AWS telegram emoji pack
https://news.1rj.ru/str/addemoji/qcloudy_aws
https://news.1rj.ru/str/addemoji/qcloudy_aws
Good guide for understanding kubernetes network policies https://medium.com/geekculture/a-beginners-guide-to-understanding-kubernetes-network-policies-bc8f55fb9c0
Medium
A Beginners Guide to Understanding Kubernetes: Network Policies
A high-level beginner-friendly overview of Network Policies in Kubernetes and why you should care about them.
A wireguard operator created to easily provision a VPN in a k8s cluster
https://github.com/jodevsa/wireguard-operator
https://github.com/jodevsa/wireguard-operator
GitHub
GitHub - devops-land/wireguard-operator: Project is now maintained by Namecheap on https://github.com/nccloud/wireguard-operator.…
Project is now maintained by Namecheap on https://github.com/nccloud/wireguard-operator. This repo is archived. - devops-land/wireguard-operator
Network mapping could help you with debug problems and understand real network interaction between your microservices. So this implementation with Grafana https://betterprogramming.pub/improve-cluster-monitoring-with-network-mapping-in-grafana-fa8bb479fd47
Medium
Improve Cluster Monitoring With Network Mapping in Grafana
A deep dive into obtaining network maps and correlating IP with cluster workloads to speed up debugging
Good article about Cgroups in Linux https://towardsdatascience.com/the-power-of-linux-cgroups-how-containers-take-control-of-their-resources-ba564fef13b0
All we know that "at least privileges model" one of the most important parts the security. But why people still struggle with it? https://sysdig.com/blog/identity-access-management-difficult-cloud/
Sysdig
Why Companies Still Struggle with Least Privilege in the Cloud | Sysdig
According to the Sysdig 2023 Cloud-Native Usage Report, misconfigurations are still the biggest player in security incidents and, therefore, should be one of the greatest causes for concern in organizations.
Guy share the company experience about building Infrastructure platform with k8s https://betterprogramming.pub/how-we-built-an-infrastructure-platform-on-top-of-kubernetes-a39e67d85680
Medium
How We Built an Infrastructure Platform on Top of Kubernetes
How and why we used kubernetes for our infrastructure platform and some lessons learned along the way
Linkedin engineering team's article about autoscaling builds https://engineering.linkedin.com/blog/2023/scaling-autobuild--our-journey-towards-delivering-an-enhanced-cu
Linkedin
Scaling AutoBuild: Our Journey Towards Delivering An Enhanced Customer Experience
Never forget about security in your cluster https://medium.com/@badawekoo/harden-kubernetes-cluster-with-pod-and-container-security-contexts-119639dbb6ce
Medium
Harden Kubernetes cluster with Pod and container security contexts
When it comes to security in Kubernetes, It is very vital to secure the individual resources of the cluster. Pods and containers are…
Continuous profiling for Python applications https://medium.com/@martin.heinz/boost-your-python-application-performance-using-continuous-profiling-7eb993e68d23
Medium
Boost Your Python Application Performance Using Continuous Profiling
Learn how to use Grafana Phlare and continuous profiling to discover bottlenecks in you code and boost the performance of your Python apps
Good article about scaning vulnerabilities
https://semaphoreci.com/blog/govulncheck
https://semaphoreci.com/blog/govulncheck
The article discusses how to use eBPF (extended Berkeley Packet Filter) to collect telemetry data from a service without code changes and without requesting engineering efforts. eBPF provides the ability to execute programs on the Operational System Kernel, extending the OS capabilities and leveraging the kernel's privileged ability to control the system. The author explains how to use Pixie, an open-source observability solution for Kubernetes applications that uses eBPF to collect telemetry data automatically. Pixie offers features such as network monitoring, database query profiling, continuous application profiling, and Kafka monitoring. However, Pixie has two drawbacks, long-term data retention, and a lack of support for ARM architectures. The article concludes by suggesting other tools that offer similar features to Pixie, such as Cilium Hubble.
https://itnext.io/observability-strategies-to-not-overload-engineering-teams-ebpf-b034b26d7f1d
https://itnext.io/observability-strategies-to-not-overload-engineering-teams-ebpf-b034b26d7f1d
Medium
Observability strategies to not overload engineering teams – eBPF
eBPF is a powerful technology since it allows you to inject custom user-definition programs in the kernel without having to install…
kubectl foreach is a command-line tool that enables running kubectl commands on one or more contexts (clusters) in parallel. Users can match context names from kubeconfig using patterns such as exact names and regular expressions. The tool offers options for limiting parallel executions, disabling confirmation prompts, and replacing values in kubectl arguments with context names. kubectl foreach can be installed using Krew kubectl plugin manager and used to query pods and run commands on multiple contexts at the same time. The tool is not intended for deploying workloads to clusters or using programmatically yet.
https://github.com/ahmetb/kubectl-foreach
https://github.com/ahmetb/kubectl-foreach
GitHub
GitHub - ahmetb/kubectl-foreach: Run kubectl commands in all/some contexts in parallel (similar to GNU xargs+parallel)
Run kubectl commands in all/some contexts in parallel (similar to GNU xargs+parallel) - ahmetb/kubectl-foreach
This article provides a deep dive into container file systems, specifically the use of OverlayFS in containers. It explains the need for container file systems to reduce data redundancy and save disk space, as well as how UnionFS mounts multiple directories together in one directory. The article also provides sample commands to illustrate how OverlayFS works and how Docker container uses it to divide container image files into multiple layers. Overall, this article is useful for those who want to understand the technical details of container file systems and how they work in containers.
https://medium.com/geekculture/k8s-container-file-system-ec26eda8b3ea
https://medium.com/geekculture/k8s-container-file-system-ec26eda8b3ea
Medium
K8s — Container File System
Container file system deep dive
The article explains how to enable communication between microservices in a Kubernetes cluster, using various methods. The author starts by deploying a simple setup that simulates two pods communicating with each other. They then explore different methods to achieve communication between these pods, including using pod IPs directly, creating and using services, and communicating between services across namespaces. The author also explains how to use environment variables and fully-qualified DNS names to address services. The article is a useful reference for anyone working with Kubernetes microservices. https://dev.to/narasimha1997/communication-between-microservices-in-a-kubernetes-cluster-1n41
DEV Community
Communication between Microservices in a Kubernetes cluster
Kubernetes is a popular, open source container orchestrator which takes care of creating, running and...
👌1
The article discusses the differences between Red Hat OpenShift and Kubernetes, two popular container orchestration management systems. While Kubernetes is an open-source container orchestration system developed by Google, OpenShift is a cloud-based Kubernetes container platform that offers consistent security, built-in monitoring, centralized policy management, and compatibility with Kubernetes container workloads. OpenShift contains all the native Kubernetes and Podman features and adds value through its own management functionality and DevOps tooling features. OpenShift offers stronger security features than native Kubernetes, but its stricter policies can make it harder to administer initially. While Kubernetes is more flexible, OpenShift is cheaper and offers enterprise-level support, making it more valuable to large organizations. The article provides details on deployment options, support, cost, releases and updates, networking, templates, image registry management, and integrated CI/CD for both systems.
https://itnext.io/openshift-vs-kubernetes-what-is-the-difference-cadee96497b7
https://itnext.io/openshift-vs-kubernetes-what-is-the-difference-cadee96497b7
Medium
OpenShift vs. Kubernetes: What is the Difference?
In this article, we will examine and point out some of the differences between 2 popular container orchestration management systems, Red…