AWS Certified Cloud Practitioner
Optional. Useful if you'll run Kubernetes on EKS/AKS/GKE and want to understand the underlying cloud layer.
Cloud native engineering is a distinct career track from cloud platform administration. This roadmap takes you through the full CNCF ecosystem: from Kubernetes basics (KCNA) to security (KCSA), platform engineering (CNPA), observability (OTCA), GitOps (CGOA), networking (Cilium), and policy (Kyverno) — plus the HashiCorp IaC and secrets management certs that complete a platform engineer's toolkit.
Build the vocabulary for containers and cloud before diving into Kubernetes operations.
Optional. Useful if you'll run Kubernetes on EKS/AKS/GKE and want to understand the underlying cloud layer.
Container fundamentals before Kubernetes. Image builds, networking, volumes, and multi-stage builds.
The mandatory Kubernetes foundation — concepts first, then security basics.
The entry-point to the CNCF certification path. Concept-level K8s — the most efficient way to pass the CKAD/CKA pre-work.
Security associate-level cert for K8s — RBAC, network policies, admission control, and supply chain security.
Platform engineers provision and manage infrastructure declaratively. These are the two most-used HashiCorp tools in Kubernetes shops.
The standard IaC tool for provisioning the cloud infrastructure that K8s clusters run on.
Secrets injection into Kubernetes pods is a recurring platform engineering problem. Vault is the reference solution.
Service discovery and service mesh coordination. Relevant if your platform uses Consul for networking.
GitOps has become the delivery standard for Kubernetes-based platforms.
The CNCF GitOps cert — Argo CD, Flux, and the GitOps operating model.
Argo CD is the most-deployed GitOps tool. CAPA goes deeper on Argo Workflows, Events, and Rollouts.
GitHub Actions is the entry point of most cloud native delivery pipelines before they hit Argo/Flux.
You can't operate what you can't see. Observability is the SRE half of platform engineering.
OTel is the vendor-neutral standard for distributed tracing, metrics, and logs. This is the cert for it.
Prometheus is the de-facto metrics system for Kubernetes. PCA validates the queries, alerts, and architecture.
Pick the specialist certs that match your platform's stack. Each of these is a distinct CNCF tool with its own cert.
Cilium has become the default CNI for Kubernetes at scale. CCA validates eBPF-based networking and network policy.
Kyverno is the leading Kubernetes policy engine. Policy-as-code for admission control and config validation.
The broadest cloud native platform engineering cert — integrates the tools from this entire roadmap.
Backstage is becoming the standard internal developer platform (IDP). CBA validates its architecture and extensibility.
Platform engineers increasingly own cluster cost. FinOps gives you the framework to manage it.
KCNA if you understand containers already. Docker Certified Associate if you're still fuzzy on images, registries, and runtimes.
Yes — even on managed K8s you configure RBAC, networking, ingress, GitOps, and observability. The CNCF certs are vendor-neutral by design.
No — Phase 6 is a menu. Pick the two or three certs that match your current platform stack (e.g. Cilium + Kyverno if your team uses both, or CNPA if you want a breadth cert).
A step-by-step path from cloud fundamentals to senior DevOps, covering AWS, Azure, GCP, Kubernetes, Terraform, and GitHub Actions.
Become a cloud solutions architect on AWS, Azure, or GCP — with the cross-cloud and platform skills that get you to senior.
Move from general IT security into senior cloud security on AWS, Azure, or GCP — backed by vendor-neutral foundations.