeout issues.

ingressnginx502503
intermediate ⏱ 15 minutes

Kubernetes CNI Plugins Compared

Compare Calico, Cilium, Flannel, and Multus CNI plugins for Kubernetes. Performance benchmarks, features, and selection criteria for your cluster.

cnicalicociliumflannel
intermediate ⏱ 25 minutes

Configure Knative Ingress Networking

Set up Knative Serving ingress with Kourier, Istio, or Contour. Custom domains, TLS, path routing, and external visibility.

knativeingresskourieristio
intermediate ⏱ 30 minutes

Migrate Ingress to Gateway API ingress2gateway

Migrate Ingress to Gateway API using ingress2gateway. Convert HTTPRoute and TLSRoute with zero-downtime parallel migration.

gateway-apiingressmigrationingress2gateway
intermediate ⏱ 25 minutes

Expose OpenClaw via K8s Ingress with TLS

Configure Kubernetes Ingress with TLS to expose OpenClaw gateway securely. Covers cert-manager, NGINX Ingress, and allowed origins.

openclawingresstlscert-manager
intermediate ⏱ 15 minutes

Manage hostNetwork Pod Port Allocation

Plan and manage host port usage for hostNetwork pods. Prevent port conflicts, track allocations, and handle port exhaustion.

hostnetworkportsschedulingnetworking
intermediate ⏱ 25 minutes

Configure SR-IOV agent-config.yaml Device b...

Use agent-config.yaml to select network devices by PCI path for SR-IOV VF creation, ensuring deterministic NIC targeting across OpenShift nodes.

sr-iovnetworkingopenshiftnvidia
advanced ⏱ 15 minutes

GPUDirect RDMA via DMA-BUF on Kubernetes

Configure GPUDirect RDMA using DMA-BUF kernel subsystem for zero-copy GPU-to-GPU transfers over InfiniBand and RoCE networks.

gpudirectrdmadma-bufinfiniband
advanced ⏱ 15 minutes

HAProxy Keepalived Multi-Tenant GPU Ingress

Configure HAProxy with Keepalived VIPs for per-tenant GPU cluster ingress with Jinja2 templates and per-tenant access logging.

haproxykeepalivedmulti-tenantvip
advanced ⏱ 15 minutes

InfiniBand vs Ethernet for AI on Kubernetes

Compare InfiniBand and Ethernet networking for GPU AI workloads on Kubernetes, including RDMA, RoCE, latency, and throughput considerations.

infinibandethernetrdmaroce
advanced ⏱ 25 minutes

NFSoRDMA Bond with Access Mode Switch

Configure bonded NICs for NFS over RDMA using switch access mode for VLAN assignment. Aggregation on untagged interfaces for RDMA redundancy.

nfsordmardmabondinglacp
advanced ⏱ 25 minutes

NFSoRDMA Dedicated NIC Configuration

Configure dedicated NICs for NFS over RDMA on Kubernetes worker nodes. NFSoRDMA requires untagged interfaces β€” no VLAN tagging supported.

nfsordmardmanfsnetworking
advanced ⏱ 15 minutes

NFSoRDMA Jumbo Frames MTU Configuration

Configure 9000 MTU jumbo frames for NFSoRDMA interfaces using NNCP to maximize RDMA throughput on Kubernetes worker nodes.

nfsordmardmamtujumbo-frames
advanced ⏱ 30 minutes

NFSoRDMA Multi-VLAN Switch Access Mode

Design multi-VLAN NFSoRDMA networks using switch access mode ports. Separate storage, replication, and backup traffic with dedicated NICs per VLAN.

nfsordmardmavlanaccess-mode
advanced ⏱ 20 minutes

NFSoRDMA Troubleshooting and Performance

Troubleshoot NFS over RDMA connectivity issues, diagnose TCP fallback, tune performance, and benchmark RDMA throughput on Kubernetes workers.

nfsordmardmatroubleshootingperformance
advanced ⏱ 30 minutes

NFSoRDMA Worker Node Setup Guide

Complete worker node setup for NFS over RDMA including kernel modules, NFS client configuration, PersistentVolume mounts, and RDMA transport verification.

nfsordmardmanfspersistent-volume
intermediate ⏱ 15 minutes

NNCP DNS and Static Routes on Workers

Configure static routes, DNS servers, and policy-based routing on worker nodes using NodeNetworkConfigurationPolicy for multi-network setups.

nncpnmstatednsrouting
intermediate ⏱ 20 minutes

NNCP Bond Interfaces on Worker Nodes

Create bonded network interfaces on Kubernetes worker nodes using NodeNetworkConfigurationPolicy for NIC redundancy and link aggregation.

nncpnmstatebondinglacp
intermediate ⏱ 20 minutes

NNCP Linux Bridge on Worker Nodes

Create Linux bridges on Kubernetes worker nodes using NodeNetworkConfigurationPolicy for KubeVirt VM networking and pod bridging.

nncpnmstatelinux-bridgekubevirt
intermediate ⏱ 15 minutes

NNCP MTU and Jumbo Frames on Workers

Set MTU and enable jumbo frames on worker node interfaces using NodeNetworkConfigurationPolicy for high-throughput storage and AI networking.

nncpnmstatemtujumbo-frames
advanced ⏱ 30 minutes

NNCP Multi-NIC Architecture for Workers

Design a complete multi-NIC worker node architecture with NNCP for separated management, storage, tenant, and GPU traffic using bonds, VLANs, and bridges.

nncpnmstatemulti-nicarchitecture
advanced ⏱ 25 minutes

NNCP OVS Bridge on Worker Nodes

Configure Open vSwitch bridges on Kubernetes worker nodes using NodeNetworkConfigurationPolicy for advanced SDN and DPDK networking.

nncpnmstateovsopenvswitch
intermediate ⏱ 15 minutes

NNCP Rollback and Troubleshooting

Troubleshoot NodeNetworkConfigurationPolicy failures, monitor enactments, configure rollback timeouts, and recover from bad network configurations.

nncpnmstatetroubleshootingrollback
advanced ⏱ 25 minutes

NNCP SR-IOV and Macvlan on Workers

Configure SR-IOV virtual functions and macvlan interfaces on worker nodes using NodeNetworkConfigurationPolicy for high-performance networking.

nncpnmstatesriovmacvlan
intermediate ⏱ 15 minutes

NNCP Static IP Assignment on Worker Nodes

Use NodeNetworkConfigurationPolicy to assign static IPv4 and IPv6 addresses to worker node interfaces with nodeSelector targeting.

nncpnmstatenetworkingstatic-ip
intermediate ⏱ 15 minutes

NNCP VLAN Tagging on Worker Nodes

Configure VLAN interfaces on Kubernetes worker nodes using NodeNetworkConfigurationPolicy for network segmentation and traffic isolation.

nncpnmstatevlannetworking
intermediate ⏱ 15 minutes

NodePort Raw Traffic vs HTTPS Ingress

Route raw GPU inference traffic via NodePort for low-latency gRPC and HTTPS model serving via OpenShift ingress controller.

nodeportingressgrpctls
advanced ⏱ 15 minutes

NVIDIA NIC Driver Container Entrypoint

Understand and customize the NVIDIA NIC driver container entrypoint for MOFED and DOCA driver lifecycle on Kubernetes and OpenShift.

nvidiamofeddocadriver
advanced ⏱ 15 minutes

SR-IOV Mixed NICs for GPU Nodes

Configure SR-IOV with mixed ConnectX-7 and ConnectX-6 NICs for RDMA data plane and management traffic on GPU worker nodes.

sriovconnectx-7connectx-6rdma
advanced ⏱ 30 minutes

SR-IOV VF Networking for AI Workloads

Deploy SR-IOV Virtual Functions with RDMA support for distributed AI training on Kubernetes, including multi-NIC pod configuration and NCCL tuning.

sriovrdmaaidistributed-training
advanced ⏱ 25 minutes

SR-IOV NicClusterPolicy for VF Configuration

Configure SR-IOV Virtual Functions on Mellanox ConnectX NICs using the NVIDIA Network Operator NicClusterPolicy for high-performance Kubernetes networking.

sriovnetworkingnvidiavirtual-functions
advanced ⏱ 60 minutes

Configure GPUDirect RDMA the NVIDIA GPU Ope...

Set up GPUDirect RDMA on Kubernetes using the NVIDIA GPU Operator with either DMA-BUF or legacy nvidia-peermem, including Network Operator integration.

nvidiagpurdmagpudirect
advanced ⏱ 45 minutes

Switch GPUDirect RDMA from nvidia-peermem t...

Migrate from the legacy nvidia-peermem kernel module to the recommended DMA-BUF GPUDirect RDMA path using the NVIDIA GPU Operator.

nvidiagpurdmadma-buf
advanced ⏱ 30 minutes

Validate GPUDirect RDMA Performance DMA-BUF

Run ib_write_bw with CUDA DMA-BUF to verify GPUDirect RDMA data transfer rates between GPU pods and validate network operator configuration.

nvidiagpurdmadma-buf
advanced ⏱ 20 minutes

Configure SriovNetwork with NVIDIA nv-ipam

Create a SriovNetwork resource that auto-generates a Multus NetworkAttachmentDefinition using nv-ipam for high-performance SR-IOV secondary interfaces.

sriovnetworknv-ipammultusopenshift
advanced ⏱ 15 minutes

Create an NVIDIA nv-ipam IPPool SR-IOV Netw...

Define a valid nv-ipam IPPool and node-aware sizing strategy so SR-IOV workloads can reliably obtain secondary interface IP addresses on Kubernetes.

nv-ipamippoolsriovipam
intermediate ⏱ 20 minutes

Enable NIC Feature Discovery in NVIDIA Netw...

Enable NIC Feature Discovery through NicClusterPolicy and verify the node labels required by SR-IOV and RDMA GPU networking workflows on Kubernetes.

nvidianetwork-operatornic-feature-discoverysriov
intermediate ⏱ 25 minutes

Create SR-IOV VFs on OpenShift SriovNetwork...

Use the OpenShift SR-IOV Network Operator to create and manage Virtual Functions from selected Physical Functions on GPU worker nodes.

openshiftsriovvfnetwork-operator
intermediate ⏱ 15 minutes

Verify Which Interface Carries OVN Underlay...

Confirm the actual OVN underlay network path by checking ovn-encap-ip, bridge port ownership, and physical route associations on Kubernetes nodes.

ovnunderlayopenshiftnetworking
advanced ⏱ 55 minutes

Istio Traffic Management and Routing

Implement advanced traffic management with Istio service mesh including traffic splitting, fault injection, circuit breaking, and intelligent routing.

istioservice-meshtraffic-managementcircuit-breaker
intermediate ⏱ 30 minutes

Kubernetes Gateway API: HTTPRoute Guide

Deploy Kubernetes Gateway API for HTTP routing. GatewayClass, Gateway, HTTPRoute, TLSRoute, traffic splitting, and migration from Ingress resources.

gateway-apinetworkingingressrouting
intermediate ⏱ 35 minutes

Linkerd Service Mesh: mTLS and Observability

Deploy Linkerd service mesh on Kubernetes. Automatic mTLS, traffic management, observability dashboards, service profiles, and traffic splitting.

linkerdservice-meshmtlsobservability
intermediate ⏱ 15 minutes

How to Configure Kubernetes Cluster DNS

Customize CoreDNS configuration for your cluster. Add custom DNS entries, configure forwarding, and optimize DNS resolution.

corednsdnsnetworkingconfiguration
intermediate ⏱ 15 minutes

How to Customize DNS Configuration in K8s

Configure custom DNS settings in Kubernetes. Learn CoreDNS customization, stub domains, upstream servers, and pod DNS policies.

dnscorednsnetworkingconfiguration
intermediate ⏱ 15 minutes

How to Configure Kubernetes DNS Policies

Control pod DNS resolution with DNS policies and configs. Configure custom nameservers, search domains, and optimize DNS for your workloads.

dnsnetworkingcorednsresolution
intermediate ⏱ 15 minutes

How to Implement Request Routing with Ingress

Configure advanced routing rules with Kubernetes Ingress. Implement path-based routing, host-based routing, and traffic management.

ingressroutingtrafficnginx
intermediate ⏱ 15 minutes

Secure Ingress with SSL/TLS Certificates

Configure TLS termination for Kubernetes Ingress using cert-manager and Let's Encrypt. Automate certificate issuance and renewal.

tlssslcertificatesingress
advanced ⏱ 15 minutes

How to Implement Service Mesh with Istio

Deploy Istio service mesh for traffic management, security, and observability. Learn to configure virtual services, destination rules, and mTLS.

istioservice-meshtrafficmtls
intermediate ⏱ 15 minutes

How to Configure DNS in Kubernetes

Understand and configure Kubernetes DNS with CoreDNS. Customize DNS policies, configure external DNS resolution, and troubleshoot DNS issues.

dnscorednsnetworkingservice-discovery
intermediate ⏱ 15 minutes

How to Use Kubernetes EndpointSlices

Understand and manage EndpointSlices for scalable service discovery. Configure endpoint slicing, troubleshoot connectivity, and optimize large clusters.

endpointslicesservicesnetworkingdiscovery
intermediate ⏱ 15 minutes

How to Implement Network Policies

Secure pod-to-pod communication with Kubernetes Network Policies. Learn to create ingress and egress rules, isolate namespaces, and implement zero-trust.

network-policiessecuritynetworkingzero-trust
intermediate ⏱ 15 minutes

Kubernetes Rate Limiting with NGINX and Istio

Implement Kubernetes rate limiting for API protection. Ingress NGINX annotations, Istio rate limits, Kong plugins, and per-service rate limiting patterns.

rate-limitingingressapi-gatewaytraffic-management
beginner ⏱ 15 minutes

Expose Services with LoadBalancer and NodePort

Learn different ways to expose Kubernetes services externally using LoadBalancer, NodePort, and ExternalIPs. Compare options for various environments.

serviceloadbalancernodeportnetworking
beginner ⏱ 10 minutes

K8s NetworkPolicy: Default Deny All Traffic

Implement zero-trust network security in Kubernetes with default deny-all NetworkPolicy. Block all ingress and egress traffic with allow-list rules.

networkpolicysecurityzero-trustnetworking
intermediate ⏱ 20 minutes

Configure NGINX Ingress TLS using cert-manager

Learn how to set up NGINX Ingress Controller with automatic TLS certificates from Let's Encrypt using cert-manager. Complete YAML examples and.

ingressnginxtlscert-manager
Luca Berton Ansible Pilot Ansible by Example Open Empower K8s Recipes Terraform Pilot CopyPasteLearn ProteinLens