Command Palette

Search for a command to run...

Hectal

The DevOps path · beginner → production engineer

Don't just learn tools.
Learn how production fits together.

This is the map for every DevOps course on Hectal: where to start, what order to learn things in, which project to build after each step, and the advanced guides that tie it all into one production system. Each course links to the others where topics connect, so you always know why you're learning something and where it shows up next.

The end goal

Not someone who knows Docker commands, Kubernetes commands, and Jenkins, but someone who can take a service all the way from commit to a reliable production system:

From code to productiondiagram
Rendering diagram…

The learning order

  1. 01
    DevOps Fundamentals

    Why DevOps exists, the lifecycle, CALMS, roles, and how success is measured.

  2. 02
    Linux

    Shell, filesystem, permissions, processes, systemd, storage, Bash scripting.

  3. 03
    Networking

    IP and subnetting, TCP/UDP, DNS, routing and NAT, load balancing, Nginx, troubleshooting.

  4. 04
    Git

    Commits, branching, merging and rebasing, workflows, pull requests, recovery.

  5. 05
    CI/CD

    Build systems (Maven/Gradle), pipelines, GitHub Actions, Jenkins, GitLab CI, artifacts, deployment strategies.

  6. 06
    The Twelve-Factor App

    Write services platforms can run well: config, statelessness, graceful shutdown, trunk-based development, feature flags.

  7. 07
    Docker

    Images, Dockerfiles, volumes, networks, Compose, multi-stage builds, container internals.

  8. 08
    AWS

    IAM, EC2, VPC, load balancers, S3, RDS, containers, serverless, messaging, monitoring.

  9. 09
    Terraform

    Build ShopLite's AWS infrastructure as code: state, modules, environments, CI, testing.

  10. 10
  11. 11
    GitOps & Config Management

    Ansible, Argo CD, environments, secrets in Git, canary/blue-green with Argo Rollouts, multi-cluster.

  12. 12
    System Design

    The architecture view behind everything you run: scalability, databases, caching, messaging, microservices, distributed systems, and production architecture. Each topic links to where you build and operate it in these courses.

  13. 13
    Stateful Systems

    PostgreSQL, Kafka, RabbitMQ/SQS, Redis, Elasticsearch/OpenSearch, performance engineering.

  14. 14
    Secrets Management

    Secrets Manager vs Parameter Store, HashiCorp Vault, dynamic secrets, rotation, envelope encryption.

  15. 15
    Observability

    Metrics, logs, traces with Prometheus, Grafana, Loki, Tempo, OpenTelemetry; SLO alerting.

  16. 16
    DevSecOps

    Secrets, supply chain, container and IaC hardening, pipeline security, runtime detection.

  17. 17
    SRE

    Incident response, SLOs and error budgets, toil, capacity, cascading failures, game days.

  18. 18
    Incident Management & Reliability Metrics

    Severity, on-call, escalation, incident command, runbooks vs playbooks, RCA, MTTD/MTTR/MTBF.

  19. 19
    Production Architecture & DR

    How it all fits: edge, HA, multi-region, disaster recovery strategies.

  20. 20
    Cloud Cost Optimization

    FinOps, right-sizing, Savings Plans, Spot, storage and network costs, Kubernetes cost.

  21. 21
    Advanced AWS & Landing Zones

    Organizations, SCPs, Control Tower, Transit Gateway, PrivateLink, security services.

  22. 22
    Advanced Kubernetes Ecosystem

    CNI, CSI, service mesh, KEDA, Falco, cluster upgrades, and how the ecosystem fits.

  23. 23
    Infrastructure Testing & Policy as Code

    Terraform tests, Terratest, Helm/Kubernetes tests, OPA/Rego, Conftest, pipeline testing.

  24. 24
    Chaos Engineering

    Steady-state hypotheses, blast radius, Chaos Mesh, LitmusChaos, AWS FIS.

  25. 25
    Platform Engineering

    Build the internal developer platform: Gateway API, Karpenter, Kyverno, Backstage, Crossplane, DORA.

  26. 26
    The Tooling Landscape

    Alternatives for every job (OpenTofu, Pulumi, CDK, Tekton, Podman...) and the AWS ↔ Azure ↔ GCP map.

  27. 27
    Interviews & Career

    How DevOps interviews work, a troubleshooting framework, design rounds, portfolio, and growth.

Guides that connect the courses

G0Beginner

DevOps Fundamentals

Why DevOps exists, from waterfall to agile to continuous delivery; the CALMS framework and the Three Ways; the DevOps lifecycle; CI, CD, and CT; IaC and configuration management; feedback loops; the roles; and how success is measured.

G1Advanced

Production Architecture, High Availability, and Disaster Recovery

How a production request flows from DNS to database and back, designing for high availability (no single point of failure, multi-AZ), multi-region patterns, the four disaster recovery strategies, and how observability and on-call close the loop.

G2Advanced

Chaos Engineering

Breaking things on purpose, safely: steady-state hypotheses, blast radius and stop conditions, pod/network/CPU/memory/dependency/zone failure experiments with Chaos Mesh, LitmusChaos, and AWS Fault Injection Service.

G3Intermediate

Cloud Cost Optimization (FinOps)

Where cloud money actually goes, right-sizing, Savings Plans and Reserved Instances, Spot, storage lifecycle, the hidden costs of NAT gateways and data transfer, Kubernetes cost allocation, and budgets and anomaly alerts.

G4Advanced

Infrastructure Testing and Policy as Code

The testing pyramid for infrastructure: formatting and static analysis, Terraform native tests with mocks, Terratest integration tests, Helm and Kubernetes manifest tests, OPA/Rego and Conftest policies, and testing the pipelines themselves.

G5Advanced

Advanced AWS: Landing Zones, Network Hubs, and Security Services

Running AWS at company scale: Organizations, SCPs, Control Tower and landing zones, IAM Identity Center, Transit Gateway, PrivateLink and endpoints, WAF and Shield, and the detective services (CloudTrail, Config, GuardDuty, Security Hub, Inspector, Macie) wired together with EventBridge.

G6Advanced

The Advanced Kubernetes Ecosystem

A map of the add-ons production clusters run: CNI and eBPF networking, CSI storage, service mesh (mTLS, retries, traffic shifting), KEDA event-driven autoscaling, Falco runtime security, and safe cluster upgrades.

G7Intermediate

Incident Management and Reliability Metrics

The incident lifecycle from detection to postmortem: severity levels, on-call and escalation, incident command roles, runbooks vs playbooks, root cause analysis, corrective actions, and the metrics that measure it all (MTTD, MTTA, MTTR, MTBF, change failure rate).

G8Advanced

Secrets Management: Vault, Dynamic Secrets, and Rotation

Where secrets should live and how they reach workloads: AWS Secrets Manager vs Parameter Store, HashiCorp Vault (KV, dynamic database credentials, Kubernetes auth), injection patterns, automatic rotation, envelope encryption with KMS, and short-lived credentials everywhere.

G9Intermediate

The Twelve-Factor App and Cloud-Native Service Design

What makes an application easy to containerise, scale, and operate: the twelve factors mapped to Spring Boot and Kubernetes, graceful shutdown, health endpoints, trunk-based development, feature flags, and semantic versioning.

G10Intermediate

The Tooling Landscape: Alternatives and the Multi-Cloud Map

The courses teach one main tool per job. This guide maps the alternatives you'll meet in job descriptions (OpenTofu, Pulumi, CDK/CloudFormation, Terragrunt, Atlantis; Tekton, Argo Workflows, Spinnaker, Azure DevOps; Podman, Buildah, Kaniko) and translates AWS services to Azure and GCP.

G11Beginner

DevOps Interviews and Career: Turning Skills Into a Job

How DevOps/SRE/platform interviews are run, a framework for troubleshooting questions, infrastructure design rounds, live-debugging scenarios to practise, building a portfolio from the 12 projects, and growing from junior to senior.

Projects: build these progressively