Tag
Kubernetes
← Clear filter
OperationsWordPress on Kubernetes: seven traps between the chart and the first page
WordPress runs well on Kubernetes if a few things are right from the start. Seven traps almost everyone hits once during their first setup, and how to avoid them.
- Kubernetes
- Volumes
- Databases
ArchitectureHelm charts and their disks: what is left after helm uninstall
A Helm chart often brings its own disks, for example for the database bundled in the chart. Some disappear on uninstall, data and all, others stay around forever. You want to know which before you start.
- Volumes
- Backups
- Kubernetes
OperationsLogs, usage and uptime without your own monitoring stack
During an incident, three questions matter: What is the application writing, how heavily was it used, and can it be reached from outside? Not every team needs its own monitoring stack for that.
- Monitoring
- Kubernetes
- Kapsule
SecurityKubernetes Secrets: why Base64 is not encryption
A Kubernetes Secret is Base64, readable by anyone with the right permissions. Where secrets leak, and what a secret manager, rotation and clean permissions change.
- Secrets
- Kubernetes
- Scaleway
OperationsRollbacks on Kubernetes: why a tag is not a version
A rollback that pulls the same tag again brings back the broken version. If you want to roll back reliably, you need the digest of every deployment, and a plan for the database.
- CI/CD
- Kubernetes
- Backups
OperationsBus factor 1: when the cluster belongs to a single colleague
In many small teams, the cluster belongs to one colleague. That works fine until they go on vacation. Six steps to make sure operations no longer hinge on one person.
- Kubernetes
- SaaS
- Costs
SecurityNIS2 in Kubernetes operations: the evidence an auditor wants to see
NIS2 doesn’t require any particular technology, but measures and proof. For Kubernetes operations, that means personal access, a complete log and tested backups.
- Compliance
- Kubernetes
- SaaS
OperationsFrom AWS to Scaleway: what becomes of RDS, S3 and Route 53
Almost every AWS service has a counterpart at Scaleway. The move rarely fails because of Kubernetes – it fails on the database cutover, egress costs and DNS.
- Migration
- Scaleway
- Kubernetes
ArchitectureFrom ingress-nginx to Envoy Gateway: switching controllers without a dark window
Change the ingress class and deploy: the new controller serves, the old one no longer does, and DNS still points at the old one. The host answers 404 until the TTL expires. Here’s a better way.
- Ingress
- Kubernetes
- TLS
ArchitecturePersistent volumes on Kubernetes: ReadWriteOnce, Recreate and the snapshot before deletion
A rolling update with a volume is a deadlock waiting to happen. And deleting a volume from the manifest is data loss waiting to happen. Five rules that prevent both.
- Volumes
- Kubernetes
- Backups
OperationsKubernetes upgrades on Kapsule without the fear
Kubernetes ships three minor versions a year, and Kapsule supports only a limited number of them. Wait two years and you have four upgrades ahead of you. Better: one per quarter, boring.
- Kapsule
- Kubernetes
- Scaleway
OperationsKaniko or GitHub Actions: where should the image be built?
Kaniko builds where the application runs. GitHub Actions builds where the code lives. Neither needs a Docker daemon, and both have a catch you only notice in production.
- CI/CD
- Kubernetes
- Costs
OperationsWhy your app sees the wrong IP behind the load balancer
Every visitor comes from the same IP, the login limit locks out all customers at once, and the allowlist lets nobody in. That’s not an attack, that’s the load balancer.
- Ingress
- Scaleway
- Kubernetes
ArchitectureMulti-tenant SaaS: a namespace per customer or a row per customer?
Multi-tenancy is not a yes-or-no question. Most SaaS vendors need both: rows for the many small customers and namespaces for the few large ones.
- SaaS
- Multi-tenant
- Kubernetes