Forwarded from LearnKube news
🤝 What does it take to become part of the Kubernetes community?
After 12 in-depth interviews and months of research, we're releasing "Kubernetes World: Finding Your Path"—a book that explores the real journey into cloud native, beyond certifications and code contributions.
The book features conversations with:
- Bob Killen, Jorge Castro, and Taylor Dolezal on contributor experience
- Lin Sun and Kaslin Fields on navigating multiple paths
- Cortney Nickerson, Phil Estes, and Prasanth Baskar on building credibility
- Emily Long and Yasmin on networks and growth
- Whitney Lee on sustaining long-term involvement
What emerged from these conversations is a map of the invisible work, the mentorship moments, and the community values that actually matter when building a career in cloud native.
Special thanks to Heroku for sponsoring this project, to Yadin Porter de León for bringing these stories together, and to all our guests who shared their journeys.
Read it now: ku.bz/k8s-world
After 12 in-depth interviews and months of research, we're releasing "Kubernetes World: Finding Your Path"—a book that explores the real journey into cloud native, beyond certifications and code contributions.
The book features conversations with:
- Bob Killen, Jorge Castro, and Taylor Dolezal on contributor experience
- Lin Sun and Kaslin Fields on navigating multiple paths
- Cortney Nickerson, Phil Estes, and Prasanth Baskar on building credibility
- Emily Long and Yasmin on networks and growth
- Whitney Lee on sustaining long-term involvement
What emerged from these conversations is a map of the invisible work, the mentorship moments, and the community values that actually matter when building a career in cloud native.
Special thanks to Heroku for sponsoring this project, to Yadin Porter de León for bringing these stories together, and to all our guests who shared their journeys.
Read it now: ku.bz/k8s-world
Forwarded from Kube Events
We're giving away 10 tickets to DeveloperWeek.
The world's largest independent dev conference: 8 events in one: AI, Cloud Native, DevOps, Frontend, Security. 250+ speakers, workshops, and a hackathon.
📅 18-20 Feb
📍 San Jose, CA + Virtual
Get in touch at hello@kube.events to claim yours.
→ https://www.developerweek.com/
The world's largest independent dev conference: 8 events in one: AI, Cloud Native, DevOps, Frontend, Security. 250+ speakers, workshops, and a hackathon.
📅 18-20 Feb
📍 San Jose, CA + Virtual
Get in touch at hello@kube.events to claim yours.
→ https://www.developerweek.com/
Forwarded from LearnKube news
📕 We published a book on optimising and right-sizing GPUs in Kubernetes.
Most GPU clusters show 100% allocation and single-digit actual usage.
The book helps you:
- Tell whether your GPUs are actually computing or just allocated
- Pick the right metrics instead of trusting nvidia-smi
- Choose between time-slicing, MIG, and dedicated GPUs based on real data
- Stop GPU waste from cascading into CPU and memory waste
Download it for free here: ku.bz/KL4jRvsL4
This book was made possible by Kubex.
Most GPU clusters show 100% allocation and single-digit actual usage.
The book helps you:
- Tell whether your GPUs are actually computing or just allocated
- Pick the right metrics instead of trusting nvidia-smi
- Choose between time-slicing, MIG, and dedicated GPUs based on real data
- Stop GPU waste from cascading into CPU and memory waste
Download it for free here: ku.bz/KL4jRvsL4
This book was made possible by Kubex.
New report: Immutable OS for Kubernetes
We’ve published a new report on how teams manage Kubernetes node OSes in practice.
Based on 2,138 responses across 4 platforms, the report examines node updates, incident response, CVE patch windows, and OS customization. The results suggest that immutable-node operations are becoming more common, but the hard part is still operational: building reliable image pipelines, observability, and rollout processes around the base OS.
Read the full report:
https://kube.today/immutable-linux-kubernetes-2026
⭐️ This research was sponsored by Spectro Cloud. If you want to explore an immutable OS built for Kubernetes, check out Hadron OS:
https://ku.bz/P5Gj9c18t
We’ve published a new report on how teams manage Kubernetes node OSes in practice.
Based on 2,138 responses across 4 platforms, the report examines node updates, incident response, CVE patch windows, and OS customization. The results suggest that immutable-node operations are becoming more common, but the hard part is still operational: building reliable image pipelines, observability, and rollout processes around the base OS.
Read the full report:
https://kube.today/immutable-linux-kubernetes-2026
⭐️ This research was sponsored by Spectro Cloud. If you want to explore an immutable OS built for Kubernetes, check out Hadron OS:
https://ku.bz/P5Gj9c18t
Forwarded from LearnKube news
We published a new page for companies that want to work with LearnKube:
https://learnkube.com/for-marketers
Some LearnKube projects are too large to make alone.
The GPU ebooks we published recently are a good example:
https://learnkube.com/books
They are free because sponsors helped fund the research, writing, production, webinars, and distribution behind them.
We want to keep creating ambitious technical education for Kubernetes and platform engineering teams.
We already have ideas we’d like to develop around AI infrastructure, Kubernetes resource optimization, platform engineering, and general Kubernetes education.
If your company wants to support these efforts and reach Kubernetes practitioners with useful technical content, we’d like to talk:
https://learnkube.com/for-marketers
https://learnkube.com/for-marketers
Some LearnKube projects are too large to make alone.
The GPU ebooks we published recently are a good example:
https://learnkube.com/books
They are free because sponsors helped fund the research, writing, production, webinars, and distribution behind them.
We want to keep creating ambitious technical education for Kubernetes and platform engineering teams.
We already have ideas we’d like to develop around AI infrastructure, Kubernetes resource optimization, platform engineering, and general Kubernetes education.
If your company wants to support these efforts and reach Kubernetes practitioners with useful technical content, we’d like to talk:
https://learnkube.com/for-marketers
Forwarded from LearnKube news
We published a Kubernetes production-readiness checklist for teams preparing workloads for production.
The checklist is designed to help platform and application teams review the Kubernetes-specific behavior that affects an application before it goes live.
It includes:
- An interactive checklist
- Detailed explanations for each production-readiness check
- A downloadable PDF worksheet
It walks through five areas:
- The contract between your application and Kubernetes
- The manifests that define how Kubernetes should run it
- The workload security posture
- Scaling behavior under load
- Operational checks after launch
Open the checklist:
https://learnkube.com/production-best-practices
If you want a guided review, LearnKube also offers a Kubernetes Production Readiness Review with one of our instructors:
https://learnkube.com/production-readiness-review
The checklist is designed to help platform and application teams review the Kubernetes-specific behavior that affects an application before it goes live.
It includes:
- An interactive checklist
- Detailed explanations for each production-readiness check
- A downloadable PDF worksheet
It walks through five areas:
- The contract between your application and Kubernetes
- The manifests that define how Kubernetes should run it
- The workload security posture
- Scaling behavior under load
- Operational checks after launch
Open the checklist:
https://learnkube.com/production-best-practices
If you want a guided review, LearnKube also offers a Kubernetes Production Readiness Review with one of our instructors:
https://learnkube.com/production-readiness-review
Forwarded from LearnKube news
🚀 New on LearnKube: "Kubelet Metrics: How cAdvisor and CRI Collect Kubernetes Stats."
Kubernetes metrics often look like a Prometheus topic, but the data originates much lower in the stack.
This guide explains how kubelet collects and exposes pod, container, node, and resource metrics, and how that path changes when stats move from cAdvisor to the container runtime through CRI.
You will learn:
- how Linux cgroups provide the raw counters behind container metrics
- where cAdvisor fits inside kubelet
- what kubelet exposes through /metrics, /metrics/cadvisor, /metrics/resource, and /stats/summary
- how containerd and CRI-O can return pod and container stats through CRI
- why the same kubelet endpoint can hide a different internal collection path
Read the full article:
https://learnkube.com/kubernetes-metrics-cadvisor-kubelet-cri
Kubernetes metrics often look like a Prometheus topic, but the data originates much lower in the stack.
This guide explains how kubelet collects and exposes pod, container, node, and resource metrics, and how that path changes when stats move from cAdvisor to the container runtime through CRI.
You will learn:
- how Linux cgroups provide the raw counters behind container metrics
- where cAdvisor fits inside kubelet
- what kubelet exposes through /metrics, /metrics/cadvisor, /metrics/resource, and /stats/summary
- how containerd and CRI-O can return pod and container stats through CRI
- why the same kubelet endpoint can hide a different internal collection path
Read the full article:
https://learnkube.com/kubernetes-metrics-cadvisor-kubelet-cri
Forwarded from LearnKube news
🚀 New on LearnKube: “User and workload identities in Kubernetes.”
The Kubernetes API server must identify the caller before it can check permissions.
The article follows that identity through the request path: external users, in-cluster workloads, service account tokens, projected volumes, JWT claims, TokenReview, and AWS IAM federation.
You will learn:
- how authentication differs from authorization
- why human users usually come from OIDC, certificates, webhooks, proxies, or static token files
- how pods authenticate with service accounts
- why TokenRequest and projected volumes replaced automatic long-lived token secrets
- what
- how EKS IRSA uses projected tokens to federate with AWS IAM
- how TokenReview validates Kubernetes-issued tokens inside the cluster
Read the full article:
https://learnkube.com/authentication-kubernetes
The Kubernetes API server must identify the caller before it can check permissions.
The article follows that identity through the request path: external users, in-cluster workloads, service account tokens, projected volumes, JWT claims, TokenReview, and AWS IAM federation.
You will learn:
- how authentication differs from authorization
- why human users usually come from OIDC, certificates, webhooks, proxies, or static token files
- how pods authenticate with service accounts
- why TokenRequest and projected volumes replaced automatic long-lived token secrets
- what
sub, aud, iss, and exp tell you inside a JWT- how EKS IRSA uses projected tokens to federate with AWS IAM
- how TokenReview validates Kubernetes-issued tokens inside the cluster
Read the full article:
https://learnkube.com/authentication-kubernetes
Forwarded from LearnKube news
🚀 New on LearnKube: Microservice authentication with Kubernetes Service Accounts.
Service Accounts are usually described as identities used to call the Kubernetes API.
But you can also use them to authenticate requests between services inside the cluster.
The article walks through:
- how an API service can pass its Service Account token to a data store
- how the data store can validate the token with the TokenReview API
- why accepting any valid token is not enough
- how projected Service Account tokens let you bind a token to a specific audience
Thanks to Gulcan for putting together the full walkthrough with diagrams, manifests, Go snippets, TokenReview examples, and projected Service Account tokens.
Read the full guide:
https://learnkube.com/microservices-authentication-kubernetes
Service Accounts are usually described as identities used to call the Kubernetes API.
But you can also use them to authenticate requests between services inside the cluster.
The article walks through:
- how an API service can pass its Service Account token to a data store
- how the data store can validate the token with the TokenReview API
- why accepting any valid token is not enough
- how projected Service Account tokens let you bind a token to a specific audience
Thanks to Gulcan for putting together the full walkthrough with diagrams, manifests, Go snippets, TokenReview examples, and projected Service Account tokens.
Read the full guide:
https://learnkube.com/microservices-authentication-kubernetes
Forwarded from LearnKube news
New on LearnKube: Server-side apply: what happens when you run kubectl apply
Server-side apply changes how Kubernetes handles field ownership.
Kubernetes objects are shared state. Manifests, controllers, release tools, autoscalers, webhooks, and operators can all shape the same object.
With client-side apply, stale intent can overwrite live changes.
With server-side apply, ownership moves into the API server. Kubernetes tracks which manager owns each field and surfaces conflicts when ownership is contested.
Chiara put serious work into this guide, and you can read it in full here: https://learnkube.com/server-side-apply-kubernetes
Server-side apply changes how Kubernetes handles field ownership.
Kubernetes objects are shared state. Manifests, controllers, release tools, autoscalers, webhooks, and operators can all shape the same object.
With client-side apply, stale intent can overwrite live changes.
With server-side apply, ownership moves into the API server. Kubernetes tracks which manager owns each field and surfaces conflicts when ownership is contested.
Chiara put serious work into this guide, and you can read it in full here: https://learnkube.com/server-side-apply-kubernetes
Forwarded from KubeFM
Media is too big
VIEW IN TELEGRAM
Federico Iezzi, Customer Engineer at Google Cloud, explains how his team achieved 1 million output tokens per second using Qwen 3.5 27B, vLLM, GKE Autopilot, and NVIDIA B200 GPUs.
You will learn:
- Why memory bandwidth limits decode performance
- How Federico chose between tensor and data parallelism
- What changed after enabling multi-token prediction and reducing the KV cache footprint with FP8 quantization
Watch (or listen to) it here: https://ku.bz/1xD9Md0mb
🌟 This episode is brought to you by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
You will learn:
- Why memory bandwidth limits decode performance
- How Federico chose between tensor and data parallelism
- What changed after enabling multi-token prediction and reducing the KV cache footprint with FP8 quantization
Watch (or listen to) it here: https://ku.bz/1xD9Md0mb
🌟 This episode is brought to you by LearnKube. Download the free book, The Technical Guide to Kubernetes Rightsizing, to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
Forwarded from KubeFM
This media is not supported in your browser
VIEW IN TELEGRAM
The newest tool is not automatically the right architectural choice.
Before evaluating implementations, Fabián Sellés Rosa defined three criteria: flexibility, production maturity, and operational effort. This made it possible to compare Crossplane, a custom controller, and KRO with ACK on the same terms.
You will learn:
- Why KIAM became urgent to replace after years of stable operation
- How to define evaluation criteria before comparing tools
- Why Adevinta selected KRO with ACK for reconciliation
- How Kyverno preserves namespace-level IAM boundaries
Watch (or listen to) it here: https://ku.bz/R_06hwnCn
🌟 This episode is brought to you by LearnKube. Download The Technical Guide to Kubernetes Rightsizing to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb
Before evaluating implementations, Fabián Sellés Rosa defined three criteria: flexibility, production maturity, and operational effort. This made it possible to compare Crossplane, a custom controller, and KRO with ACK on the same terms.
You will learn:
- Why KIAM became urgent to replace after years of stable operation
- How to define evaluation criteria before comparing tools
- Why Adevinta selected KRO with ACK for reconciliation
- How Kyverno preserves namespace-level IAM boundaries
Watch (or listen to) it here: https://ku.bz/R_06hwnCn
🌟 This episode is brought to you by LearnKube. Download The Technical Guide to Kubernetes Rightsizing to understand what Prometheus and Grafana cannot tell you about safely reducing requests and limits: https://learnkube.com/kubernetes-rightsizing
With @Birthmarkb