Blog

Featured
When Kubernetes restarts your pod — And when it doesn’t
Project Maintainer Post When Kubernetes restarts your pod — And when it doesn’t
A production internals guide verified against Kubernetes 1.35 GACompanion repository: github.com/opscart/k8s-pod-restart-mechanics The terminology problem Engineers say “the pod restarted” when they mean four different things. Getting this wrong leads to flawed runbooks and bad on-call decisions....
March 17, 2026 | Shamsher Khan, Project Maintainer
  • Reset

Showing 875 of 2609 posts


On-prem DBaaS in 2026: Platforms, standards, and gaps
Member Post On-prem DBaaS in 2026: Platforms, standards, and gaps
For application teams, databases should feel like a solved problem. A team needs PostgreSQL, MariaDB, Redis, or another data service, submits a request, receives credentials, and starts building. In practice, the experience is rarely that simple....
July 15, 2026 | Oliver Wolf, anynines

Where should AI workloads run? A sovereign and sensible approach
Member Post Where should AI workloads run? A sovereign and sensible approach
Opinions on AI range from transformative optimism to deep skepticism, but one thing is clear: AI is becoming an increasingly important part of enterprise technology strategies. Feel free to pick whichever you like. But whatever you...
July 10, 2026 | Johannes Hemminger and Martin Hafner, KubeOps

Navigating the ingress-NGINX retirement
Member Post Navigating the ingress-NGINX retirement
1. The Post-March 2026 landscape ⚠ The CatalystAcknowledge the March 2026 retirement of the Kubernetes SIG Network ingress-nginx controller. Staying on this controller introduces severe operational risks, including unpatched CVEs and a complete halt of feature...
July 9, 2026 | Sunny Chan, TCC Consulting

Network boundary for AI agents using NGINX and OpenTelemetry
Member Post Network boundary for AI agents using NGINX and OpenTelemetry
I recently had an interesting conversation at a KCD about OpenClaw with one of the attendees, and they remarked that they wouldn’t put an agent in their network, because “we don’t know what that thing really...
July 8, 2026 | Marko Sluga, F5

The 4-body problem of SRE: Why autonomous operations depend on context
Member Post The 4-body problem of SRE: Why autonomous operations depend on context
What a room full of senior SREs confirmed about the trust gap, and where the actual work begins I spent a day last week at an event in Bengaluru asking a room full of senior SREs,...
July 6, 2026 | Sanjeev Sharma, Field CTO at StackGen

Evolving platform engineering for AI-native workloads
Member Post Evolving platform engineering for AI-native workloads
Platform Engineering 1.0 delivered real value. Golden paths accelerated deployment. Internal Developer Platforms (IDPs) reduced cognitive load for developers. Self-service infrastructure gave developers back hours they had been spending filing tickets. Pipelines provided a standard vehicle to...
July 6, 2026 | Pankaj Gupta, Senior Director of Private Cloud Solutions for VMware by Broadcom

How data sovereignty is changing cloud native infrastructure design
Member Post How data sovereignty is changing cloud native infrastructure design
The core issue isn’t where your server sits. It’s who can be compelled to hand over what’s on it. For years, cloud providers treated sovereignty as a geography problem. Pick a region. Choose a country. Keep...
July 3, 2026 | Dana Cazacu, Marketing Manager, VEXXHOST

(re)introducing kpt: Your toolchain for infrastructure automation
Member Post (re)introducing kpt: Your toolchain for infrastructure automation
What is kpt? The opening tagline of the kpt documentation describes it as “… a package-centric toolchain that enables a WYSIWYG configuration authoring, automation, and delivery experience, which simplifies managing Kubernetes platforms and KRM-driven infrastructure at...
July 2, 2026 | Ciaran Johnston, Ericsson

OTel and mesh-derived metrics: A 2026 reference
Community Post OTel and mesh-derived metrics: A 2026 reference
If you already run an OpenTelemetry pipeline, you have good visibility into what your applications are doing. This blog post is about what you don’t see yet: the east-west traffic between your services, measured at the...
June 29, 2026 | Mesut Oezdil, DevOps Engineer (written on behalf of Buoyant)

Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes
Member Post Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes
Linux provides powerful kernel-level security mechanisms, seccomp, SELinux, and AppArmor, that restrict what containerized workloads can do. Each uses profiles that define permitted behavior, but writing, distributing, and maintaining those profiles by hand is tedious and...
June 26, 2026 | Sascha Grunert (Red Hat)

Securing CI/CD for an open source project, part 3: Credentials, verification, and what’s next
Member Post Securing CI/CD for an open source project, part 3: Credentials, verification, and what’s next
This is the third and final post in a series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control and Part 2 covered dependency hardening. This post covers the last layer: keeping CI...
June 26, 2026 | André Martins (Cilium maintainer and Software Engineer, Isovalent at Cisco) and Feroz Salam (Cilium Security Team and Security Engineer, Isovalent at Cisco)

Improving Arm64 support in CNCF projects with OCI credits
Member Post Improving Arm64 support in CNCF projects with OCI credits
In recent years, Arm64 has been taking the cloud service provider world by storm. Recent reports indicate that, as of the end of 2025, over 50% of new instances on AWS and over 33% on Azure...
June 15, 2026 | Dave Neary, Director of Developer Relations at Ampere Computing

Securing CI/CD for an open source project: Locking down dependencies
Member Post Securing CI/CD for an open source project: Locking down dependencies
Part two This is the second post in a three-part series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control: who can trigger builds and what code CI is allowed to execute. This...
June 12, 2026 | André Martins (Cilium maintainer and Software Engineer, Isovalent at Cisco) and Feroz Salam (Cilium Security Team and Security Engineer, Isovalent at Cisco)

Solving secret sprawl in multi-account Kubernetes with External Secrets Operator
Member Post Solving secret sprawl in multi-account Kubernetes with External Secrets Operator
Infrastructure provisioning in Kubernetes has become increasingly automated, but secret management often remains a challenge as environments grow. Organizations commonly separate development, staging, and production workloads across clusters, namespaces, or cloud accounts to improve security and...
June 9, 2026 | Viktoria Bisova, DevOps Engineer, Itigix

Breaking free of a single datacenter: Practical geo-distributed AI operations with the k0smos platforms 
Member Post Breaking free of a single datacenter: Practical geo-distributed AI operations with the k0smos platforms 
Breaking the single datacenter assumption Modern AI architectures are built on the assumption of centralized, homogeneous data centers. In reality, infrastructure is messy. For most organizations, compute resources are fragmented across private clouds, research environments, and...
June 8, 2026 | Prithvi Raj (Mirantis), Alexander Acker (Logsight.ai), and Soeren Becker (Logsight.ai)

Benchmarking KubeVirt performance with virtbench
Member Post Benchmarking KubeVirt performance with virtbench
Organizations migrating VM estates from traditional hypervisors to KubeVirt often discover that many Kubernetes observability tools were originally designed around container workloads rather than VM-centric operational metrics. While KubeVirt schedules VMs as pods, the performance variables...
June 8, 2026 | Bob Glithero, Senior Technical Product Marketing Manager, Portworx by Everpure

Securing CI/CD for an open source project: Controlling who runs what
Member Post Securing CI/CD for an open source project: Controlling who runs what
Part one The last twelve months have been rough on the open source supply chain. Axios was compromised on npm and shipped a remote access trojan inside otherwise normal-looking releases. LiteLLM’s PyPI package was hijacked to...
June 4, 2026 | André Martins, Cilium maintainer and Software Engineer, Isovalent at Cisco and Feroz Salam, Cilium Security Team and a Security Engineer, Isovalent at Cisco.

Dynamic configuration for cloud native Swift services
Member Post Dynamic configuration for cloud native Swift services
Modern Swift services increasingly run alongside the same cloud native infrastructure stacks that power much of today’s Kubernetes ecosystem — including ConfigMaps, containerized workloads, declarative deployments, and service lifecycle management. Projects such as Prometheus and OpenTelemetry...
June 1, 2026 | Joe Heck, Swift Documentation Workgroup Member, Apple

Zero-Downtime migration from ingress NGINX to Envoy Gateway
Member Post Zero-Downtime migration from ingress NGINX to Envoy Gateway
Teams running Ingress NGINX in production are increasingly evaluating migration paths as Kubernetes networking evolves toward Gateway API. For many organizations, the challenge is not just selecting a Gateway API implementation, but designing a migration strategy...
May 25, 2026 | Andrew Katsikas, Pelotech

Introducing Prempti: Policy and visibility for AI coding agents
Member Post Introducing Prempti: Policy and visibility for AI coding agents
AI coding agents have become a real part of the developer workflow. Tools like Claude Code sit in your terminal, read your files, run shell commands, make network requests, and write code, all on your behalf....
May 20, 2026 | Leonardo Grasso, Falco Maintainer