Skip to main content

368 posts tagged with "Engineering"

Engineering insights and technical deep dives

View all tags

CNCF's Composable-by-Design Rule: What It Actually Costs to Build a Swappable PaaS
·Dora Noda·8 min

CNCF's Composable-by-Design Rule: What It Actually Costs to Build a Swappable PaaS

CNCF says platforms should be built from swappable, API-first building blocks. Here's what that actually costs on day one versus a hardcoded platform, worked through two real architecture cases — one of them a GPU request a Cluster API-based PaaS wasn't built to handle.

self-hosting
PaaS
infrastructure
AI
+1
The Docker Desktop License Threshold Nobody Rechecks: What 250 Employees or $10M Revenue Actually Costs a Team
·Dora Noda·8 min

The Docker Desktop License Threshold Nobody Rechecks: What 250 Employees or $10M Revenue Actually Costs a Team

Docker Desktop stops being free the moment a company crosses 250 employees or $10M in revenue — whichever it hits first. For a 30-developer team, that's $5,400 to $8,640 a year, plus a three-year audit lookback most finance teams never see coming.

self-hosting
PaaS
cost-optimization
engineering
Preventing etcd Zombies on Upgrade to 3.6: A Cluster API Operator's Pre-Flight Checklist
·Dora Noda·8 min

Preventing etcd Zombies on Upgrade to 3.6: A Cluster API Operator's Pre-Flight Checklist

Kubeadm still pins etcd to v3.5.24-0 for Kubernetes 1.31 through 1.33 — one patch below the v3.5.26 floor etcd's maintainers say you need before v3.6. Here's why Cluster API's machine-replacement upgrade model skips that safety margin entirely, and the pre-flight checklist to run before you cross the boundary.

Kubernetes
self-hosting
PaaS
engineering
Grafana Fleet Management Now Pushes Config to Any OTel Collector — But Still Can't Run Air-Gapped
·Dora Noda·8 min

Grafana Fleet Management Now Pushes Config to Any OTel Collector — But Still Can't Run Air-Gapped

Grafana Fleet Management went GA for vendor-neutral OpenTelemetry Collectors on July 8, 2026 — one control plane, one matcher-scoped push, instead of a per-node config edit. The catch: it still requires a live Grafana Cloud backend, and a 20-star open-source project is the only fully self-hosted alternative.

self-hosting
PaaS
infrastructure
engineering
kpack: The Buildpack Controller That Rebuilds When the Base Layer Patches, Not When You Push
·Dora Noda·9 min

kpack: The Buildpack Controller That Rebuilds When the Base Layer Patches, Not When You Push

Most git-push PaaS tools only rebuild an app image when you push code — so a CVE patched into the base image sits unused until you happen to touch your source again. kpack's Image/Builder/ClusterStack CRDs close that gap by watching the base layer itself.

self-hosting
PaaS
security
engineering
+1
Kubernetes 1.36 Lets You Resize a Job Before It Starts: The Queue-Then-Resize Pattern a Build Queue Needed
·Dora Noda·7 min

Kubernetes 1.36 Lets You Resize a Job Before It Starts: The Queue-Then-Resize Pattern a Build Queue Needed

Kubernetes 1.36 lets a queue controller patch a suspended Job's CPU/memory/GPU requests down to whatever's actually free, then unsuspend it, without losing the Job's identity or history. Here's the worked example, the safety guarantee behind it, and how to wire it into a build-queue controller.

self-hosting
PaaS
infrastructure
engineering
+1
Kubernetes 1.36 Ships Sharded Watch — Cluster API's Own Controllers Can't Use It Yet
·Dora Noda·8 min

Kubernetes 1.36 Ships Sharded Watch — Cluster API's Own Controllers Can't Use It Yet

KEP-5866 lets Kubernetes 1.36 filter watch events at the API server instead of every controller replica. Cluster API's own controllers can't use it yet — here's the architecture gap and what would actually close it.

self-hosting
PaaS
infrastructure
engineering
Your Kubernetes Autoscaler Can't See Your Queue: Building the Exporter That Fixes It
·Dora Noda·7 min

Your Kubernetes Autoscaler Can't See Your Queue: Building the Exporter That Fixes It

CPU and memory can't see a growing job queue on an I/O-bound worker. Here's the exact Go exporter, Prometheus adapter config, and HPA YAML that lets Kubernetes autoscale on queue depth instead — and what shipping it as a golden path would take on a self-hosted PaaS.

self-hosting
PaaS
infrastructure
engineering
Your Post-Quantum TLS Migration Isn't a Second Certificate Format — It's the Same Freshness Problem You Already Solved for 6-Day Certs
·Dora Noda·8 min

Your Post-Quantum TLS Migration Isn't a Second Certificate Format — It's the Same Freshness Problem You Already Solved for 6-Day Certs

Let's Encrypt is skipping a direct ML-DSA swap for Merkle Tree Certificates because the naive post-quantum handshake blows past 14,700 bytes. Here's the actual byte math, the late-2026 staging timeline, and what a self-hosted PaaS's ACME automation needs to track before production MTCs land in 2027.

self-hosting
PaaS
security
infrastructure
+1
Showing 172–180 of 368 posts