Lessons · new

Learn how it works

Lessons on how systems like Rasputin work: one idea per lesson, practiced on your own computer, with Rasputin as the worked example.

Each lesson teaches one idea you can use anywhere, and uses Rasputin as the real example. The labs run on your own computer. In some you build something in a folder you make for the lesson; in others you ask public systems a question and read the reply. A few lessons are for reading only and have no lab. None of them needs Rasputin hardware, Rasputin code or an account.

A lesson is written for one reader: beginner (new to the field), intermediate (knows the basics and wants the tradeoff) or advanced (a practitioner who wants how it is built).

This section is new. The lists below show only lessons that are published, and more are being written.

All lessons

The parts of a small distributed system One image, role chosen at boot How to read a decision record Runs on, tested on: reading a support claim Why every change goes through one path Converge or act once, derive or store A multi-step change with no undo How a name becomes an address Two names instead of one name with two answers How an authoritative nameserver answers, and where it breaks How a firewall decides Declaring firewall rules instead of editing them What an overlay network is Embedding a server or running it beside you Why a listed route still carries nothing Detecting traffic is not stopping it What a detection-only decision gives up Why a browser warns about a private certificate authority Why a vendor's signing CA and each installation's CA stay separate How machines send each other messages Choosing a transport for machines that come and go What an old reader does with a new field Building a reader that refuses one tile, not the catalog Why a passkey belongs to one name What passkey-only sign-in costs Why software has version numbers What a calendar version stops telling you What a signature proves that a checksum does not Why a second signing key needs its own purpose What a passing check proves Which checks can stop a merge How an update can fall back Rolling an update across a fleet How a machine proves an update worked What provisioning gives a new machine Why first boot stops instead of guessing What a heartbeat, a metric and a log line tell you How you know a backup works Why restore is never automatic A backup the service writes and cannot read

Track: Network engineer 18 lessons

18 lessons are published in this track so far, in reading order.

The parts of a small distributed system How to read a decision record How a name becomes an address How a firewall decides What an overlay network is Why a browser warns about a private certificate authority Detecting traffic is not stopping it What a heartbeat, a metric and a log line tell you One image, role chosen at boot Runs on, tested on: reading a support claim Converge or act once, derive or store Two names instead of one name with two answers Declaring firewall rules instead of editing them Embedding a server or running it beside you Why a vendor's signing CA and each installation's CA stay separate What a detection-only decision gives up How an authoritative nameserver answers, and where it breaks Why a listed route still carries nothing

Track: Software developer 17 lessons

17 lessons are published in this track so far, in reading order.

The parts of a small distributed system How to read a decision record Why every change goes through one path How machines send each other messages Why a passkey belongs to one name Why software has version numbers What a passing check proves One image, role chosen at boot Runs on, tested on: reading a support claim Converge or act once, derive or store Choosing a transport for machines that come and go What an old reader does with a new field What passkey-only sign-in costs What a calendar version stops telling you Which checks can stop a merge A multi-step change with no undo Building a reader that refuses one tile, not the catalog

Track: DevOps 15 lessons

15 lessons are published in this track so far, in reading order.

The parts of a small distributed system How to read a decision record Why software has version numbers What a passing check proves What a signature proves that a checksum does not How an update can fall back What provisioning gives a new machine One image, role chosen at boot Runs on, tested on: reading a support claim What a calendar version stops telling you Which checks can stop a merge Why a second signing key needs its own purpose Rolling an update across a fleet Why first boot stops instead of guessing How a machine proves an update worked

Track: Operations 16 lessons

16 lessons are published in this track so far, in reading order.

The parts of a small distributed system How to read a decision record What provisioning gives a new machine What a heartbeat, a metric and a log line tell you How an update can fall back How you know a backup works Why a browser warns about a private certificate authority One image, role chosen at boot Runs on, tested on: reading a support claim Converge or act once, derive or store Why first boot stops instead of guessing Rolling an update across a fleet Why restore is never automatic Why a vendor's signing CA and each installation's CA stay separate How a machine proves an update worked A backup the service writes and cannot read