DevOps drawer
@DevOps101
397
subscribers
9
photos
2
files
9.17K
links
Curated DevOps resources from trustworthy sources.
Download Telegram
Join
DevOps drawer
397 subscribers
DevOps drawer
https://www.keycloak.org
Keycloak
Keycloak - the open source identity and access management solution. Add single-sign-on and authentication to applications and secure services with minimum effort.
DevOps drawer
https://landscape.cncf.io/
CNCF Landscape
The CNCF Cloud Native Landscape is intended as a map through the previously uncharted terrain of Cloud Native technologies. It attempts to categorize projects and products in the Cloud Native space.
DevOps drawer
https://medium.com/swlh/bringing-prometheus-metrics-and-grafana-dashboard-for-cost-allocation-on-kubernetes-clusters-1ee7f68cd677
Medium
Bringing Prometheus Metrics and Grafana Dashboard for Cost Allocation on Kubernetes Clusters
Concepts, tools and practices
DevOps drawer
https://speakerdeck.com/thockin/kubernetes-what-is-reconciliation
Speaker Deck
Kubernetes: What is "reconciliation"?
A very brief exploration of what we mean when we talk about reconciliation in the context of Kubernetes APIs and controllers.
This is mostly animatio…
DevOps drawer
https://itnext.io/slashing-needed-permissions-in-istio-f05fe145698d
Medium
Reducing needed permissions in Istio
Istio is by default requiring more permissions to be able to run than what most users wanted to give their pods and containers (check out…
DevOps drawer
https://d2iq.com/blog/mesosphere-is-now-d2iq
D2Iq
Mesosphere is now D2iQ | D2iQ
Today is very exciting for the Mesosphere family. We are launching into the next phase of our growth strategy, which will take our employees,...
DevOps drawer
https://www.cncf.io/blog/2019/08/06/open-sourcing-the-kubernetes-security-audit/
CNCF
Open sourcing the Kubernetes security audit
Last year, the Cloud Native Computing Foundation (CNCF) began the process of performing and open sourcing third-party security audits for its projects in order to improve the overall security of our…
DevOps drawer
https://groups.google.com/forum/#!topic/kubernetes-security-announce/vUtEcSEY6SM
DevOps drawer
https://www.loodse.com/blog/2019-07-25-running-ha-kubernetes/
Kubermatic
Running HA Kubernetes clusters on AWS using KubeOne
Learn step-by-step how to deploy and run a vanilla cluster with machine-controller and metrics-server on AWS and other providers.
DevOps drawer
https://medium.com/flant-com/migrating-rabbitmq-to-kubernetes-without-downtime-3b02a97a9cdf
Medium
Migrating RabbitMQ to Kubernetes without downtime
General approach to the migration as well as practical steps to reproduce it.
DevOps drawer
https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/august/tools-and-methods-for-auditing-kubernetes-rbac-policies/
DevOps drawer
https://www.stackrox.com/post/2019/08/how-to-remediate-kubernetes-security-vulnerability-cve-2019-11247/
www.stackrox.io
How to Remediate Kubernetes Security Vulnerability: CVE-2019-11247 | StackRox Community
CVE-2019-11247 discloses a serious vulnerability in the K8s API that could allow users to read, modify or delete cluster-wide custom resources, even if they only have RBAC permissions for namespaced resources.
DevOps drawer
https://medium.com/kudos-engineering/increasing-resilience-in-kubernetes-b6ddc9fecf80
Medium
Increasing resilience in Kubernetes
High availability and resilience are key features of Kubernetes. But what do you do when your kubernetes cluster starts to become unstable…
DevOps drawer
https://www.stackrox.com/post/2019/08/istio-security-basics-running-microservices-on-zero-trust-networks/
Redhat
Istio Security: Running Microservices on Zero-Trust Networks
In this post, we’ll dive a little deeper into how Istio can help improve the runtime security of the applications in a service mesh and where it fits in the broader picture of Kubernetes security controls and practices.
DevOps drawer
https://sysdig.com/blog/kubernetes-autoscaler/
Sysdig
Kubernetes pod autoscaler using custom metrics
You can use any Sysdig metric as the pivot value for your Kubernetes autoscaler. This post will show you how to implement required API server extension.
DevOps drawer
https://www.mirantis.com/blog/make-your-container-images-safer-and-more-reliable-with-harbor-the-cloud-native-registry/
Mirantis
Make your container images safer and more reliable with Harbor, the cloud native registry| Mirantis
DevOps drawer
https://kubernetes.io/blog/2019/08/06/opa-gatekeeper-policy-and-governance-for-kubernetes/
Kubernetes
OPA Gatekeeper: Policy and Governance for Kubernetes
The Open Policy Agent Gatekeeper project can be leveraged to help enforce policies and strengthen governance in your Kubernetes environment. In this post, we will walk through the goals, history, and current state of the project.
The following recordings…
DevOps drawer
https://kubernetespodcast.com/episode/065-attacking-and-defending-kubernetes/
Kubernetespodcast
Kubernetes Podcast from Google: Episode 65 - Attacking and Defending Kubernetes, with Ian Coldwater
Ian Coldwater specializes in breaking and hardening Kubernetes, containers, and cloud native infrastructure. A pre-eminent public speaker in the Kubernetes security community, they are currently a Lead Platform Security Engineer at Heroku. Ian joins Adam…
DevOps drawer
https://techcrunch.com/2019/08/05/mesosphere-changes-name-to-d2iq-shifts-focus-to-kubernetes-cloud-native/
TechCrunch
Mesosphere changes name to D2IQ, shifts focus to Kubernetes, cloud native
Mesosphere was born as the commercial face of the open-source Mesos project. It was surely a clever solution to make virtual machines run much more efficiently, but times change and companies change. Today the company announced it was changing its name to…
DevOps drawer
https://containerjournal.com/2019/08/01/powering-edge-with-kubernetes-a-primer/
Container Journal
Powering Edge With Kubernetes: A Primer
Kubernetes increasingly is being adopted at the infrastructure edge to connect to the cloud for processing the data from IoT devices.