BuddingUpdated

Platform Engineer Roadmap: a step-by-step learning path

Free platform engineer roadmap in 8 stages: containers, Kubernetes, Terraform, GitOps, observability, security and Backstage, with docs and a project per step.

This platform engineer roadmap takes you from the basics to building an internal developer platform, one stage at a time. Every stage links to official documentation or a free tutorial, and ends with something small to build, so you finish with working projects and not only notes.

A platform engineer builds the things every team would otherwise build for itself: a way to create a service, a pipeline, somewhere to run it, monitoring and secrets. The team builds it once, as a product, for the developers who use it. That product is the internal developer platform, and the best result is a golden path: pick a template and get a repository, a pipeline, a deployed service and dashboards, without opening a ticket.

The CNCF's Platforms white paper puts it as platforms that curate and present foundational capabilities to internal customers such as application developers, and describes platform engineering as inspired by the cross-functional cooperation DevOps promised.

The test of a good platform is simple: developers choose to use it. If they still need a ticket, it isn't a platform yet.

The platform engineer roadmap at a glance

  1. Foundations: Linux, networking, Git, scripting
  2. Containers: Docker and images
  3. Kubernetes: run and understand a cluster
  4. Infrastructure as code: Terraform or OpenTofu, Crossplane
  5. CI/CD and GitOps: pipelines, Argo CD or Flux
  6. Observability and reliability: metrics, logs, traces, SLOs
  7. Security and policy: supply chain, policy as code
  8. The platform itself: templates, a portal, product thinking

What does a platform engineer do?

  • Builds and runs the shared tooling developers use to ship: templates, pipelines, environments and the portal that ties them together.
  • Treats developers as customers: asks what slows them down, builds the smallest thing that fixes it, and checks whether it gets used.
  • Sets safe defaults, so security, monitoring and cost controls come built in instead of being added later.
  • Works with SRE and security teams, and keeps the platform reliable and upgradable.

DevOps is a way of working. SRE keeps production reliable, with SLOs and error budgets. Platform engineering builds the tools that make both easier. The longer comparison is in Platform engineering vs DevOps vs SRE.

Start here: eight stages

Work through the stages in order, and build the small thing at the end of each one before moving on.

1. Foundations

Linux, networking, Git and a scripting language. You can't build a platform on things you can't debug.

Build: write a shell script that checks a service is healthy and exits non-zero when it isn't.

2. Containers

Build, run and shrink images, then run several together.

Build: containerise one app with a multi-stage Dockerfile.

3. Kubernetes

Pods, Deployments, Services, Ingress or Gateway API, storage and RBAC. Then run a cluster yourself so you know what is underneath.

Build: deploy the container from stage 2 with a Deployment, a Service and an Ingress or Gateway.

4. Infrastructure as code

Everything the platform runs on should come from code you can review.

Build: create a network and a small cluster from code, then destroy it.

5. CI/CD and GitOps

A change in Git becomes a running change, and the cluster is made to match Git.

Build: a pipeline that builds the image, and an Argo CD or Flux application that deploys it from a Git repository.

6. Observability and reliability

Dashboards and alerts come with every service on the golden path.

Build: add metrics and a dashboard to the app, and one alert on an SLO.

7. Security and policy

Make the secure way the default, so developers don't have to remember it.

Build: add a policy that rejects pods running as root, and sign the image your pipeline builds.

8. The platform itself

Now put it together as a product: templates, a portal, and defaults that make the right thing the easy thing.

Build: a Backstage template that creates a repository with a pipeline, a Deployment and a dashboard in one step. That is your golden path.

How to become a platform engineer

  1. Pick a real target. Choose one kind of service, for example a small web API, and make it the thing your platform serves.
  2. Build the path end to end. Containerise it, run it on Kubernetes, create the infrastructure with Terraform, deploy it with GitOps, add monitoring and a policy check.
  3. Turn it into a template. Anyone should be able to get a working copy in one step. This is the project to show in a portfolio or an interview.
  4. Get a user. Ask a colleague or friend to use it and watch where they get stuck. Fix that first.
  5. Write it down. Short docs and a diagram of how it fits together show the product thinking this role needs.

Books, talks and communities

Certifications

The Linux Foundation offers the Certified Cloud Native Platform Engineering Associate (CNPA). The Kubernetes certifications (CKA, CKAD, CKS) are a good way to prove stage 3.

Platform engineer roadmap: common questions

Do I need to know Kubernetes to be a platform engineer?

Many platforms are built on Kubernetes, so it is worth learning well, but the role is not only Kubernetes. The skills that carry over are the ones in stages 4 to 8: infrastructure as code, delivery, observability, security and thinking of developers as users.

Do I need to be a developer?

You need to read and write code, mostly scripts, templates and small services. You do not need to be a full-time application developer, but you do need to understand how developers work and what slows them down.

What is the difference between platform engineering and DevOps?

DevOps is a way of working. Platform engineering builds the shared tools that make that way of working easy for everyone else. See Platform engineering vs DevOps vs SRE.

What is an internal developer platform?

The self-service layer a platform team offers, so developers can create, deploy and run services without filing tickets. See Internal developer platform.

Is Backstage the same as a platform?

No. Backstage is a developer portal framework. It can be the front door of a platform, but the platform is the templates, delivery, infrastructure and defaults behind it.

Where should I start if I already work in DevOps or as a sysadmin?

Start at stage 4 or 5 to fill gaps, then go straight to stage 8: build one golden path and get a real user for it. The product and user side is usually the new skill.

A last tip

Treat developers as your customers. Ask what slows them down, build the smallest thing that fixes it, and check whether they use it.

Notes in Platform Engineering