// Topics / Kubernetes

Kubernetes

    Kubernetes Requests and Limits: Lessons From an Outage CPU is compressible and memory is not. How to set Kubernetes requests and limits from real usage, when to skip CPU limits, and which guardrails to add. kubernetes infrastructure devops Service Mesh Decision Guide: You Probably Don't Need One Yet Service meshes pay off with dozens of services, many teams, and mTLS mandates. Most teams adopt one too early. Five questions to decide, plus alternatives. kubernetes architecture Kubernetes Security Hardening: Pods, RBAC, Network, Secrets Kubernetes defaults favor convenience over security. A layered hardening guide covering pods, RBAC, network policies, secrets, and the control plane. kubernetes security devops Kubernetes Cost Optimization: Right-Size Requests First Most clusters I review run at 20-40% utilization. How I help teams cut Kubernetes bills: honest requests, better bin packing, spot nodes, and ownership. kubernetes cost infrastructure API Gateway Patterns: Edge, BFF, and Service Mesh Ingress Edge gateways, BFFs, and mesh ingress: what belongs in an API gateway, what doesn't, and what I learned running them at my infrastructure startup and a large telecom. api microservices architecture GitOps and Canary Rollouts: No More Gambling on Deploys How we wired Argo CD and Argo Rollouts together at my infrastructure startup: canary steps, Prometheus analysis gates, repo layout, and what still goes wrong. ci-cd kubernetes Container Runtime Security: Seccomp, Network Policy, Falco Image scanning tells you what's in the box; runtime security tells you what it's doing. How we lock down containers with seccomp, network policy, Falco. containers security kubernetes API Gateway Build vs Buy: Kong, Envoy, or Custom Go I've built a custom Go gateway, run Kong in prod, evaluated Envoy, and used managed cloud gateways. What I recommend after doing each wrong at least once. api go kubernetes Kubernetes Operators in Go: Lessons From Six in Production Lessons from building production operators at a cloud infrastructure startup: the reconciliation loop, controller-runtime patterns, and the mistakes that cost us sleep. kubernetes go infrastructure Kubernetes Requests and Limits: How I Size Resources Most K8s clusters I audit are either wildly overprovisioned or one bad deploy away from eviction storms. Here's how I set requests, limits, and guardrails. kubernetes devops infrastructure Kubernetes Predictions for 2020: Day-Two Operations Win The adoption debate is over. 2020 is about operating Kubernetes well: managed control planes, GitOps by default, and policy enforcement. kubernetes trends cloud Zero-Downtime Deployments: Migrations, Probes, and Habits Zero-downtime deploys depend less on tooling than on expand-and-contract migrations, backward-compatible code, readiness probes, and graceful shutdown. ci-cd devops kubernetes Kubernetes Security Hardening: Fixing Insecure Defaults Kubernetes defaults optimize for fast adoption, not safety. A hardening checklist from running production clusters at three startups. kubernetes security infrastructure GitOps with Flux and Argo CD: Stop Deploying From a Laptop How to move a team off ad-hoc kubectl deploys to Git-driven Kubernetes with Flux and Argo CD: repo layout, secrets, rollbacks, and my mistakes. ci-cd devops kubernetes Kubernetes Production Checklist: The Boring Basics Most Kubernetes outages come from skipped basics: limits, probes, network policies, RBAC, upgrades, etcd restores. The checklist I run on every cluster. kubernetes devops infrastructure 2018 in Review: Spectre, GDPR, and a Humbled Tech Industry A personal look back at 2018: Spectre and Meltdown, the GDPR scramble, a startup accelerator, Kubernetes winning, and what to watch in 2019. year-in-review trends reflection Istio 1.0 in Practice: Powerful, Painful, Often Overkill Evaluating Istio 1.0 at a fintech startup: what it gives you, what it costs in overhead and complexity, and why most teams should think twice. kubernetes microservices infrastructure Container Security in 2018: PSP, Distroless, Image Signing Eight months after my first container security post: PodSecurityPolicy, distroless images, image signing, and Vault at a fintech startup. security containers kubernetes Kubernetes Operators: Powerful, but Overhyped Kubernetes operators are useful for Day 2 operations, but writing a good one is hard. When to adopt an existing operator, when to build your own. kubernetes devops infrastructure Two Years of Kubernetes in Production: The Boring Parts Year two of running Kubernetes in production: network policies, DNS, resource requests, PodDisruptionBudgets, upgrades, and RBAC. kubernetes containers devops Container Security Beyond the Basics: What We Hardened Containers share the host kernel, so they aren't a security boundary. How we hardened images, runtimes, network policies, and RBAC at a fintech startup. containers kubernetes security Service Mesh: You Probably Don't Need One I evaluated Istio and Linkerd for our microservices at the fintech startup. My conclusion: most teams are buying complexity they haven't earned yet. kubernetes microservices Kubernetes in Production: What Paid Off and What Bit Us Running Kubernetes in production: what paid off, what bit us (networking, secrets, YAML sprawl), and who should adopt it. kubernetes containers devops Container Orchestration: Docker Swarm vs Kubernetes vs Mesos Docker Swarm, Kubernetes, and Mesos compared side by side at a mobility startup in late 2016. Kubernetes will win, but its operational tax is real. containers kubernetes agents