The DevOps path · beginner → production engineer
Don't just learn tools.
Learn how production fits together.
This is the map for every DevOps course on Hectal: where to start, what order to learn things in, which project to build after each step, and the advanced guides that tie it all into one production system. Each course links to the others where topics connect, so you always know why you're learning something and where it shows up next.
The end goal
Not someone who knows Docker commands, Kubernetes commands, and Jenkins, but someone who can take a service all the way from commit to a reliable production system:
The learning order
- 01DevOps Fundamentals
Why DevOps exists, the lifecycle, CALMS, roles, and how success is measured.
- 02Linux
Shell, filesystem, permissions, processes, systemd, storage, Bash scripting.
- 03Networking
IP and subnetting, TCP/UDP, DNS, routing and NAT, load balancing, Nginx, troubleshooting.
- 04Git
Commits, branching, merging and rebasing, workflows, pull requests, recovery.
- 05CI/CD
Build systems (Maven/Gradle), pipelines, GitHub Actions, Jenkins, GitLab CI, artifacts, deployment strategies.
- 06The Twelve-Factor App
Write services platforms can run well: config, statelessness, graceful shutdown, trunk-based development, feature flags.
- 07Docker
Images, Dockerfiles, volumes, networks, Compose, multi-stage builds, container internals.
- 08AWS
IAM, EC2, VPC, load balancers, S3, RDS, containers, serverless, messaging, monitoring.
- 09Terraform
Build ShopLite's AWS infrastructure as code: state, modules, environments, CI, testing.
- 10Kubernetes
Workloads, services, config, storage, scheduling, scaling, security, troubleshooting, Helm, operators.
- 11GitOps & Config Management
Ansible, Argo CD, environments, secrets in Git, canary/blue-green with Argo Rollouts, multi-cluster.
- 12System Design
The architecture view behind everything you run: scalability, databases, caching, messaging, microservices, distributed systems, and production architecture. Each topic links to where you build and operate it in these courses.
- 13Stateful Systems
PostgreSQL, Kafka, RabbitMQ/SQS, Redis, Elasticsearch/OpenSearch, performance engineering.
- 14Secrets Management
Secrets Manager vs Parameter Store, HashiCorp Vault, dynamic secrets, rotation, envelope encryption.
- 15Observability
Metrics, logs, traces with Prometheus, Grafana, Loki, Tempo, OpenTelemetry; SLO alerting.
- 16DevSecOps
Secrets, supply chain, container and IaC hardening, pipeline security, runtime detection.
- 17SRE
Incident response, SLOs and error budgets, toil, capacity, cascading failures, game days.
- 18Incident Management & Reliability Metrics
Severity, on-call, escalation, incident command, runbooks vs playbooks, RCA, MTTD/MTTR/MTBF.
- 19Production Architecture & DR
How it all fits: edge, HA, multi-region, disaster recovery strategies.
- 20Cloud Cost Optimization
FinOps, right-sizing, Savings Plans, Spot, storage and network costs, Kubernetes cost.
- 21Advanced AWS & Landing Zones
Organizations, SCPs, Control Tower, Transit Gateway, PrivateLink, security services.
- 22Advanced Kubernetes Ecosystem
CNI, CSI, service mesh, KEDA, Falco, cluster upgrades, and how the ecosystem fits.
- 23Infrastructure Testing & Policy as Code
Terraform tests, Terratest, Helm/Kubernetes tests, OPA/Rego, Conftest, pipeline testing.
- 24Chaos Engineering
Steady-state hypotheses, blast radius, Chaos Mesh, LitmusChaos, AWS FIS.
- 25Platform Engineering
Build the internal developer platform: Gateway API, Karpenter, Kyverno, Backstage, Crossplane, DORA.
- 26The Tooling Landscape
Alternatives for every job (OpenTofu, Pulumi, CDK, Tekton, Podman...) and the AWS ↔ Azure ↔ GCP map.
- 27Interviews & Career
How DevOps interviews work, a troubleshooting framework, design rounds, portfolio, and growth.
Guides that connect the courses
DevOps Fundamentals
Why DevOps exists, from waterfall to agile to continuous delivery; the CALMS framework and the Three Ways; the DevOps lifecycle; CI, CD, and CT; IaC and configuration management; feedback loops; the roles; and how success is measured.
Production Architecture, High Availability, and Disaster Recovery
How a production request flows from DNS to database and back, designing for high availability (no single point of failure, multi-AZ), multi-region patterns, the four disaster recovery strategies, and how observability and on-call close the loop.
Chaos Engineering
Breaking things on purpose, safely: steady-state hypotheses, blast radius and stop conditions, pod/network/CPU/memory/dependency/zone failure experiments with Chaos Mesh, LitmusChaos, and AWS Fault Injection Service.
Cloud Cost Optimization (FinOps)
Where cloud money actually goes, right-sizing, Savings Plans and Reserved Instances, Spot, storage lifecycle, the hidden costs of NAT gateways and data transfer, Kubernetes cost allocation, and budgets and anomaly alerts.
Infrastructure Testing and Policy as Code
The testing pyramid for infrastructure: formatting and static analysis, Terraform native tests with mocks, Terratest integration tests, Helm and Kubernetes manifest tests, OPA/Rego and Conftest policies, and testing the pipelines themselves.
Advanced AWS: Landing Zones, Network Hubs, and Security Services
Running AWS at company scale: Organizations, SCPs, Control Tower and landing zones, IAM Identity Center, Transit Gateway, PrivateLink and endpoints, WAF and Shield, and the detective services (CloudTrail, Config, GuardDuty, Security Hub, Inspector, Macie) wired together with EventBridge.
The Advanced Kubernetes Ecosystem
A map of the add-ons production clusters run: CNI and eBPF networking, CSI storage, service mesh (mTLS, retries, traffic shifting), KEDA event-driven autoscaling, Falco runtime security, and safe cluster upgrades.
Incident Management and Reliability Metrics
The incident lifecycle from detection to postmortem: severity levels, on-call and escalation, incident command roles, runbooks vs playbooks, root cause analysis, corrective actions, and the metrics that measure it all (MTTD, MTTA, MTTR, MTBF, change failure rate).
Secrets Management: Vault, Dynamic Secrets, and Rotation
Where secrets should live and how they reach workloads: AWS Secrets Manager vs Parameter Store, HashiCorp Vault (KV, dynamic database credentials, Kubernetes auth), injection patterns, automatic rotation, envelope encryption with KMS, and short-lived credentials everywhere.
The Twelve-Factor App and Cloud-Native Service Design
What makes an application easy to containerise, scale, and operate: the twelve factors mapped to Spring Boot and Kubernetes, graceful shutdown, health endpoints, trunk-based development, feature flags, and semantic versioning.
The Tooling Landscape: Alternatives and the Multi-Cloud Map
The courses teach one main tool per job. This guide maps the alternatives you'll meet in job descriptions (OpenTofu, Pulumi, CDK/CloudFormation, Terragrunt, Atlantis; Tekton, Argo Workflows, Spinnaker, Azure DevOps; Podman, Buildah, Kaniko) and translates AWS services to Azure and GCP.
DevOps Interviews and Career: Turning Skills Into a Job
How DevOps/SRE/platform interviews are run, a framework for troubleshooting questions, infrastructure design rounds, live-debugging scenarios to practise, building a portfolio from the 12 projects, and growing from junior to senior.
Projects: build these progressively
Project 1 · 1–2 days
Deploy Spring Boot on a Bare Linux Server
BeginnerProject 2 · 1 day
Dockerize the Spring Boot Service
BeginnerProject 3 · 2–3 days
The Full Stack in Docker Compose
IntermediateProject 4 · 2 days
CI/CD Pipeline with Jenkins
IntermediateProject 5 · 3–4 days
Deploy the Complete App to Kubernetes
IntermediateProject 6 · 2 days
Package Everything as Helm Charts
IntermediateProject 7 · 4–5 days
AWS Infrastructure with Terraform
IntermediateProject 8 · 4–5 days
Run the Stack on Amazon EKS
AdvancedProject 9 · 3–4 days
GitOps Delivery: GitHub Actions → ECR → Argo CD → EKS
AdvancedProject 10 · 4 days
Full Observability: OpenTelemetry, Prometheus, Grafana, Loki, Tempo
AdvancedProject 11 · 3 days
A DevSecOps Pipeline: Scan, SBOM, Sign, Verify
AdvancedProject 12 · 2–3 weeks