kubeapps
A web-based UI for deploying and managing applications in Kubernetes clustershttps://github.com/vmware-tanzu/kubeapps
Why You Should Avoid Sealed Secrets in Your GitOps Deployment
The pitfalls and alternatives of this common GitOps practice as you move your deployments to production.https://betterprogramming.pub/why-you-should-avoid-sealed-secrets-in-your-gitops-deployment-e50131d360dd
argocd-vault-plugin
An Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secretshttps://github.com/argoproj-labs/argocd-vault-plugin
Observations and thoughts after building 3 kubernetes platforms in Financial Services Industry
Part 1 - Overview, K8s PaaS offerings, Networking: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-6705511c8e9b
Part 2 - Workload Identity, Secret Management / Externalization: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-158eba494528
Part 3 - GitOps: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-7d6c60206717
Part 4 - Policy Enforcement: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-e8bb24e381a2
Part 5 - Cloud Resource Brokering: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-b6404baf9ce3
Part 1 - Overview, K8s PaaS offerings, Networking: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-6705511c8e9b
Part 2 - Workload Identity, Secret Management / Externalization: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-158eba494528
Part 3 - GitOps: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-7d6c60206717
Part 4 - Policy Enforcement: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-e8bb24e381a2
Part 5 - Cloud Resource Brokering: https://itnext.io/observations-and-thoughts-after-building-3-kubernetes-platforms-in-financial-services-industry-b6404baf9ce3
Beginners Guide to Argo CD
Learn, Implement and Share about Argo CD after this 15 minutes read.https://blog.tanmaysarkar.tech/beginners-guide-to-argo-cd
The importance of limits for containerised JVM applications
https://blog.viascom.dev/the-importance-of-limits-for-containerised-jvm-applications-94c51e730059
https://blog.viascom.dev/the-importance-of-limits-for-containerised-jvm-applications-94c51e730059
mountpoint-s3
A simple, high-throughput file client for mounting an Amazon S3 bucket as a local file system.https://github.com/awslabs/mountpoint-s3
How Docker BuildKit and GitLab Runner fill up storage in Kubernetes
https://medium.com/geekculture/how-docker-buildkit-and-gitlab-runner-fill-up-storage-in-kubernetes-fix-it-a839c841bf95
https://medium.com/geekculture/how-docker-buildkit-and-gitlab-runner-fill-up-storage-in-kubernetes-fix-it-a839c841bf95
qdrant
Qdrant - Vector Search Engine and Database for the next generation of AI applications.https://github.com/qdrant/qdrant
Cilium CNI on EKS using secondary CIDR and prefix delegation
https://medium.com/@benoit.mouquet/cilium-cni-on-eks-using-secondary-cidr-and-prefix-delegation-55e57ffd2537
https://medium.com/@benoit.mouquet/cilium-cni-on-eks-using-secondary-cidr-and-prefix-delegation-55e57ffd2537
Watch: 5 tips for improving Grafana Loki query performance
https://grafana.com/blog/2023/01/10/watch-5-tips-for-improving-grafana-loki-query-performance
https://grafana.com/blog/2023/01/10/watch-5-tips-for-improving-grafana-loki-query-performance
woodpecker
Woodpecker is a community fork of the Drone CI system.https://github.com/woodpecker-ci/woodpecker
Bastion hosts vs. VPNs
Bastion hosts can be a valuable resource for companies, improving security and limiting access to shared resources. However, it may not be necessary to use a bastion host when resources can be accessed directly from your network. This article will explore what bastion hosts are, what they’re used for, their limitations, and how they compare to VPNs such as Tailscale.https://tailscale.com/learn/bastion-hosts-vs-vpns
meshery
Meshery is the cloud native management plane offering lifecycle, configuration, and performance management of Kubernetes, service meshes, and your workloads.https://github.com/meshery/meshery
Terraform Security Best Practices
In this article we want to explain the benefits of using Terraform, and provide guidance for using Terraform in a secure way by reference to some security best practices.https://sysdig.com/blog/terraform-security-best-practices