DevOps&SRE Library
19K subscribers
426 photos
2 videos
2 files
5.17K links
Библиотека статей по теме DevOps и SRE.

Реклама: @ostinostin
Контент: @mxssl

РКН: https://www.gosuslugi.ru/snet/67704b536aa9672b963777b3
Download Telegram
tapes

tapes is an Agentic telemetry system for content-addressable LLM interactions. It provides durable storage of agent sessions, plug-and-play OpenTelemetry instrumentation, and deterministic replay of past agent messages.


https://github.com/papercomputeco/tapes
How I think about Kubernetes

This article explains how to think about Kubernetes as a runtime for declarative infrastructure with a type system rather than just a container orchestrator.


https://garnaudov.com/writings/how-i-think-about-kubernetes
Harness engineering: leveraging Codex in an agent-first world

https://openai.com/index/harness-engineering
How We Shrunk a Kubernetes Sidecar from 421MB to 90MB (With No OS Inside)

This article explains how to reduce a Kubernetes sidecar container from 421MB to 90MB by building a statically linked Go binary and using a FROM scratch base image.


https://medium.com/@soumya-rout/how-we-shrunk-a-kubernetes-sidecar-from-421mb-to-90mb-with-no-os-inside-8757eaefc3ed
Wozz: Kubernetes Cost Tool

Wozz is a Kubernetes cost optimization tool that catches expensive resource changes before they merge.


https://github.com/WozzHQ/wozz
Before You Migrate: Five Surprising Ingress-NGINX Behaviors You Need to Know

As announced November 2025, Kubernetes will retire Ingress-NGINX in March 2026. Despite its widespread usage, Ingress-NGINX is full of surprising defaults and side effects that are probably present in your cluster today. This blog highlights these behaviors so that you can migrate away safely and make a conscious decision about which behaviors to keep. This post also compares Ingress-NGINX with Gateway API and shows you how to preserve Ingress-NGINX behavior in Gateway API. The recurring risk pattern in every section is the same: a seemingly correct translation can still cause outages if it does not consider Ingress-NGINX's quirks.

I'm going to assume that you, the reader, have some familiarity with Ingress-NGINX and the Ingress API. Most examples use httpbin as the backend.

Also, note that Ingress-NGINX and NGINX Ingress are two separate Ingress controllers. Ingress-NGINX is an Ingress controller maintained and governed by the Kubernetes community that is retiring March 2026. NGINX Ingress is an Ingress controller by F5. Both use NGINX as the dataplane, but are otherwise unrelated. From now on, this blog post only discusses Ingress-NGINX.


https://kubernetes.io/blog/2026/02/27/ingress-nginx-before-you-migrate
Spegel for p2p docker registries in k3s

https://ellie.wtf/notes/spegel
ing-switch: Migrate from Ingress NGINX to Traefik or Gateway API in Minutes, Not Days

Migrate Kubernetes Ingress NGINX to Traefik or Gateway API — CLI + web UI


https://blog.kubesimplify.com/ing-switch-migrate-from-ingress-nginx-to-traefik-or-gateway-api-in-minutes-not-days
1
siper

Siper is a high-performance, XDP-based IP blacklist firewall built with Go and C (eBPF). It allows you to drop malicious traffic at the earliest possible stage in the Linux networking stack—the network driver level. By leveraging XDP (Express Data Path), Siper processes packets before they even reach the kernel's heavy networking subsystem, providing extreme performance even under heavy DDoS conditions.


https://github.com/fksvs/siper
Upgrade AWS CSI Drivers in your Multi-Tenant Kubernetes Cluster

Since 2023, AWS CSI drivers can be misused to bypass node isolation in multi-tenant clusters.


https://soc-inspiration.medium.com/upgrade-aws-csi-drivers-in-your-multi-tenant-kubernetes-cluster-a2cbc47e47f8
CoreDNS in OpenShift

Understanding CoreDNS, Forwarders, ndots, and Name Resolution Flow


https://medium.com/@arjun0451/coredns-in-openshift-01f3142bde25
crd-bootstrap

Continuously reconcile CRDs in the cluster with template validation before apply.


https://github.com/Skarlso/crd-bootstrap
uncloud

A lightweight tool for deploying and managing containerised applications across a network of Docker hosts. Bridging the gap between Docker and Kubernetes


https://github.com/psviderski/uncloud
dockadvisor

Lightweight Dockerfile linter that helps you write better Dockerfiles. Get instant feedback with quality scores, security checks, and 60+ best practice rules.


https://github.com/deckrun/dockadvisor
kaniop

Kaniop is a Kubernetes operator for managing Kanidm.

Kanidm is a modern, secure identity management system that provides authentication and authorization services with support for POSIX accounts, OAuth2, and more.


https://github.com/pando85/kaniop
kured

Kured (KUbernetes REboot Daemon) is a Kubernetes daemonset that performs safe automatic node reboots when the need to do so is indicated by the package management system of the underlying OS.


https://github.com/kubereboot/kured