그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그 그
Gardener Cookies
Tuesday, December 25, 2018 in 2018
2 minute read
Green Tea Matcha Cookies For a team event during the Christmas season we decided to completely reinterpret the topic cookies. :-) Matcha cookies have the delicate flavor and color of green tea. These soft, pillowy and chewy green tea cookies are …
Cookies Are Dangerous...
Saturday, December 22, 2018 in 2018
less than a minute
…they mess up the figure. For a team event during the Christmas season we decided to completely reinterpret the topic cookies… since the vegetables have gone on a well-deserved vacation. :-) Get the recipe at Gardener Cookies.
Hibernate a Cluster to Save Money
Wednesday, July 11, 2018 in 2018
less than a minute
You want to experiment with Kubernetes or set up a customer scenario, but don’t want to run the cluster 24 / 7 due to cost reasons? Gardener gives you the possibility to scale your cluster down to zero nodes. Learn more on Hibernate a Cluster.
Watching Logs of Several Pods
Monday, June 11, 2018 in 2018
less than a minute
One thing that always bothered me was that I couldn’t get the logs of several pods at once with kubectl. A simple tail -f <path-to-logfile> isn’t possible. Certainly, you can use kubectl logs -f <pod-id>, but it doesn’t …
Shared Storage with S3 Backend
Monday, June 11, 2018 in 2018
less than a minute
The storage is definitely the most complex and important part of an application setup. Once this part is completed, one of the most problematic parts could be solved. Mounting an S3 bucket into a pod using FUSE allows you to access data stored in S3 …
ReadWriteMany - Dynamically Provisioned Persistent Volumes Using Amazon EFS
Monday, June 11, 2018 in 2018
2 minute read
The efs-provisioner allows you to mount EFS storage as PersistentVolumes in Kubernetes. It consists of a container that has access to an AWS EFS resource. The container reads a configmap containing the EFS filesystem ID, the AWS region and the name …
Namespace Scope
Monday, June 11, 2018 in 2018
less than a minute
Should I use: ❌ one namespace per user/developer? ❌ one namespace per team? ❌ one per service type? ❌ one namespace per application type? 😄 one namespace per running instance of your application? Apply the Principle of Least Privilege All user …
Namespace Isolation
Monday, June 11, 2018 in 2018
less than a minute
…or DENY all traffic from other namespaces You can configure a NetworkPolicy to deny all traffic from other namespaces while allowing all traffic coming from the same namespace the pod is deployed to. There are many reasons why you may choose …
Kubernetes is Available in Docker for Mac 17.12 CE
Monday, June 11, 2018 in 2018
less than a minute
Kubernetes is only available in Docker for Mac 17.12 CE and higher on the Edge channel. Kubernetes support is not included in Docker for Mac Stable releases. To find out more about Stable and Edge channels and how to switch between them, see general …
Hardening the Gardener Community Setup
Monday, June 11, 2018 in 2018
less than a minute
The Gardener project team has analyzed the impact of the Gardener CVE-2018-2475 and the Kubernetes CVE-2018-1002105 on the Gardener Community Setup. Following some recommendations it is possible to mitigate both vulnerabilities.