9 seasons, 72 episodes and 62 practice projects for practical Python, Linux, Git, cloud and AI work inside a fictional Code Nexus team. It starts with a working login and ends with AI agents in production. There's some Linux in between.
The first 15 episodes are free; Core programme and Certification prep include the rest.
Season 1
Your first days at Code Nexus: get your workstation working, read the evidence, and write your first Python.
The badge works. Let's see what else does.
Episode 1
Your Access Badge Works!
Computer fundamentals: hardware vs software, the operating system, peripherals.
Episode 2
Thirty-Seven Browser Tabs
CPU, RAM, and storage — what each one does and its units.
Episode 3
The Feed Has Disappeared
LAN vs WAN, IP addresses, DNS, ports, client and server.
Episode 4
The Suspicious Welcome Pack
Recognising phishing; multi-factor auth; keeping software updated.
Episode 5
Nobody Is Counting Likes by Hand
PCEP 1.1-1.5: syntax, indentation, literals, numeral systems, numeric and bitwise operators, operator precedence, type conversion, console input and output.
Episode 6
Should This Comment Be Flagged?
PCEP 2.1: if / elif / else, nested conditions, comparison operators, Boolean logic (and / or / not), and truthiness.
Episode 7
Ten Thousand Comments
PCEP 2.2 and 3.1: for and while loops, range, break / continue / pass, the loop-else clause, nested loops, and basic list traversal.
Episode 8
Messy Data, Real People
PCEP 3.1-3.4: lists, tuples, dictionaries, strings, slicing, membership, copying (aliasing), comprehensions, and nested collections.
2 practice projects
Season 2
Turn one-off scripts into reliable tools: functions, data, classes and the habits that make code team-ready.
Nobody expects the IndentationError.
Episode 1
Stop Copying That Function
PCEP 4.1-4.2: decomposition, positional and keyword arguments, return and None, default arguments, local vs global scope, and simple recursion.
Episode 2
The Program Crashed, Politely
PCEP 4.3-4.4 and PCAP 2.1-2.2: the exception hierarchy, matching except clauses, propagation, raise and assert, and defining a small custom exception.
Episode 3
Someone Already Built It
PCAP 1.1-1.5: import forms, qualified names, module search path, `__name__` / `if __name__ == '__main__'`, selected `math` / `random` / `platform` calls, and building your own package.
Episode 4
Emoji Are Not Always One Thing
PCAP 3.1-3.3: character encoding and Unicode, code points, `ord` / `chr`, string operations and comparison, and string methods.
Episode 5
Meet the Creator Object
PCAP 4.1-4.3 and 4.6: defining classes, instances vs the class, attributes and methods, `self`, `__init__`, instance state vs class state, and name mangling.
Episode 6
The Inheritance Plot Twist
PCAP 4.4-4.5: introspection (isinstance / issubclass / hasattr), inheritance, method overriding, polymorphism, `super()`, and choosing inheritance vs composition.
Episode 7
The Export That Ate Memory
PCAP 5.1-5.5: list/dict comprehensions, lambdas, map/filter, closures and late binding, generators and lazy evaluation, and text I/O concepts (modes, encoding, cleanup, errors).
Episode 8
The Vector and the Table
NumPy ndarray creation, vectorization, and array broadcasting.
Episode 9
Python Promotion Review
All PCAP domains, plus the programme bridges: HTTP status handling, JSON shape validation, and parameterised SQL. This is a consolidation and retrieval episode.
Certification checkpoint
Certified Entry-Level Python Programmer
PCEP-30-02
5 capstone projects
Read the PCEP guideCertification checkpoint
Certified Associate in Python Programming
PCAP-31-03
5 capstone projects
Read the PCAP guide10 practice projects
Season 3
Join the engineering team: Linux and the shell, Git and GitHub, and how work gets reviewed.
Your code has colleagues now.
Episode 1
Where Did the Desktop Go?
LPI 1.1, 1.3, 2.1-2.2, 4.1: Linux distributions and the shell, open-source licensing, command structure and options, quoting, environment variables, and reading man / --help.
Episode 2
Permission Denied, Again
LPI 2.3-2.4, 5.1-5.4: absolute and relative paths, hidden files, file operations, users and groups, permissions, ownership, and links.
Episode 3
The Logs Are Trying to Tell You
LPI 3.1-3.3, 4.3: text filters (grep, sort, cut, uniq), redirection and pipes, simple shell helpers, archives (tar/gzip), storage (df/du), and processes.
Episode 4
Please Stop Emailing Code
GH-900 basics and repositories: Git versus a hosting service, commits, branches, remotes, GitHub Flow, Markdown, and repository structure.
Episode 5
Your First Pull Request
GH-900 collaboration and projects: issues, pull requests, discussions, reviews, labels, milestones, project views, and resolving merge conflicts.
Episode 6
The Community Has Questions
GH-900 modern practices, security and community: hosted editors (Codespaces, dev containers, github.dev), repository visibility and roles, branch protection, a required status check, contribution files, and InnerSource vs open source.
Episode 7
The Integration Ticket
Engineering bridge: HTTP methods and status codes, request headers and bearer auth, keeping secrets out of URLs, retrying transient failures with a cap, SQL joins and the fan-out problem, GROUP BY and COUNT, and parsing JSON safely.
Episode 8
First Team Release
GitHub Foundations consolidation: the full issue -> branch -> review -> merge -> verify -> release flow, a release checklist and its residual risk, and rejecting a confident bad fix. Spirals Linux verification, Python, and the API/SQL bridge.
Certification checkpoint
GitHub Foundations
GH-900
5 capstone projects
Read the GitHub Foundations guide10 practice projects
Season 4
Capacity, cost and responsibility on Azure and AWS, and how to choose between them.
Scales to infinity and beyond. So does the invoice.
Episode 1
Why Not Just Buy Servers?
AZ-900 cloud concepts: the shared responsibility model, cloud service models (IaaS, PaaS, SaaS), deployment models (public, private, hybrid), consumption-based pricing, and the core benefits of cloud — elasticity, scalability, agility, and moving capital expense to operating expense.
Episode 2
A Home in Azure
AZ-900 Azure architecture and services: the resource hierarchy (subscription, resource group, resource), regions and availability zones, compute choices (VM, containers, serverless), object storage with redundancy (local, zone, geo) and access tiers (hot, cool, archive), private connectivity, and co-locating chatty resources.
Episode 3
Who Gave Them Access?
AZ-900 identity, access and security: identities vs roles vs scope, authentication vs authorisation, multi-factor authentication, role-based access control (RBAC), least privilege, Zero Trust, defence in depth, and using positive and negative access tests to prove a change.
Episode 4
The Bill Has a Plot Twist
AZ-900 management and governance: cost drivers, tags, budgets and budget alerts, the difference between Cost analysis, Advisor, Service Health and Monitor, governance through policy, and infrastructure as code (deployment templates).
Episode 5
Meet SignalNest
CLF-C02 cloud concepts and technology: the value of cloud (agility, not rewriting what works), comparing provider terminology without assuming equivalence, AWS global infrastructure (regions, availability zones, edge locations), migration as a deliberate decision, integration boundaries, and Well-Architected thinking.
Episode 6
The Other Cloud Console
CLF-C02 technology and services: AWS compute (EC2, Lambda, containers), object storage and storage classes (S3), databases (RDS relational, DynamoDB key-value), networking (VPC, DNS, CDN), load distribution, event-driven routes, and distinguishing managed services from learner-owned responsibilities.
Episode 7
An IAM Policy Walks into a Bucket
CLF-C02 security and compliance: the shared responsibility model for security, IAM policy evaluation (default deny, explicit allow, explicit deny wins), least-privilege policy scoping, root-account protection, encryption at rest and in transit, audit logs as evidence, and who owns which control.
Episode 8
Two Clouds, One Budget
CLF-C02 billing, pricing and support: purchase models (on-demand, savings plans / reserved, spot), budgets and cost tools, organisations and consolidated billing, support plan tiers, and reasoning about multi-cloud cost and resilience honestly.
Certification checkpoint
Microsoft Azure Fundamentals
AZ-900
5 capstone projects
Read the Azure Fundamentals guideCertification checkpoint
AWS Certified Cloud Practitioner
CLF-C02
5 capstone projects
Read the AWS Cloud Practitioner guide10 practice projects
Season 5
What AI can and cannot do: machine learning basics, responsible use, and making a case with evidence.
"Can we add AI?" is the start of the meeting, not the end.
Episode 1
Do We Need AI for That?
AI-901 / AIF concepts and machine-learning foundations: supervised vs unsupervised learning, features and labels, classification / regression / clustering, the model lifecycle, training and inference, train/test splits, and deciding when a model is the right tool versus rules.
Episode 2
The Model Audition
AI-901 model capabilities and implementation: reading a model card (context window, cost, regions, modalities), deployment as a state change, generation parameters like temperature, system vs user prompts, and writing a lightweight Python client against a model SDK.
Episode 3
The Anatomy of a Token
Subword Byte-Pair Encoding (BPE) and token vocabulary lookup.
Episode 4
The Caption Heard Around the Office
AI-901 language and speech implementation: speech-to-text (transcription) and its failure modes, language detection, translation, sentiment and entity analysis, confidence scores, and deciding when an automated caption is safe to publish versus needs a human.
Episode 5
Give the Feed Eyes
AI-901 vision and extraction implementation: image description and alt text, structured extraction from documents against a schema, handling a schema mismatch, grounding output in the source media, and recognising fabricated detail.
Episode 6
8-BIT Needs Boundaries
AI-901 single-agent implementation and responsible AI: constraining an agent with a system prompt and supplied knowledge, restricting its tools, evaluating safety / bias / refusal probes, scoping its access to least privilege, and configuring it to document uncertainty instead of fabricating an answer. Responsible-AI principles: fairness, reliability, privacy, inclusiveness, transparency, accountability.
Episode 7
SignalNest's Model Menu
AIF-C01 AI/ML fundamentals: predictive vs generative AI, the ML lifecycle, foundation models and generative AI (benefits and limits), and choosing among AWS AI options — pre-built AI services, managed foundation models (Bedrock), and custom model training/hosting (SageMaker) — for a specific need.
Episode 8
Prompt, Retrieve or Fine-Tune?
AIF-C01 generative AI in practice: prompting and context, retrieval-augmented generation (RAG), embeddings and vector search, model adaptation and fine-tuning, evaluation, and choosing the lightest approach that meets a knowledge or style requirement.
Episode 9
The Fairness Review
AIF-C01 responsible AI, governance and compliance: reading subgroup (fairness) evaluation results, classifying control gaps across fairness, privacy, security and evaluation, data minimisation and retention, model cards and audit evidence, and defending a launch / no-launch recommendation against competing constraints. A risk register as a lifecycle control.
Certification checkpoint
Microsoft Azure AI Fundamentals
AI-901
5 capstone projects
Read the Azure AI Fundamentals guideCertification checkpoint
AWS Certified AI Practitioner
AIF-C01
5 capstone projects
Read the AWS AI Practitioner guide10 practice projects
Season 6
Build a creator-support assistant with retrieval, tools, evaluation and the safety controls to defend it.
Confidence is not a source.
Episode 1
Code Nexus Assist Gets a Real Brief
AI-103 planning and generation: choosing services and regions against a brief, deployments and quotas, project connections, managed identity instead of shared keys, bounded retries, and turning requirements into measurable acceptance criteria.
Episode 2
The Assistant Invented a Refund
AI-103 retrieval and grounding: ingestion (published-only, latest-version, chunking, OCR and enrichment for scanned sources), embeddings, semantic, keyword and hybrid retrieval, chunk-size trade-offs, document-level access control, freshness, and proving an answer is grounded in permitted sources.
Episode 3
Creators Want Visual Superpowers
AI-103 vision and media: reading image and video analysis (text, objects, regions, scene, confidence), writing supported alt text and visual descriptions, video understanding as timed segments, masked edits limited to a region, image generation controls and policy, embedded-text injection, provenance labelling and human review.
Episode 4
Lost in Translation, Found in Tests
AI-103 text and speech: language detection, sentiment, entities, structured JSON output contracts, translation and tone, transcription confidence, speech translation and synthesis as separate stations, audio reasoning and its limits, explicit error handling, regression tests with known-answer fixtures.
Episode 5
Receipts, Screenshots and Voice Notes
AI-103 content extraction: analyzers for documents, images, audio and video, OCR and layout, structured and Markdown output, per-field confidence, evidence-linked records, indexing clean representations, reconciling contradictory readings, and routing uncertainty to review instead of inventing values.
Episode 6
Give the Assistant Tools
AI-103 agents: roles and goals, tool contracts (name, parameters, side effects, approval), function calling, separating user data and tool output from instructions, object-level authorisation inside tools, scoped and per-user memory, per-agent tool grants, supervised multi-agent hand-offs, and traces as evidence.
Episode 7
The Agent Did What?
AI-103 responsible AI, security and operationalisation: trust boundaries and indirect prompt injection, guardrails, scoped tools and per-agent grants, output checks, human approval for consequential actions, auditing through traces, and safety and quality evaluation with attack and benign regression sets and error analysis.
Episode 8
The AI Engineering Review
AI-103 across all domains: planning and quotas, retrieval and search health, vision, language and speech, extraction, agents and memory, and security — plus monitoring for quality, latency, cost and drift, held-out evaluation, prompt and configuration tuning, failure analysis, staged release, and recording model, index and prompt versions.
Certification checkpoint
Developing AI Apps and Agents on Azure
AI-103
5 capstone projects
Read the Azure AI Apps and Agents Developer guide5 practice projects
Season 7
Ship it: package the service in Docker, run it on Kubernetes, and keep it healthy under load.
Kabelo has heard this one before.
Episode 1
It Works on My Laptop
Docker practice: images and containers, layers and build cache, build context and .dockerignore, ordering a Dockerfile, pinning inputs, non-root execution, avoiding embedded secrets and checking local build reproducibility.
Episode 2
Where Did the Data Go?
Docker skills: container-local versus persistent storage, named volumes and mounts, restart versus replacement, user-defined networks and service discovery by name, why localhost inside a container is the container, publishing ports, environment configuration and secrets at run time, and proving restart behaviour with evidence.
Episode 3
The Secret in the Image
Docker security and supply chain: what image layers and history retain, secrets in files, ENV and ARG, non-root execution, scanning for vulnerabilities and secrets, tags versus digests, pinning a deployment to a digest, rotating a leaked credential, unpublishing an image, and verifying both the remediation and the service.
Episode 4
We Went Viral
Kubernetes fundamentals: what a cluster is made of (control plane and nodes, API server, etcd, scheduler, controllers, kubelet), declarative resources, Deployments, ReplicaSets and Pods, reconciliation, resource requests and limits, and how the scheduler places pods.
Episode 5
Three Pods Are Not Ready
Kubernetes workload health: readiness, liveness and startup probes and what each one does when it fails, reading Running versus Ready, restart counts and exit codes, container logs and pod events, environment configuration errors, labels and selectors, Services and endpoints, and diagnosing in layers without disabling health checks.
Episode 6
Service, Meet Network
Kubernetes networking and storage: Service selectors, DNS-style addresses, PersistentVolumeClaims and access modes; test the specific ingress rules in the fixture without claiming complete tenant or geographical isolation.
Episode 7
Deploy Without the Dramatic Music
Kubernetes application delivery: declarative rolling updates with maxSurge and maxUnavailable, reading rollout status and revision history, rollback with kubectl rollout undo, the difference between metrics, logs and events as observability signals, why a stuck rollout isn't fixed by scaling harder, and verifying user-facing health after recovery.
Episode 8
The Platform Readiness Review
Combined Docker and Kubernetes practice: audit a runbook, inspect build inputs and digests, rehearse deployment and compatible rollback, diagnose a fixture failure and record evidence and remaining production requirements.
Certification checkpoint
Kubernetes and Cloud Native Associate
KCNA
5 capstone projects
Read the Kubernetes (KCNA) guide5 practice projects
Season 8
Own delivery end to end: pipelines, review, rollout and a capstone you can show an employer.
The deploy button is not the ending.
Episode 1
Stop Deploying by Memory
Branch protection with a required review and a required status check that actually blocks an unready merge; reading the commit/PR audit trail to find who changed what and when; using it to diagnose and recover from an unreviewed regression; team-scale collaborator roles.
Episode 2
From Commit to Candidate
CI/CD stages and explicit dependencies; triggers; dependency-cache keys; artifact and commit traceability; inspect repeat-build evidence while accounting for mutable external inputs and environment differences.
Episode 3
The Environment Is Part of the Code
Infrastructure as code: parameterised templates, declared-versus-observed state, reviewed plans, scoped deployment identities and workload federation; distinguish fixture snapshot restore from a production rollback or backup strategy.
Episode 4
The Security Gate Says No
Security and compliance gates in a delivery pipeline: separating blocking risk from noise; scanning shipped dependencies against advisories at a chosen severity; checking where a dependency came from; scoped, short-lived pipeline credentials; independent approvals; rotating an exposed secret; and keeping scan evidence linked to a traceable artifact.
Episode 5
The Tests Passed. The AI Got Worse.
Separate unit, integration, security and AI-evaluation gates; AI-quality metrics with sample size and margin of error; conservative thresholds; holdout contamination; releasing gradually with a canary; rolling back to the last known-good release; and recording a release decision that says what the measurement can and can't support.
Episode 6
Creator Night: The Feed Is Failing
Incident response under pressure: ordering actions into stabilise, diagnose and follow up; scoping a failure from logs; recording hypotheses with evidence; mitigating with a verified rollback; reasoning about a latent defect and the missing guard that spread it; communicating accurately without overclaiming; and writing a blameless, checkable incident record.
Episode 7
Creator Night: The Bill and the Breach
Bounded incident evidence, least-privilege containment and approval checks; capacity controls distinct from budget alerts; distinguish attack traffic from a client fault; test retry and cost changes and record the security and cost findings.
Episode 8
You Are the Engineer
Owning an engineering recommendation end to end: clarifying a brief into constraints, gaps and assumptions; building and testing a safe core; securing and staging a release through the gates; diagnosing an unfamiliar fault; and defending a release decision language by language with evidence, a tested rollback and an operational handover.
Certification checkpoint
Designing and Implementing Microsoft DevOps Solutions
AZ-400
5 capstone projects
Read the Azure DevOps Expert guide5 practice projects
Season 9
Build, evaluate, and harden autonomous multi-agent systems: loop architectures, Model Context Protocol (MCP), and production guardrails.
The agents have a plan. Check it.
Episode 1
The Runaway Ticket
Autonomous agent architectures: the Perception-Reasoning-Action loop (perception of state, tool planning, invocation, observation injection, termination).
Episode 2
The Universal Connector
Model Context Protocol (MCP) architecture: host applications, protocol clients, and decoupled servers communicating over JSON-RPC 2.0.
Episode 3
The Swarm and the Supervisor
Multi-agent system architecture: Supervisor-Worker pattern, intent routing, and compound query decomposition.
Episode 4
The Judge and the Benchmark
Trajectory evaluation: tool-call precision, tool-call recall, argument accuracy, and excess-turn penalty scoring.
Episode 5
The Vault and the Thread
Recent-message buffers: slice a positive-size window, append evicted text and identify unbounded history growth and overflow cases.
Episode 6
The Autonomous Release
Worker topology: task routing and controlled catalog aggregation using fictional tool-server aliases, with host-side authorisation kept explicit.
5 practice projects