Case Study: Reducing Complexity By Migrating from K8S to ECS Fargate for NetworkLessons
https://dev.to/aws-builders/case-study-reducing-complexity-by-migrating-from-k8s-to-ecs-fargate-for-networklessons-3271
The Kubernetes story is one I hear often. Teams adopt K8s expecting operational simplicity, only to discover they've traded application complexity for infrastructure complexity. For a solo founder focused on content creation, maintaining a Kubernetes cluster was simply the wrong trade-off.
https://dev.to/aws-builders/case-study-reducing-complexity-by-migrating-from-k8s-to-ecs-fargate-for-networklessons-3271
Database State Management in Kubernetes: Running SQL Server on AKS with GitOps
https://medium.com/@firaassboui/database-state-management-in-kubernetes-running-sql-server-on-aks-with-gitops-69286a87f8de
This article is about the patterns that actually work when you're managing real databases in Kubernetes, not hello-world demos: when your boss says "everything should be containerized" but your databases laugh in the face of ephemeral pods, and when GitOps meets a 200GB production database that absolutely cannot lose a single transaction.
https://medium.com/@firaassboui/database-state-management-in-kubernetes-running-sql-server-on-aks-with-gitops-69286a87f8de
Deploy LLM Models on OpenShift
https://medium.com/@ahmeddraz/deploy-llm-models-on-openshift-84ecb014f09a
Operators make life easier, but they are not always an option. In this post, I'll walk through a practical way to deploy large language models on OpenShift without relying on the OpenShift AI or NVIDIA operators. The approach uses llama.cpp as a lightweight runtime engine and runs a quantized GGUF model to enable efficient inference with minimal dependencies.
https://medium.com/@ahmeddraz/deploy-llm-models-on-openshift-84ecb014f09a
Enforcing Signed Container Images in Kubernetes Using Cosign & Kyverno (Helm-based Setup)
https://medium.com/@hansakabiyon99/enforcing-signed-container-images-in-kubernetes-using-cosign-kyverno-helm-based-setup-646209ecb8ce
This article explains how Cosign, Kyverno, and Harbor can work together to enforce image signature verification in Kubernetes. The approach is well-suited for enterprise environments with private registries, custom TLS certificates, and restricted access to public transparency logs.
https://medium.com/@hansakabiyon99/enforcing-signed-container-images-in-kubernetes-using-cosign-kyverno-helm-based-setup-646209ecb8ce
Modernizing Jenkins: From Static Agents to Kubernetes Dynamic Pods
https://blog.stackademic.com/modernizing-jenkins-from-static-agents-to-kubernetes-dynamic-pods-fbda3f897018
Jenkins might feel like legacy tech, but it's still powering CI/CD at thousands of companies. Instead of ripping it out, here's how to modernize it with Kubernetes — solving cost tracking, resource isolation, and scalability problems along the way.
https://blog.stackademic.com/modernizing-jenkins-from-static-agents-to-kubernetes-dynamic-pods-fbda3f897018
Building a Local Data Platform with Kubernetes and Terraform
https://blog.dataengineerthings.org/building-a-local-data-platform-with-kubernetes-and-terraform-9547a4256a7f
This blog aims to provide a practical example of how core tools like Kubernetes, Terraform, and DevContainers can be combined to build a local data platform in a structured and maintainable way.
https://blog.dataengineerthings.org/building-a-local-data-platform-with-kubernetes-and-terraform-9547a4256a7f
netfence
https://github.com/danthegoodman1/netfence
Netfence runs as a daemon on your VM/container hosts and automatically injects eBPF filter programs into cgroups and network interfaces, with a built-in DNS server that resolves allowed domains and populates the IP allowlist.
https://github.com/danthegoodman1/netfence
endpoint-monitoring-operator
https://github.com/iam404/endpoint-monitoring-operator
A lightweight, extensible Kubernetes Operator that probes any endpoint—HTTP/JSON, TCP, DNS, ICMP, Trino, OpenSearch, and more—and routes alerts to Slack or e-mail with a simple Custom Resource.
https://github.com/iam404/endpoint-monitoring-operator
argocd-diff-preview
https://github.com/dag-andersen/argocd-diff-preview
Argo CD Diff Preview is a tool that renders the diff between two branches in a Git repository. It is designed to render manifests generated by Argo CD, providing a clear and concise view of the changes between two branches. It operates similarly to Atlantis for Terraform, creating a plan that outlines the proposed changes.
https://github.com/dag-andersen/argocd-diff-preview
From Push to Production: Our Deployment Pipeline with Argo CD
https://medium.com/openmirai/from-push-to-production-our-deployment-pipeline-with-argo-cd-00e55b3feee9
So we built a pipeline that’s intentionally “boring”: GitHub pull requests, GitHub Actions, Kubernetes, and Argo CD — split across staging and production.
This post is a walkthrough of how a feature goes from a developer’s machine to real users, and why we made the choices we did.
https://medium.com/openmirai/from-push-to-production-our-deployment-pipeline-with-argo-cd-00e55b3feee9
From Minutes to Seconds: How I Eliminated Kubernetes Image Pull Delays
https://medium.com/@yyadid7/from-minutes-to-seconds-how-i-eliminated-kubernetes-image-pull-delays-16f166327576
How I reduced pod startup times from minutes to seconds with intelligent image preloading
https://medium.com/@yyadid7/from-minutes-to-seconds-how-i-eliminated-kubernetes-image-pull-delays-16f166327576
Nomad on OpenShift: The case for the control plane
https://hashicorpengineering.substack.com/p/nomad-on-openshift-the-control-plane
If Red Hat trusts OpenShift to run the control plane for their largest infrastructure orchestrator, the same pattern should apply to your smallest.
https://hashicorpengineering.substack.com/p/nomad-on-openshift-the-control-plane
Deep Dive: How linkerd-destination works in the Linkerd Service Mesh
https://medium.com/@bezarsnba/deep-dive-the-linkerd-destination-service-en-19f6efd1b308
Recently, in our daily operations, we took a deep dive into the inner workings of linkerd-destination, one of the most critical components of the Linkerd control plane.
https://medium.com/@bezarsnba/deep-dive-the-linkerd-destination-service-en-19f6efd1b308
28 июля(уже завтра!) в 19:00 по мск приходи онлайн на открытое собеседование, чтобы посмотреть на настоящее интервью на Middle DevOps-разработчика.
Как это будет:
Это бесплатно. Эфир проходит в рамках менторской программы от ШОРТКАТ для DevOps-разработчиков, которые хотят повысить свой грейд, ЗП и прокачать скиллы.
Переходи в нашего бота, чтобы получить ссылку на эфир → @shortcut_devops_bot
Реклама.
О рекламодателе.
Please open Telegram to view this post
VIEW IN TELEGRAM
Uniform API server access using clientcmd
https://kubernetes.io/blog/2026/01/19/clientcmd-apiserver-access
If you've ever wanted to develop a command line client for a Kubernetes API, especially if you've considered making your client usable as a kubectl plugin, you might have wondered how to make your client feel familiar to users of kubectl. In fact, the Kubernetes project provides two libraries to help you handle kubectl-style command line arguments in Go programs: clientcmd and cli-runtime (which uses clientcmd). This article will show how to use the former.
https://kubernetes.io/blog/2026/01/19/clientcmd-apiserver-access
CloudNativePG (CNPG) - install (2.18) and first test: simulate transient failure
https://dev.to/franckpachot/cloudnativepg-install-218-and-first-test-transient-failure-4ml
I'm starting a series of blog posts to explore CloudNativePG (CNPG), a Kubernetes operator for PostgreSQL that automates high availability in containerized environments.
https://dev.to/franckpachot/cloudnativepg-install-218-and-first-test-transient-failure-4ml
OpenKruise Agents
https://github.com/openkruise/agents
OpenKruise Agents provides best practices for managing AI agent workloads in Kubernetes. It is a sub-project of the open-source workload project OpenKruise under the Cloud Native Computing Foundation (CNCF), specifically tailored for the AI agent domain. OpenKruise Agents accelerates AI agent deployment and makes it easily accessible to both AI algorithm scientists and infrastructure engineers.
https://github.com/openkruise/agents
Optimizing Pod IP Allocation in AWS EKS with Amazon VPC CNI Prefix Delegation
https://medium.com/@mohamed.elmasary123/optimizing-pod-ip-allocation-in-aws-eks-with-amazon-vpc-cni-prefix-delegation-07d99004fdc2
In Amazon Web Services, each instance type has a different upper limit on how many Pods it can run. For example, an m5.large instance can only run 29 Pods, but an m5.4xlarge can run up to 234. The reason is that each EC2 instance can only have a limited number of IP addresses assigned to it.
https://medium.com/@mohamed.elmasary123/optimizing-pod-ip-allocation-in-aws-eks-with-amazon-vpc-cni-prefix-delegation-07d99004fdc2
GPU Starvation in Kubernetes: How Dynamic MIG Partitioning Saved Our GPU Budget
https://medium.com/@nscharan1/gpu-starvation-in-kubernetes-how-dynamic-mig-partitioning-saved-our-gpu-budget-d242d6e56581
In Kubernetes clusters, GPUs are expensive. Really expensive. And when your data science team is fighting over GPU resources like it’s Black Friday at Best Buy, you know something’s broken.
That was the challenge I faced a few years ago. I implemented this solution back then, and though it’s been a while, I thought now would be a great time to share the experience.
We had a k8s cluster with 8 NVIDIA A100 GPUs, and our data scientists were… unhappy. Small model training jobs waited hours for GPU access while large distributed training jobs hogged entire GPUs at 30% utilization.
The culprit? GPU allocation granularity. Kubernetes treats GPUs as atomic resources, you either get a whole GPU or nothing. There’s no middle ground.
I needed to fix this. And the solution wasn’t what I expected.
https://medium.com/@nscharan1/gpu-starvation-in-kubernetes-how-dynamic-mig-partitioning-saved-our-gpu-budget-d242d6e56581
Модуль ядра Linux — это точка входа в системную разработку
Здесь уже недостаточно знать команды ОС, важно понимать архитектуру ядра, сборку, загрузку и отладку на низком уровне.
🔔 3 августа в 20:00 МСК приглашаем вас на открытый урок, где мы разберём, зачем нужны модули ядра, как они встраиваются в работу операционной системы и какую роль играют в расширении её возможностей.
На занятии вы:
- узнаете, как создать собственный модуль, собрать его, запустить и отладить с помощью буфера сообщений ядра dmesg.
- получите практические инструкции, с которых можно начать разработку под ядро Linux.
Открытый урок проходит в преддверии старта курса «Разработка ядра Linux».
Зарегистрируйтесь, если хотите сделать первый уверенный шаг от обычной работы с Linux к системному программированию: https://vk.cc/d01rJq
Реклама. ООО «Отус онлайн-образование», ОГРН 1177746618576, erid: 2VtzqvY8GGz
Здесь уже недостаточно знать команды ОС, важно понимать архитектуру ядра, сборку, загрузку и отладку на низком уровне.
На занятии вы:
- узнаете, как создать собственный модуль, собрать его, запустить и отладить с помощью буфера сообщений ядра dmesg.
- получите практические инструкции, с которых можно начать разработку под ядро Linux.
Открытый урок проходит в преддверии старта курса «Разработка ядра Linux».
Зарегистрируйтесь, если хотите сделать первый уверенный шаг от обычной работы с Linux к системному программированию: https://vk.cc/d01rJq
Реклама. ООО «Отус онлайн-образование», ОГРН 1177746618576, erid: 2VtzqvY8GGz
Please open Telegram to view this post
VIEW IN TELEGRAM