510 posts tagged with "Kubernetes"
Container orchestration, Cluster API, and self-hosted control planes

Gateway API 1.6 Gives Agent Sandboxes a Named Egress Target—Not an Egress Policy
Gateway API 1.6's experimental XBackend can make an AI API destination reviewable. Here is the complete control stack required to turn that declaration into safe sandbox egress.

Hetzner DNS Makes `ttl` Mandatory: Audit the One ACME Call That Can Break Renewal
Hetzner Cloud DNS will require an explicit TTL on one RRSet action after September 30, 2026. Identify whether your ACME path uses it, patch the request correctly, and rehearse a safe renewal.

Karpenter on Bare Metal Is Not Magic: The Supply Chain Behind a NodeClaim
A NodeClaim can choose capacity; only an automatable machine supply can deliver it. Follow a realistic burst from pending Pod to Ready bare-metal worker.

CVE-2026-35469: Audit SPDY Exposure in Your Self-Hosted Kubernetes Fleet
CVE-2026-35469 affects a SPDY dependency, not a single Kubernetes version. Use this practical audit to identify reachable parsers, verify vendor fixes, and roll self-hosted nodes safely.

Platform Engineering 2.0 Has Five Good Ideas—and an Implementation Gap
A practical readiness matrix for turning Platform Engineering 2.0’s AI, agent, FinOps, security, and composability pillars into operating designs a Kubernetes PaaS can verify.

Porter's 0.01-vCPU Promise Meets the BYOC Cost Floor
Porter bills requested CPU and RAM inside your cloud account, but a BYOC cluster still has a fixed cost. A three-way example shows where granular requests help, where hosted tiers win, and how ownership changes the bill.

SELinux Volume Labels in Kubernetes 1.36: Audit Your Multi-Tenant Storage Before 1.37
Kubernetes 1.37 makes SELinux context mounts the default for eligible volumes. Audit CSI drivers, shared PVCs, and label conflicts before the upgrade leaves a Pod stuck in ContainerCreating.

SpinKube on an Existing Kubernetes Fleet: One More RuntimeClass, Not a Parallel Platform
Add Spin WebAssembly workloads to an existing Kubernetes fleet with a containerd shim and RuntimeClass—without adding a second scheduler or parallel platform.

Three Stages of Self-Hosting: The Operational Checklist for Moving Beyond One Server
Use four operational signals—downtime ownership, restore drills, deploy concurrency, and node replacement—to decide when a one-server PaaS should grow into a fleet.