home.social

#k8s — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #k8s, aggregated by home.social.

fetched live
  1. Как мы тестируем Kubernetes‑операторы в MWS Cloud Platform

    Сегодня Kubernetes стал де-факто стандартом для развёртывания SaaS-приложений и сервисов. Практически каждый разработчик работает с ним ежедневно, но большая часть этой работы связана с установкой уже готовых компонентов и манифестов. Если базового функционала начинает не хватать, возникает потребность в расширении. И вот тут начинается путешествие в уникальный мир k8s-операторов. Всё, начиная с архитектурных паттернов, заканчивая поддержкой и тестированием, сильно отличается от привычных подходов, поэтому перед разработчиком встаёт большой пласт материалов, требующих изучения. Об этом и поговорим. Меня зовут Антон Железнов, я разработчик в команде Managed Kubernetes

    habr.com/ru/companies/mws/arti

    #cloud #k8s #testing #mwscloudplatform #kubernetes

  2. Hello Fedi! My employer went through my #PostCovid time with me. Now that I'm back to work full time, they suddenly decided to let me go. 🤷‍♀️ I'm a #pentester with 5 years of experience in the field, before that 3 years of software dev in the #infosec field as well. Got a Bsc. in Computer Sience with emphasis on infosec and networke systems. In my #homelab I'm selfhosting on #proxmox and #k8s. I've been daily driving #linux for the past 20 years, first #gentoo, then #fedora. I'm pretty good with it, but no certs. I'm looking to continue in #offensivesecurity, but would be happy to pivot into infra/network or any other adventure given it's interessting or a good cause. Happy to invest in my skillset. Hybrid in north-eastern #Switzerland fully remote anywhere else.

    #getfedihired #fedihired

  3. Hello Fedi! My employer went through my #PostCovid time with me. Now that I'm back to work full time, they suddenly decided to let me go. 🤷‍♀️ I'm a #pentester with 5 years of experience in the field, before that 3 years of software dev in the #infosec field as well. Got a Bsc. in Computer Sience with emphasis on infosec and networke systems. In my #homelab I'm selfhosting on #proxmox and #k8s. I've been daily driving #linux for the past 20 years, first #gentoo, then #fedora. I'm pretty good with it, but no certs. I'm looking to continue in #offensivesecurity, but would be happy to pivot into infra/network or any other adventure given it's interessting or a good cause. Happy to invest in my skillset. Hybrid in north-eastern #Switzerland fully remote anywhere else.

    #getfedihired #fedihired

  4. Back in December last year, I suffered a massive incident on the home infra, which lead to all of the media’s of the Synapse server (decentralised one-place messaging service) to be lost

    Well, surprise surprise, the other day I found that my backup routine had done what it was supposed to

    Hourly cumulative backups, daily full backups, weekly backups retention for 3 months, and monthly backups retention for 1 year

    So I restored the latest before-outage backup, diffed both the production and restored volume, and transferred over the difference

    The immense sensation of relief realising everything worked as expected, and that all the memories with the SO are still there

    One more tale on how important backups are !

    #k8s #kubernetes #k3s #homelab #selfhosted #datarecovery #selfhosting #server #backups #longhorn #matrix #synapse

  5. Back in December last year, I suffered a massive incident on the home infra, which lead to all of the media’s of the Synapse server (decentralised one-place messaging service) to be lost

    Well, surprise surprise, the other day I found that my backup routine had done what it was supposed to

    Hourly cumulative backups, daily full backups, weekly backups retention for 3 months, and monthly backups retention for 1 year

    So I restored the latest before-outage backup, diffed both the production and restored volume, and transferred over the difference

    The immense sensation of relief realising everything worked as expected, and that all the memories with the SO are still there

    One more tale on how important backups are !

    #k8s #kubernetes #k3s #homelab #selfhosted #datarecovery #selfhosting #server #backups #longhorn #matrix #synapse

  6. Complete guide to Prometheus monitoring system: installation, configuration, PromQL queries, exporters, alerting, and integration with Grafana for comprehensive infrastructure observability.

    #DevOps #Linux #Docker #K8S #Kubernetes #Cloud #Self-Hosting #Monitoring #Prometheus #Open Source #Observability

    glukhov.org/observability/moni

  7. Complete guide to Prometheus monitoring system: installation, configuration, PromQL queries, exporters, alerting, and integration with Grafana for comprehensive infrastructure observability.

    -Hosting Source

    glukhov.org/observability/moni

  8. Automating Infrastructure-as-Code deployments with Kubernetes and GitOps. The key is infrastructure state management + declarative policies. CI/CD pipeline: lint → test → deploy to staging → promote to production. Essential tools: Kustomize, Helm, ArgoCD, and Flux. #Infrastructure #DevOps #DevSecOps #K8s #CI/CD #Automation #Infrastructure #DevOps #GitOps #Kubernetes #DevSecOps #Automation #Infrastructure #DevOps #Kubernetes #GitOps #DevSecOps #Automation

  9. Il CEO di #portainer ha pubblicato KubeSchool per spiegare al suo team i concetti di architettura e componenti in #kubernetes

    Dacci un occhio: kubeschool.portainer.io/

    #unolinux #linux #k8s

  10. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  11. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  12. Автотестирование кастомного K8s CNI: как правильно входить в ха… то есть поду

    Представьте, однажды вы приходите в новую компанию на позицию Automation QA и перед вами возникает задача: на пустом поле проекта посеять зерна автотестов, которые прорастут в регулярный процесс тестирования и будут отлавливать различные баги. Такая задача возникла и передо мной, поэтому я хочу поделиться своим опытом, как строил тестирование кастомного K8s CNI-плагина, в новой для себя области. Статья будет полезна QA-инженерам, которые на «ты» с Python, но на «вы» с тестированием Kubernetes с помощью автотестов. При решении задачи я столкнулся с вопросами, на которые нигде не нашел ответа. Возможно, раз мне помог описанный путь, поможет и вам. Войти в поду

    habr.com/ru/companies/cloud_ru

    #тестирование #automation_qa #cniплагин #k8s #kubernetes #multus #сетевая_связность #netcat #python

  13. Скрытый control plane в k8s

    Рассмотрим нестандартный вариант установки Kubernetes, а именно установка кластера без control-plane ноды как таковой в стандартном ее восприятии. Установим кластер Kubernetes где слой control-plane будет просто хостом без CRI, только базове systemd сервисы. "Спрячем" control-plane от лишних глаз.

    habr.com/ru/articles/1061228/

    #kubernetes #k8s #cilium #control_plane

  14. O curta sobre #kubernetes liberado agora pelo canal Codesource ficou bem legal. Em 15 minutos ele dá uma boa resumida na história.
    Se quiserem algo mais extenso, com entrevistas etc, tem o do CultRepo, em duas partes, que também é ótimo. #k8s
    youtu.be/sTLiqkMwJb4

  15. O curta sobre #kubernetes liberado agora pelo canal Codesource ficou bem legal. Em 15 minutos ele dá uma boa resumida na história.
    Se quiserem algo mais extenso, com entrevistas etc, tem o do CultRepo, em duas partes, que também é ótimo. #k8s
    youtu.be/sTLiqkMwJb4

  16. Esp-Monitor: архитектура и развертывание self-hosted IoT-платформы для микроконтроллеров ESP

    Одним из самых вдохновляющих моментов в разработке микроконтроллерных устройств является их первая установка и запуск в локальной сети. И этот же момент может превратиться в настоящий ад, когда процедуру приходится повторять десятки или сотни раз. Множество однотипных контроллеров, развертываемых одновременно, требуют часов монотонного конфигурирования — времени, которое любому инженеру хотелось бы провести с большей творческой пользой. Для решения этой проблемы был разработан легкий open-source сервис с открытым исходным кодом и условным названием «esp-monitor» .

    habr.com/ru/articles/1059516/

    #IoT #esp32 #esp8266 #esphome #go #golang #backend #ios #k8s #kubernetes

  17. RE: mastodon.social/@hynek/1169171

    Currently running docker swarm in a small team and hit enough rough edges that need to move container orchestration to something else (swarm also not really actively maintained) - nomad was on the list but fortunately avoided switching before hashi stuff went bad (below experiences help feel this was the right call)

    Thinking of making the jump to #microk8s or one of the other lightweight #k8s distros - any recommendations or war stories?

  18. RE: mastodon.social/@hynek/1169171

    Currently running docker swarm in a small team and hit enough rough edges that need to move container orchestration to something else (swarm also not really actively maintained) - nomad was on the list but fortunately avoided switching before hashi stuff went bad (below experiences help feel this was the right call)

    Thinking of making the jump to #microk8s or one of the other lightweight #k8s distros - any recommendations or war stories?

  19. Памятник kubelet, Kubernetes != CRI

    У обычной ноды Kubernetes жёсткий потолок в 110 подов (формально настраиваемый kubelet-флаг --max-pods , но поднимать его руками не рекомендуется даже апстримом: упирается в размер Pod CIDR на ноду, и выше 110 Kubernetes просто не валидируют, так что на практике это потолок дефакто), плюс налог на каждый контейнер: containerd или CRI-O (справедливости ради, у CRI-O ~20 МБ, но на хост, и около 1 МБ на под), ~20 МБ containerd-shim на каждый контейнер, а сам CRI добавляет заметный delay в операциях. На мощном железе это заставляет выбирать между недоутилизацией и гипервизорным слоем (KubeVirt, Kata) с его собственным налогом на microVM. На слабых VPS стандартный стек тяжёл ещё даже до первого workload: kubelet + containerd + kube-proxy + CNI — это уже 300-600+ МБ RSS прежде, чем в кластере появится хоть один рабочий под. У меня была мечта: Kubernetes + systemd. Я начал свой путь не зная куда это приведет, проект за время разработки сменил 7 разных направлений, думаю я нашел главную цель: освобождение Kubernetes. Результат на двух моих машинах (Xeon E5-2690 v4 + Intel N150): 1772 пода, 33 ноды, 2.5 миллиона запросов под нагрузкой с нулём ошибок и медианой 257 мкс . RSS демона — 365 МБ (замер от 04.04.26, сейчас уже ниже) на 1660 подов (~225 КБ на под). Дальше расскажу, что такое Periapsis, как у меня появилась эта идея и что уже работает.

    habr.com/ru/articles/1058526/

    #kubernetes #systemd #Periapsis #k8s

  20. Security Tip: Harden your containers with read-only filesystems. 🛡️ Most containers don't need to write to their root filesystem during runtime. By using the --read-only flag in Docker or K8s, you create a massive hurdle for attackers. If they exploit a service, they won't be able to download tools or modify system files. Stay updated on the latest vulnerabilities: cvedatabase.com

  21. [Перевод] Защита CI/CD для open source-проекта: запираем зависимости

    Команда VK Cloud перевела второй пост из серии трёх частей о том, как Cilium укрепляет свой CI/CD-конвейер. Первая часть рассказывала про управление доступом: кто может запускать сборки и какой CI-код разрешено исполнять. Этот пост про уровень зависимостей: какой код эти сборки подтягивают и как мы убеждаемся, что его не подделали.

    habr.com/ru/companies/vktech/a

    #vk_cloud #supply_chain #защита_зависимостей #open_source #управление_зависимостями #github_actions #renovate #sha_pinning #kubernetes #k8s

  22. einen #vintage #raspi1 heute mit #nerves zum leben erweckt. ich habe einen #k8s cluster in einer alten Postkiste und der kleine #raspi soll dort die Lüftersteuerung, powercycling der nodes, LED #blinkenlights und bisschen Datensammlung (Temp, Luftfeuchte, Lufttemperatur am Eingag der Lüfter und am Ausgang erfassen und für prometheus vorbereiten). Schöne Sache, um den ersten #Pi mit ein bisschen #elixir und #nerves neues Leben zu verpassen. gerade eben zum ersten mal via #ssh eingeloggt. NICE!

  23. Got the gateway + http route working.
    Lots of little pitfalls for me, like I have default deny policies but also stupid ones like typos 😅

    Yeah, probably AI could have been a speedup.

    BUT. I would not have learned much. And that's the point for me. How can I validate anything without having a real understanding? And that's where we're obviously heading to. Systems nobody can validate.

    #k8s #cilium #gateway #ai

  24. @flameeyes
    Thank you for sharing this insight.

    Please tell your instance admin, to fix their IPv6 as well. As federation for IPv6 is broken/not possible due to their #K8S setup.

    #IPv6

  25. #ngrok: we want to make visual and interactive content about #kubernetes We didn't want to create and maintain infrastructure for spinning up real clusters, so we decided to create a browser-based #simulator instead. The hope and dream is that this will make it possible for us (and you!) to create interactive Kubernetes content that lives for a long time, because the maintenance burden is much smaller.

    #k8s #webernetes #ts #typescript
    github.com/ngrok/webernetes

  26. Security Tip: Implement read-only root filesystems for your containers. 🛡️ Most applications don't need to write to the system root. By enforcing a read-only filesystem (e.g., --read-only in Docker or readOnlyRootFilesystem: true in Kubernetes), you limit an attacker's ability to achieve persistence. Use temporary volumes for specific write paths. Stay updated at cvedatabase.com

  27. Yesterday, I presented how to run MariaDB Server on Kubernetes using the MariaDB Operator during the DB Mastery Series about MariaDB & MySQL on Kubernetes. My slides are available at: speakerdeck.com/lefred/running 🦭 ☸️ #MariaDB #k8s