Tag: #kubernetes
Writing on GPUs, LLMs, MLOps, Kubernetes — and mindset · 247 posts
Cilium Datapath Architecture — Inside a Cluster Without kube-proxy
A deep dive into the eBPF datapath of Cilium, the CNCF graduated CNI, following a packet on its journey. We cover how kube-proxy replacement works, the identity-based security model, tunneling versus native routing, and
2026-06-13 · 16 min read #cilium#ebpf#kubernetes#cni#networkingCilium Network Policy in Practice — Zero Trust from L3 to L7 and DNS
A hands-on guide to going beyond the limits of Kubernetes NetworkPolicy with CiliumNetworkPolicy, controlling L3/L4/L7 and DNS-based egress. Covers a four-stage default-deny rollout roadmap, a Hubble-driven policy author
2026-06-13 · 14 min read #cilium#network-policy#zero-trust#kubernetes#securitySPIFFE/SPIRE Workload Identity — Service-to-Service Authentication Without Secrets
SPIFFE/SPIRE is the answer to secret sprawl in the age of non-human identity. We cover SPIFFE IDs and SVIDs, the SPIRE server/agent architecture and attestation, hands-on Kubernetes deployment YAML, and automatic mTLS vi
2026-06-12 · 16 min read #spiffe#spire#mtls#workload-identity#kubernetesOIDC Token Validation at the API Gateway — Istio, Envoy, and Gateway API in Practice
Validate at the edge or in the service? This post covers detailed Envoy jwtauthn filter configuration, the Istio RequestAuthentication plus AuthorizationPolicy combination, JWKS caching and failure modes, audience strate
2026-06-12 · 15 min read #istio#envoy#jwt#oidc#api-gatewayKeycloak HA on Kubernetes — Infinispan Clustering and Zero-Downtime Deployments
A hands-on guide to running Keycloak with high availability on Kubernetes. We compare the Operator and Helm, walk through Infinispan caches and JGroups DNSPING, persistent user sessions, the 26.6 zero-downtime rolling pa
2026-06-12 · 13 min read #keycloak#kubernetes#infinispan#ha#devopsKubernetes Ecosystem 2026 Deep-Dive — Helm, Kustomize, Argo CD, Flux, KEDA, Karpenter, Cluster API, Operator Framework
A complete tour of the Kubernetes ecosystem as of May 2026. We cover manifest tools (Helm 3.18+, Kustomize, Carvel, Jsonnet, cdk8s), the Argo CD vs Flux v2 GitOps split, KEDA and Karpenter autoscaling, Cluster API and CA
2026-05-16 · 23 min read #kubernetes#helm#kustomize#argocd#fluxKubestronaut Path 2026 Deep-Dive - CKA, CKAD, CKS, KCNA, KCSA and the CNCF Certification Ladder (Prometheus, Istio, Cilium, OpenTelemetry, Argo)
A thorough 2026 guide to the Kubestronaut program and the CNCF certification ladder. We cover the five core exams (CKA, CKAD, CKS, KCNA, KCSA) in depth — domains, exam format, passing scores, pass rates, Killer Shell moc
2026-05-16 · 20 min read #kubestronaut#cncf#kubernetes#cka#ckadKubernetes Admission Policies & Security 2026 — Kyverno (CNCF Graduated) / OPA Gatekeeper / VAP (CEL) / Falco / KubeArmor / Tetragon Deep Dive
The full topology of Kubernetes security in 2026. Kyverno that became CNCF Graduated in November 2024, Rego-based OPA Gatekeeper, the built-in Validating Admission Policy that went GA in k8s 1.30 (CEL), the alpha Mutatin
2026-05-16 · 24 min read #kubernetes#security#admission-controller#kyverno#opa-gatekeeperKubernetes Certifications & Kubestronaut 2026 - The Complete Deep Dive Into CKA, CKAD, CKS, KCNA, KCSA, and the CNCF Roadmap
A full 2026 map of CNCF certifications - exam formats and domains for KCNA, KCSA, CKA, CKAD, and CKS, the Kubestronaut and Golden Kubestronaut requirements, recommended study path, killer.sh and KodeKloud usage, cost/ren
2026-05-16 · 22 min read #english#kubernetes#cncf#cka#ckadContainer Runtime Alternatives 2026 Deep Dive - containerd, CRI-O, Podman, runc, gVisor, Kata Containers, youki, WasmEdge, and Firecracker
The container runtime landscape in 2026 is no longer Docker-centric. Kubernetes removed dockershim in 1.24, and containerd 2.0 and CRI-O 1.31 have become the cluster default. On developer workstations Podman 5 and Docker
2026-05-16 · 18 min read #english#container-runtime#containerd#cri-o#podmaneBPF Observability 2026 — Pixie / Parca / Cilium Hubble / Tetragon / Beyla / Coroot / Falco Deep Dive
A complete map of the eBPF ecosystem as of 2026. Compares Pixie, Parca, Cilium Hubble, Tetragon, BCC/bpftrace, OpenTelemetry eBPF Collector, Grafana Beyla, Coroot, Inspektor Gadget, Kepler and Falco — plus the CO-RE revo
2026-05-15 · 24 min read #ebpf#observability#pixie#parca#ciliumThe Complete Golden Kubestronaut Roadmap — Conquering All 16 CNCF Certifications (With Per-Cert Study Content, 2026)
Kubestronaut means all 5 Kubernetes certifications; Golden Kubestronaut means all 15 CNCF certifications plus LFCS. This post breaks down all 16 exams one by one — the difference between the two tiers, the two exam forma
2026-05-14 · 14 min read #kubernetes#cncf#certification#kubestronaut#golden-kubestronautMLOps Complete Guide — Model Serving, Feature Store, Drift, A/B Testing, GPU Economics (Season 2 Ep 7, 2025)
Training a model and running it in production are completely different games. Serving (TorchServe, Triton, vLLM, TGI), Feature Stores (Feast, Tecton), training infra (Ray, Determined), experiment tracking (MLflow, W&B),
2026-04-15 · 12 min read #mlops#model-serving#feature-store#drift-detection#ab-testingKubernetes Internals Complete Guide — etcd, API Server, Controller, Scheduler, kubelet, CRI/CNI/CSI Deep Dive (2025)
Everything about Kubernetes internals — history from Google Borg, etcd Raft consensus, API Server REST and watch protocol, scheduler filter/score algorithms, controller manager reconciliation loops, kubelet Pod lifecycle
2026-04-15 · 11 min read #kubernetes#etcd#controller#scheduler#kubeletContainer & Docker Internals Deep Dive — Namespace, cgroups, OverlayFS, seccomp, Capabilities and Kubernetes (2025)
"A container is not a lightweight VM." Behind a single docker run there are 7 Linux namespaces, cgroups v2, OverlayFS layers, seccomp filters, and Linux capabilities. From LXC in 2008 to Docker in 2013, OCI standardizati
2026-04-15 · 12 min read #docker#container#namespace#cgroups#overlayfsChaos Engineering Deep Dive — Netflix Simian Army, LitmusChaos/Chaos Mesh, AWS FIS, Game Day
Why Netflix started randomly killing production servers in 2010. From Chaos Monkey philosophy and the 4 principles, to the full Simian Army, LitmusChaos/Chaos Mesh/AWS FIS comparison, Game Day design, and blameless postm
2026-04-15 · 10 min read #chaos-engineering#sre#reliability#netflix#kubernetesKubernetes Networking Deep Dive Guide 2025: CNI, Service, Ingress, DNS, Network Policy
Everything about K8s networking! Pod networking model, CNI plugins (Calico/Cilium/Flannel), Service (ClusterIP/NodePort/LoadBalancer), Ingress vs Gateway API, CoreDNS, Network Policy, eBPF-based networking, and traffic f
2026-04-14 · 24 min read #kubernetes#networking#cni#service#ingressGitOps Complete Guide 2025: ArgoCD vs Flux, ApplicationSet, Image Updater, Multi-Cluster
Everything about GitOps! ArgoCD vs Flux comparison, Git as single source of truth, ApplicationSet (Cluster/Git/Matrix generators), Image Updater (automatic image updates), Helm/Kustomize integration, Progressive Delivery
2026-04-14 · 16 min read #gitops#argocd#flux#continuous-delivery#kubernetesKubernetes Advanced Operations Guide 2025: Autoscaling, Scheduling, Resource Management, Multi-Cluster
Everything about K8s advanced operations! Autoscaling (HPA/VPA/KEDA/Karpenter), Scheduling (Affinity/Taint-Toleration/Priority/Topology), Resource Management (QoS/LimitRange/ResourceQuota), Multi-Cluster (Cluster API/Fle
2026-04-14 · 15 min read #kubernetes#hpa#vpa#keda#schedulerContainer Security & Supply Chain Complete Guide 2025: Image Scanning, Sigstore, SBOM, Runtime Security
Everything about container security! Image scanning (Trivy/Grype/Snyk), image signing (Sigstore/cosign), SBOM (CycloneDX/SPDX), runtime security (Falco/Tetragon), Pod Security Standards, Network Policy, Seccomp/AppArmor,
2026-04-14 · 15 min read #container-security#supply-chain#image-scanning#sigstore#sbom