
Stop Copying Registry Passwords Into Every Namespace: Kubernetes 1.34 ServiceAccount Image Pulls in Practice
Kubernetes 1.34's beta ServiceAccount token flow replaces per-namespace imagePullSecrets with short-lived, workload-bound pull credentials — how to wire the registry side, bind ServiceAccounts, handle rotation, and test the failure modes before deleting static secrets.

One Webhook, Every Repo Traced: Zero-Instrumentation CI Tracing With OTel's githubreceiver
A single org-level GitHub webhook plus the OTel Collector's githubreceiver turns workflow_run and workflow_job events into drillable traces — slow, flaky, and queued-job visibility across every repo with zero workflow-file edits, and a sizing method worth copying.

Your Build Cache Is Invisible to Kubelet: Sizing Image GC So Tenant Builds Stop Evicting Tenant Pods
Tenant builds fill shared nodes with cache that kubelet image GC can never reclaim — until DiskPressure evicts running pods. A measured method for budgeting per-node disk, with a worked 80GB example and copy-paste kubelet plus BuildKit configs.

Rotate the Database Password Without Shipping a Rebuild: A No-Redeploy Secrets Playbook for Git-Push Platforms
Self-hosted git-push platforms bake secrets into deploys, so every password rotation ships a rebuild. A playbook for decoupling them: projected Secret volumes, a reload sidecar, and the overlap ordering that keeps Postgres readers connected throughout.

RustFS Hits 1.0 as Docker Hub Drops MinIO: Your Forced S3 Migration, Mapped
MinIO's Docker Hub repositories are gone and RustFS just hit 1.0. Here is the ten-minute quay.io bridge that restores redeploys, a comparison of RustFS, Garage, and SeaweedFS, and an mc mirror runbook for moving your buckets.

Running Your First StorageVersionMigration: What Kubernetes v1.37's GA Migration API Changes in Your Cluster API Upgrade Runbook
Kubernetes v1.37 turned storage version migration into a stable, always-on API. Here is how to run your first migration — Secrets re-encryption, CRD version collapse, and per-resource status checks — and where it slots into a Cluster API fleet's upgrade runbook.

Heroku to Linode + Kamal in Production: A Real Team's Terraform-Retiring Migration, Step by Step
A production Rails site left Heroku for Linode plus Kamal in three days across four tracked issues, ending with the Heroku provider deleted from Terraform. This walkthrough covers each cutover step, the before/after bill, and what the team's no-fallback decision costs the week DNS flips.

Your Operator's /readyz Is Lying: The controller-runtime Cache-Sync Trap Behind Green Dashboards and Stalled Reconciles
A kubebuilder operator's scaffolded readyz check returns 200 before the informer cache syncs, before leader election completes, and before webhooks serve. The three readiness checks that close the gap, the RBAC stall that makes them necessary, and the audit to run this week.

GitHub's Egress Firewall Won't Cover Your Self-Hosted Runners — Here's the Blueprint That Will
GitHub's 2026 roadmap adds a root-proof egress firewall for hosted runners only. Replicate that guarantee on self-hosted ARC runners with ephemeral pods, default-deny egress, Cilium DNS allowlists, and SHA-pinned actions.