Skip to main content

58 posts tagged with "Guide"

Comprehensive guides and documentation

View all tags

containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet
·Dora Noda·9 min

containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet

containerd 2.1 went end-of-life with no patch for Critical CVE-2026-46680, a runAsNonRoot bypass. Which versions are safe, how to pick a landing zone, and the five-step Cluster API runbook: audit, image, template, roll, verify.

Kubernetes
security
self-hosting
guide
No More Annotations: Gateway API v1.5 and v1.6 Make PaaS Ingress 100% Portable YAML
·Dora Noda·8 min

No More Annotations: Gateway API v1.5 and v1.6 Make PaaS Ingress 100% Portable YAML

Gateway API v1.5 and v1.6 moved the CORS filter, TLSRoute, and TCP/UDP routes into the Standard channel, so a git-push PaaS can express a tenant's whole ingress layer as portable YAML with zero annotations. Includes the GRPCRoute timeline correction and the four-item conformance checklist to run before tenants rely on it.

self-hosting
PaaS
Kubernetes
guide
Heroku Is in Sustaining Mode: When to Migrate and What Render, Railway, and Fly.io Really Cost
·Dora Noda·11 min

Heroku Is in Sustaining Mode: When to Migrate and What Render, Railway, and Fly.io Really Cost

Heroku's February 2026 sustaining-mode announcement closed the door on new Enterprise contracts and froze new features. A timing framework for when to leave, a five-way cost table for the same workload on Heroku, Render, Railway, Fly.io, and Hetzner hardware, and where each alternative actually fits.

self-hosting
PaaS
migration
cost-optimization
+1
Kubernetes Fits in a Browser Tab: What ngrok's 140KiB Cluster Says Your Edge Fleet Can Drop
·Dora Noda·9 min

Kubernetes Fits in a Browser Tab: What ngrok's 140KiB Cluster Says Your Edge Fleet Can Drop

ngrok's webernetes project squeezed a working Kubernetes cluster into 140KiB of browser JavaScript. Its keep/drop inventory — verified against k3s — draws the line between what a single-node fleet can shed and what it must keep.

self-hosting
PaaS
Kubernetes
guide
SOPS with Age vs Sealed Secrets: What GitOps Secrets Cost to Rotate on a Cluster API Fleet
·Dora Noda·12 min

SOPS with Age vs Sealed Secrets: What GitOps Secrets Cost to Rotate on a Cluster API Fleet

Committing encrypted secrets to Git is the easy part. A fleet-scale comparison of SOPS with age versus Bitnami Sealed Secrets on what each costs to rotate, audit, and recover after the management cluster dies — with runbooks and the February 2026 rotation CVE that settles it.

self-hosting
PaaS
Kubernetes
security
+1
Don't Build Cron Into Your PaaS: Running Windmill's Script-to-Webhook Engine as a Tenant Workload
·Dora Noda·9 min

Don't Build Cron Into Your PaaS: Running Windmill's Script-to-Webhook Engine as a Tenant Workload

Every git-push PaaS eventually needs cron and background workers. A concrete build-vs-route decision: run Windmill's open-source workflow engine as a tenant workload, or build your own — with the six-dimension tradeoff table and the three conditions that flip the answer.

self-hosting
PaaS
Kubernetes
guide
Radar's 15-Second Local-First Kubernetes UI: Replacing the SaaS Dashboard Without Losing GitOps or Network Visibility
·Dora Noda·12 min

Radar's 15-Second Local-First Kubernetes UI: Replacing the SaaS Dashboard Without Losing GitOps or Network Visibility

Skyhook's Radar is a free Apache-2.0 Kubernetes UI that runs as a single local binary off your kubeconfig. A head-to-head verdict against Lens, Headlamp, and k9s on GitOps depth, network visibility, and trust boundary — plus where a local UI stops being enough for a team fleet.

Kubernetes
self-hosting
infrastructure
guide
The Heroku Exit Playbook: Procfile to Buildpack, Every Add-on Decision, and the Real Before/After Bill
·Dora Noda·13 min

The Heroku Exit Playbook: Procfile to Buildpack, Every Add-on Decision, and the Real Before/After Bill

A step-by-step playbook for actually leaving Heroku's sustaining-engineering mode: Procfile to manifest, add-ons sorted into keep/replace/lose, secrets without a leak window, a rehearsed database cutover, and a real before/after bill.

self-hosting
PaaS
migration
cost-optimization
+1
Webhook Signature Verification for Git-Push Deploys: What a Self-Hosted PaaS Has to Get Right That GitHub's Own Docs Gloss Over
·Dora Noda·11 min

Webhook Signature Verification for Git-Push Deploys: What a Self-Hosted PaaS Has to Get Right That GitHub's Own Docs Gloss Over

On a git-push PaaS, the webhook endpoint is a remote build trigger — and HMAC verification is its entire security boundary. A 10-point audit checklist covering the raw-body trap, the === timing leak, the timingSafeEqual length-throw, the SHA-1 header ghost, and the replay gap GitHub's docs never assemble into one place.

security
PaaS
self-hosting
guide
Showing 46–54 of 58 posts