Skip to main content

509 posts tagged with "Kubernetes"

Container orchestration, Cluster API, and self-hosted control planes

View all tags

Read the Kubernetes for platform teams guide

Hetzner's Post-July API Churn: The Primary IP Flip and Prometheus 3.14 Label Drop Your CAPH Fleet Still Hasn't Pinned
·Dora Noda·9 min

Hetzner's Post-July API Churn: The Primary IP Flip and Prometheus 3.14 Label Drop Your CAPH Fleet Still Hasn't Pinned

Hetzner's July datacenter removal was only the headline: unassigned Primary IPs flipped to assignee_type unassigned on August 1, Prometheus 3.14 dropped the Hetzner datacenter label, and the datacenters API goes 410 on October 1. A per-break fix table plus a six-grep audit runbook for CAPH fleets.

self-hosting
Kubernetes
cloud infrastructure
guide
Hetzner After the June 2026 Price Hikes: Auction Metal vs Cloud VMs as Kubernetes Fleet Nodes
·Dora Noda·11 min

Hetzner After the June 2026 Price Hikes: Auction Metal vs Cloud VMs as Kubernetes Fleet Nodes

Hetzner's June 2026 hikes tripled dedicated cloud prices while auction boxes held at €37–€46 — a euro-level comparison of auction metal versus cloud VMs as Kubernetes fleet nodes, the operational tradeoffs, and which roles fit each.

self-hosting
Kubernetes
cost-optimization
PaaS
Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself
·Dora Noda·9 min

Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself

Kubernetes 1.36 graduates fine-grained kubelet authorization to GA, replacing the over-broad nodes/proxy grant that lets read-only agents execute code in any pod. This playbook maps every kubelet endpoint to its least-privilege subresource and walks through the five-step migration for fleets running untrusted tenant workloads.

Kubernetes
security
self-hosting
infrastructure
Kubernetes 1.37 Scales HPA to Zero in Core: No More Paying for Idle Pods
·Dora Noda·13 min

Kubernetes 1.37 Scales HPA to Zero in Core: No More Paying for Idle Pods

Kubernetes 1.37 graduates HPA scale-to-zero to a default-on beta, so queue workers and preview environments can drop to zero replicas on an external metric. This post works the idle-economics math, shows the exact wiring, and maps where KEDA and Knative still fit.

Kubernetes
cost-optimization
self-hosting
PaaS
Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS
·Dora Noda·10 min

Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS

Kubernetes signs its releases with Sigstore — but a signature nobody verifies is theater. How to wire Cosign keyless signing into a git-push pipeline and enforce it with a Kyverno admission policy before unsigned images reach your nodes.

security
Kubernetes
self-hosting
PaaS
OpenCost's Built-In MCP Server Turns Cost Allocation Into an Agent-Callable Tool
·Dora Noda·8 min

OpenCost's Built-In MCP Server Turns Cost Allocation Into an Agent-Callable Tool

OpenCost's built-in MCP server exposes Kubernetes cost allocation as agent-callable tools. Here is the exact tool surface, a worked tenant-cost query, and the scoping rules that keep read-only cost data safe on a multi-tenant fleet.

Kubernetes
self-hosting
Model Context Protocol
AI agents
+1
After the 2026 Price Hikes: Re-Ranking Hetzner, OVHcloud, and DigitalOcean for a Self-Hosted PaaS Fleet
·Dora Noda·10 min

After the 2026 Price Hikes: Re-Ranking Hetzner, OVHcloud, and DigitalOcean for a Self-Hosted PaaS Fleet

Hetzner raised cloud prices twice in 2026 while OVHcloud added 9–11% — a line-by-line re-ranking of 2 vCPU/4 GB nodes and what a six-node self-hosted fleet month costs on each provider now.

self-hosting
cost-optimization
PaaS
Kubernetes
Platform Engineering 2.0: Your Internal Platform's Newest User Is an AI Agent
·Dora Noda·12 min

Platform Engineering 2.0: Your Internal Platform's Newest User Is an AI Agent

CNCF's 2026 Platform Engineering 2.0 framing says your platform's newest user is an AI agent. A 5-minute audit plus the API-first requirements — declarative state, idempotent writes, policy at execution — that make agents operable on machines you own.

AI agents
PaaS
self-hosting
Kubernetes
Your Sidecars Are Eating Whole CPUs: Kubernetes 1.37's Pod-Level Resource Managers Hit Beta
·Dora Noda·10 min

Your Sidecars Are Eating Whole CPUs: Kubernetes 1.37's Pod-Level Resource Managers Hit Beta

Kubernetes 1.37 graduates Pod-Level Resource Managers to beta, ending the era when every sidecar needed its own exclusive CPU. How the hybrid pod-budget model reclaims wasted cores, what changed since alpha, and the staging checklist for self-hosted platforms.

Kubernetes
self-hosting
PaaS
cost-optimization
Showing 100–108 of 509 posts