Gardener v1.8.0 Released

2020-08-06
Aug 20, 2020 Read Time: 6 min

Even if we are in the midst of the summer holidays, a new Gardener release came out yesterday: v1.8.0! It’s main themes are the large change of our logging stack to Loki (which was already …

Continue reading

Cluster Overprovisioning

2019-06-11
Jun 19, 2019 Read Time: 1 min

This tutorial describes how to overprovisioning of cluster nodes for scaling and failover. This is desired when you have work load that need to scale up quickly without waiting for the new cluster …

Continue reading

Anti Patterns

2018-06-11
Jun 18, 2018 Read Time: 1 min

Running as root user

Whenever possible, do not run containers as root users. One could be tempted to say that Kubernetes Pods and Node are well separated. The host and the container share the …

Continue reading

Cookies are dangerous...

2018-06-11
Jun 18, 2018 Read Time: 1 min

…they mess up the figure.

For a team event during the Christmas season we decided to completely reinterpret the topic cookies… since the vegetables have gone on a well-deserved …

Continue reading

Frontend HTTPS

2018-06-11
Jun 18, 2018 Read Time: 1 min

For encrypted communication between the client to the load balancer, you need to specify a TLS private key and certificate to be used by the ingress controller.

Create a secret in the …

Continue reading

Namespace Isolation

2018-06-11
Jun 18, 2018 Read Time: 1 min

…or DENY all traffic from other namespaces

You can configure a NetworkPolicy to deny all traffic from other namespaces while allowing all traffic coming from the same namespace the pod is …

Continue reading

Namespace Scope

2018-06-11
Jun 18, 2018 Read Time: 1 min

Should I use:

  • ❌ one namespace per user/developer?
  • ❌ one namespace per team?
  • ❌ one per service type?
  • ❌ one namespace per application type?
  • 😄 one namespace per running instance of …
Continue reading

Shared storage with S3 backend

2018-06-11
Jun 18, 2018 Read Time: 1 min

The storage is definitely the most complex and important part of an application setup, once this part is completed, one of the most problematic parts could be solved.

Mounting a S3 bucket into a pod …

Continue reading