Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 158:
🔥 From Linux Primitives to Kubernetes Security Contexts
🚀 Migrating OpenShift Stateful Workloads to Azure Kubernetes Service (AKS)
🧠 Tuning Linux Swap for Kubernetes: A Deep Dive
💻 Remote Development Environment Supercharged with MCP Servers
🔍 Tracing Strategies for LLMs Running on Google Cloud Run
Read it now: https://kube.today/issues/158
⭐️ This issue is brought to you by StormForge by CloudBolt and LearnKube. Join "Kubernetes Scheduling Deep Dive: Priority, Preemption, and Resource Requests" and learn how to protect critical workloads under resource pressure https://ku.bz/jTvQKH2sn
🔥 From Linux Primitives to Kubernetes Security Contexts
🚀 Migrating OpenShift Stateful Workloads to Azure Kubernetes Service (AKS)
🧠 Tuning Linux Swap for Kubernetes: A Deep Dive
💻 Remote Development Environment Supercharged with MCP Servers
🔍 Tracing Strategies for LLMs Running on Google Cloud Run
Read it now: https://kube.today/issues/158
⭐️ This issue is brought to you by StormForge by CloudBolt and LearnKube. Join "Kubernetes Scheduling Deep Dive: Priority, Preemption, and Resource Requests" and learn how to protect critical workloads under resource pressure https://ku.bz/jTvQKH2sn
Media is too big
VIEW IN TELEGRAM
Phillip Trickovic, GMSVP of Tintri, discusses whether Kubernetes is inherently complex or if complexity emerges based on implementation choices. He argues that complexity isn't inevitable - it depends on desired outcomes and the talent available to deliver solutions simply.
Phil acknowledges that Kubernetes can involve "many, many objects" and "many different ways to do things," making it more complicated than basic VM structures or traditional compiled applications.
Watch the full interview: https://ku.bz/pJP25dzCg
This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f
Phil acknowledges that Kubernetes can involve "many, many objects" and "many different ways to do things," making it more complicated than basic VM structures or traditional compiled applications.
Watch the full interview: https://ku.bz/pJP25dzCg
This interview is a reaction to Mac Chaffee's episode https://ku.bz/9nFPmG85f
KubeFM
Phillip Trickovic, GMSVP of Tintri, discusses whether Kubernetes is inherently complex or if complexity emerges based on implementation choices. He argues that complexity isn't inevitable - it depends on desired outcomes and the talent available to deliver…
This interview is brought to you by Tigera, the Creators of Project Calico — Learn how Calico uses eBPF for high performance, low latency, & enhanced networking. Check it out at https://ku.bz/Pl-g-KWk4
Media is too big
VIEW IN TELEGRAM
Brian Grant, CTO at ConfigHub, explains how Kubernetes resources are self-describing at rest. He discusses:
- The use of wire format for API resources in all serialization cases.
- How resources include all necessary information for API calls (API version, type, resource name, namespace).
Brian compares this to other APIs, highlighting how Kubernetes' approach reduces complexity. He also explains how this self-describing nature complements server-side apply, making updates more consistent and simpler for clients.
Watch the full episode: https://ku.bz/_ZLj6ZV-9
- The use of wire format for API resources in all serialization cases.
- How resources include all necessary information for API calls (API version, type, resource name, namespace).
Brian compares this to other APIs, highlighting how Kubernetes' approach reduces complexity. He also explains how this self-describing nature complements server-side apply, making updates more consistent and simpler for clients.
Watch the full episode: https://ku.bz/_ZLj6ZV-9
Media is too big
VIEW IN TELEGRAM
William Denniss, Group Product Manager, GKE Autopilot at Google Cloud, shares three emerging Kubernetes technologies he's tracking closely.
He discusses in-place pod upgrades, which allows updating pod resources after scheduling without restarts, creating more dynamic resource management when combined with VPA.
He also covers pod-level resource requests, a feature that simplifies resource allocation by specifying memory and CPU at the pod level rather than per container, reducing the complexity of right-sizing workloads.
Watch the full interview: https://ku.bz/VqnTC6-j1
He discusses in-place pod upgrades, which allows updating pod resources after scheduling without restarts, creating more dynamic resource management when combined with VPA.
He also covers pod-level resource requests, a feature that simplifies resource allocation by specifying memory and CPU at the pod level rather than per container, reducing the complexity of right-sizing workloads.
Watch the full interview: https://ku.bz/VqnTC6-j1
This media is not supported in your browser
VIEW IN TELEGRAM
Emin Laletović explains how to address memory issues when running Go applications in Kubernetes. He discusses:
- The mismatch between Go's garbage collector and container memory limits.
- Introduction of the
- The more aggressive and efficient memory management when approaching the limit.
This solution helped resolve out-of-memory errors without increasing container resources, demonstrating the importance of understanding language runtime behaviour in containerized environments.
Watch the full episode: https://ku.bz/7fnF-tJ8R
- The mismatch between Go's garbage collector and container memory limits.
- Introduction of the
GOMEMLIMIT environment variable in Go 1.19.- The more aggressive and efficient memory management when approaching the limit.
This solution helped resolve out-of-memory errors without increasing container resources, demonstrating the importance of understanding language runtime behaviour in containerized environments.
Watch the full episode: https://ku.bz/7fnF-tJ8R
Media is too big
VIEW IN TELEGRAM
Alex Chircop, Chief Architect @ Akamai, discusses three emerging Kubernetes tools he's tracking that address sophisticated workload challenges.
He explores KCP for scaling Kubernetes as a control plane to handle massive orchestration numbers, the ongoing challenges with OpenTelemetry for observability and, finally, and advanced access control systems beyond traditional CEL and OPA.
Watch the full interview: https://ku.bz/jHLJL8H6t
He explores KCP for scaling Kubernetes as a control plane to handle massive orchestration numbers, the ongoing challenges with OpenTelemetry for observability and, finally, and advanced access control systems beyond traditional CEL and OPA.
Watch the full interview: https://ku.bz/jHLJL8H6t
Media is too big
VIEW IN TELEGRAM
Wojciech Barczynski, VP of Engineering at Spacelift, discusses the evolution of building reliable platforms.
He emphasizes three foundational elements: engineering culture considering production readiness during development, cost of downtime evaluation, and geo-distribution requirements
The discussion explores how platform teams differ from DevOps teams by creating reusable primitives and establishing a central decision-making process for tooling while preserving team autonomy.
Watch the full interview: https://ku.bz/-2Sqn9Jb9
This interview is a reaction to Sven Hans Knecht's episode https://ku.bz/yk8pXYZ1X
He emphasizes three foundational elements: engineering culture considering production readiness during development, cost of downtime evaluation, and geo-distribution requirements
The discussion explores how platform teams differ from DevOps teams by creating reusable primitives and establishing a central decision-making process for tooling while preserving team autonomy.
Watch the full interview: https://ku.bz/-2Sqn9Jb9
This interview is a reaction to Sven Hans Knecht's episode https://ku.bz/yk8pXYZ1X
This media is not supported in your browser
VIEW IN TELEGRAM
Nick Nikitas Senior Platform Engineer at Blueground explains how they overcame cross-namespace PVC snapshotting limitations in Kubernetes.
The team implemented Velero as their backup solution, deploying it with Helm to store Kubernetes resources in AWS EBS.
The architecture leverages the AWS EBS CSI driver for volume management and integrates a snapshot controller to enable seamless restoration across namespaces.
Watch the full episode: https://ku.bz/tt4VFslxD
The team implemented Velero as their backup solution, deploying it with Helm to store Kubernetes resources in AWS EBS.
The architecture leverages the AWS EBS CSI driver for volume management and integrates a snapshot controller to enable seamless restoration across namespaces.
Watch the full episode: https://ku.bz/tt4VFslxD
Media is too big
VIEW IN TELEGRAM
Reid Vandewiele, Customer Success Architect at StormForge, shares his practical advice on implementing auto-scaling in Kubernetes environments.
Reid breaks down auto-scaling into three critical dimensions that teams should address simultaneously: cluster auto-scaling, horizontal pod auto-scaling, and vertical pod auto-scaling. He recommends specific tools for each dimension, highlighting Karpenter for cluster auto-scaling and noting that VPA, KEDA, and HPA have reached maturity for horizontal scaling, while vertical scaling remains more challenging.
Watch the full interview: https://ku.bz/nSlLGBy5l
This interview is a reaction to Thibault Jamet's episode https://ku.bz/rf1pbWXdN
Reid breaks down auto-scaling into three critical dimensions that teams should address simultaneously: cluster auto-scaling, horizontal pod auto-scaling, and vertical pod auto-scaling. He recommends specific tools for each dimension, highlighting Karpenter for cluster auto-scaling and noting that VPA, KEDA, and HPA have reached maturity for horizontal scaling, while vertical scaling remains more challenging.
Watch the full interview: https://ku.bz/nSlLGBy5l
This interview is a reaction to Thibault Jamet's episode https://ku.bz/rf1pbWXdN
This media is not supported in your browser
VIEW IN TELEGRAM
Ratan Tipirneni, President & CEO @ Tigera, announces Calico AI, a new AI-powered initiative designed to unlock the value of Tigera's existing Calico platform.
He explains how Calico serves as a unified platform for Kubernetes networking, network security, and observability, and describes their strategy to leverage AI as an umbrella term for innovation over the next couple of years
Watch the interview: https://ku.bz/fwFG0jZNk
Read the announcement: https://ku.bz/1nljhB1vQ
He explains how Calico serves as a unified platform for Kubernetes networking, network security, and observability, and describes their strategy to leverage AI as an umbrella term for innovation over the next couple of years
Watch the interview: https://ku.bz/fwFG0jZNk
Read the announcement: https://ku.bz/1nljhB1vQ
Media is too big
VIEW IN TELEGRAM
Amos walks through his production incident where adding a home computer as a Kubernetes node caused TLS certificate renewals to fail.
You will learn:
- How Kubernetes networking assumptions break when mixing cloud VMs with nodes behind consumer routers, and why cert-manager challenges fail in NAT environments
- The differences between CNI plugins like Flannel and Calico, particularly how they handle IPv6 translation
- Debugging techniques for network issues using tools like netshoot, K9s, and iproute2
- Best practices for mixed infrastructure including proper node labeling, taints, and scheduling controls
Watch (or listen to) it here: https://ku.bz/6Ll_7slr9
🌟 This episode is sponsored by LearnKube — get started on your Kubernetes journey through comprehensive online, in-person or remote training https://learnkube.com/training
With @Birthmarkb "50 off grid YT shorts" Farrell
You will learn:
- How Kubernetes networking assumptions break when mixing cloud VMs with nodes behind consumer routers, and why cert-manager challenges fail in NAT environments
- The differences between CNI plugins like Flannel and Calico, particularly how they handle IPv6 translation
- Debugging techniques for network issues using tools like netshoot, K9s, and iproute2
- Best practices for mixed infrastructure including proper node labeling, taints, and scheduling controls
Watch (or listen to) it here: https://ku.bz/6Ll_7slr9
🌟 This episode is sponsored by LearnKube — get started on your Kubernetes journey through comprehensive online, in-person or remote training https://learnkube.com/training
With @Birthmarkb "50 off grid YT shorts" Farrell
This media is not supported in your browser
VIEW IN TELEGRAM
Danielle Cook, Senior Product Marketing Manager @ Akamai, announces Akamai Inference Cloud, a new platform that combines their existing App Platform and LKE (Linode Kubernetes Engine) services.
She explains how their open source App Platform helps teams build Internal Developer Platforms (IDPs), and how this foundation now supports AI inference workloads.
Watch the interview: https://ku.bz/twmNqt6wX
Read the announcement: https://ku.bz/MPylRMg8K
She explains how their open source App Platform helps teams build Internal Developer Platforms (IDPs), and how this foundation now supports AI inference workloads.
Watch the interview: https://ku.bz/twmNqt6wX
Read the announcement: https://ku.bz/MPylRMg8K
Forwarded from LearnKube news
This week on Learn Kubernetes Weekly 159:
🔥 Kubernetes CPU Limits: Scylla and Charybdis
🧭 Kubernetes v1.34: Finer-Grained Control Over Container Restarts
🗂️ Understanding Kubernetes Cached Clients: How They Work and Why They Matter
💸 Understanding the True Cost of a Kubernetes Workload
🪙 Cloud Cost Optimization: A Senior Engineer’s Guide
Read it now: https://kube.today/issues/159
⭐️ This newsletter is brought to you by Heroku. Discover the thriving ecosystem of contributors, companies, and career paths in the Kubernetes World book https://ku.bz/bhlMdNf61
🔥 Kubernetes CPU Limits: Scylla and Charybdis
🧭 Kubernetes v1.34: Finer-Grained Control Over Container Restarts
🗂️ Understanding Kubernetes Cached Clients: How They Work and Why They Matter
💸 Understanding the True Cost of a Kubernetes Workload
🪙 Cloud Cost Optimization: A Senior Engineer’s Guide
Read it now: https://kube.today/issues/159
⭐️ This newsletter is brought to you by Heroku. Discover the thriving ecosystem of contributors, companies, and career paths in the Kubernetes World book https://ku.bz/bhlMdNf61
Media is too big
VIEW IN TELEGRAM
Gordon Myers explains why thorough testing is critical when implementing webhooks in Kubernetes.
He shares a real-world example of building a Mutating Webhook that injects secrets from HashiCorp Vault into running applications using pod annotations. The discussion covers:
- How a
- The implementation of a custom entry point script for injecting secrets as environment variables
- Why webhooks require extensive unit testing due to their cluster-wide impact
The example demonstrates how seemingly simple webhook implementations can have significant consequences for the entire Kubernetes cluster if not properly tested.
Watch the full episode: https://ku.bz/Dmn93dd7M
He shares a real-world example of building a Mutating Webhook that injects secrets from HashiCorp Vault into running applications using pod annotations. The discussion covers:
- How a
500 error in webhooks can prevent pods from launching entirely- The implementation of a custom entry point script for injecting secrets as environment variables
- Why webhooks require extensive unit testing due to their cluster-wide impact
The example demonstrates how seemingly simple webhook implementations can have significant consequences for the entire Kubernetes cluster if not properly tested.
Watch the full episode: https://ku.bz/Dmn93dd7M
KubeFM
Gordon Myers explains why thorough testing is critical when implementing webhooks in Kubernetes. He shares a real-world example of building a Mutating Webhook that injects secrets from HashiCorp Vault into running applications using pod annotations. The discussion…
This episode is sponsored by LearnKube - get started on your Kubernetes journey through comprehensive online, in-person or remote training https://learnkube.com/training
Media is too big
VIEW IN TELEGRAM
Dan Mattox, Senior Director of Engineering at Exostellar, explains why traditional GPU utilization metrics are no longer sufficient for optimization. He argues that GPU scarcity and cost are driving teams to adopt more comprehensive measurement approaches that go beyond simple utilization percentages.
Dan outlines a hierarchy of critical GPU metrics: allocation (ensuring GPUs are available), activity (confirming they're actively running workloads), utilization (proper resource usage), and crucially, queue times and workload lifecycle management.
Watch the full interview: https://ku.bz/5ymZxdYXq
This interview is a reaction to Dave Masselink's episode https://ku.bz/zk2xM1lfW
Dan outlines a hierarchy of critical GPU metrics: allocation (ensuring GPUs are available), activity (confirming they're actively running workloads), utilization (proper resource usage), and crucially, queue times and workload lifecycle management.
Watch the full interview: https://ku.bz/5ymZxdYXq
This interview is a reaction to Dave Masselink's episode https://ku.bz/zk2xM1lfW
Media is too big
VIEW IN TELEGRAM
Andy Suderman, CTO at Fairwinds, discusses the current state of AI adoption and draws parallels to the early days of Kubernetes. He explains how excessive hype leads companies to apply AI "for anything and everything" without considering practical fit, creating significant noise in the market.
Andy draws a compelling comparison to Kubernetes' early adoption phase, where operators initially tried to "run everything on Kubernetes" with mixed results. He notes that Kubernetes has now matured to the point where we understand the specific use cases where it makes sense.
The key difference with AI, according to Andy, is the accelerated timeline and broader scope. While Kubernetes remained infrastructure-focused, AI applications extend well beyond software development and infrastructure, causing the adoption cycle to move much faster.
Watch the full interview: https://ku.bz/ZQTRkMpz5
Andy draws a compelling comparison to Kubernetes' early adoption phase, where operators initially tried to "run everything on Kubernetes" with mixed results. He notes that Kubernetes has now matured to the point where we understand the specific use cases where it makes sense.
The key difference with AI, according to Andy, is the accelerated timeline and broader scope. While Kubernetes remained infrastructure-focused, AI applications extend well beyond software development and infrastructure, causing the adoption cycle to move much faster.
Watch the full interview: https://ku.bz/ZQTRkMpz5
KubeFM
Andy Suderman, CTO at Fairwinds, discusses the current state of AI adoption and draws parallels to the early days of Kubernetes. He explains how excessive hype leads companies to apply AI "for anything and everything" without considering practical fit, creating…
This interview is brought to you with support from Fairwinds — expert-led, fully managed Kubernetes that frees your engineers from infrastructure headaches and puts you on the fast track to production-grade success https://ku.bz/0-rnZ5Sjs
Media is too big
VIEW IN TELEGRAM
Andrew Hillier, Co-Founder & CTO at Densify, discusses the hottest topics driving community engagement around Kubernetes resource optimization. He explains why resource optimization has become the top trending topic, with organizations increasingly aware of how expensive misconfigured Kubernetes can be.
Andrew contrasts Kubernetes optimization with traditional cloud optimization, noting that Kubernetes is much more streamlined because it's essentially about requests and limits - settings teams aren't emotionally attached to once they understand the reasoning.
Watch the full interview: https://ku.bz/YMHdrgqz4
Andrew contrasts Kubernetes optimization with traditional cloud optimization, noting that Kubernetes is much more streamlined because it's essentially about requests and limits - settings teams aren't emotionally attached to once they understand the reasoning.
Watch the full interview: https://ku.bz/YMHdrgqz4
KubeFM
Andrew Hillier, Co-Founder & CTO at Densify, discusses the hottest topics driving community engagement around Kubernetes resource optimization. He explains why resource optimization has become the top trending topic, with organizations increasingly aware of…
This interview is brought to you with support from Kubex by Densify - automated Kubernetes optimization that cuts costs and improves performance https://ku.bz/8H62chDf9