Skip to main content

21 posts tagged with "Tutorial"

Step-by-step guides and tutorials

View all tags

Stop Copying Registry Passwords Into Every Namespace: Kubernetes 1.34 ServiceAccount Image Pulls in Practice
·Dora Noda·12 min

Stop Copying Registry Passwords Into Every Namespace: Kubernetes 1.34 ServiceAccount Image Pulls in Practice

Kubernetes 1.34's beta ServiceAccount token flow replaces per-namespace imagePullSecrets with short-lived, workload-bound pull credentials — how to wire the registry side, bind ServiceAccounts, handle rotation, and test the failure modes before deleting static secrets.

Kubernetes
security
self-hosting
PaaS
+1
One Webhook, Every Repo Traced: Zero-Instrumentation CI Tracing With OTel's githubreceiver
·Dora Noda·11 min

One Webhook, Every Repo Traced: Zero-Instrumentation CI Tracing With OTel's githubreceiver

A single org-level GitHub webhook plus the OTel Collector's githubreceiver turns workflow_run and workflow_job events into drillable traces — slow, flaky, and queued-job visibility across every repo with zero workflow-file edits, and a sizing method worth copying.

self-hosting
infrastructure
tutorial
developer tools
Your Build Cache Is Invisible to Kubelet: Sizing Image GC So Tenant Builds Stop Evicting Tenant Pods
·Dora Noda·9 min

Your Build Cache Is Invisible to Kubelet: Sizing Image GC So Tenant Builds Stop Evicting Tenant Pods

Tenant builds fill shared nodes with cache that kubelet image GC can never reclaim — until DiskPressure evicts running pods. A measured method for budgeting per-node disk, with a worked 80GB example and copy-paste kubelet plus BuildKit configs.

Kubernetes
self-hosting
PaaS
tutorial
Rotate the Database Password Without Shipping a Rebuild: A No-Redeploy Secrets Playbook for Git-Push Platforms
·Dora Noda·11 min

Rotate the Database Password Without Shipping a Rebuild: A No-Redeploy Secrets Playbook for Git-Push Platforms

Self-hosted git-push platforms bake secrets into deploys, so every password rotation ships a rebuild. A playbook for decoupling them: projected Secret volumes, a reload sidecar, and the overlap ordering that keeps Postgres readers connected throughout.

self-hosting
PaaS
Kubernetes
security
+1
RustFS Hits 1.0 as Docker Hub Drops MinIO: Your Forced S3 Migration, Mapped
·Dora Noda·8 min

RustFS Hits 1.0 as Docker Hub Drops MinIO: Your Forced S3 Migration, Mapped

MinIO's Docker Hub repositories are gone and RustFS just hit 1.0. Here is the ten-minute quay.io bridge that restores redeploys, a comparison of RustFS, Garage, and SeaweedFS, and an mc mirror runbook for moving your buckets.

self-hosting
decentralized storage
tutorial
Running Your First StorageVersionMigration: What Kubernetes v1.37's GA Migration API Changes in Your Cluster API Upgrade Runbook
·Dora Noda·10 min

Running Your First StorageVersionMigration: What Kubernetes v1.37's GA Migration API Changes in Your Cluster API Upgrade Runbook

Kubernetes v1.37 turned storage version migration into a stable, always-on API. Here is how to run your first migration — Secrets re-encryption, CRD version collapse, and per-resource status checks — and where it slots into a Cluster API fleet's upgrade runbook.

Kubernetes
self-hosting
tutorial
engineering
Heroku to Linode + Kamal in Production: A Real Team's Terraform-Retiring Migration, Step by Step
·Dora Noda·12 min

Heroku to Linode + Kamal in Production: A Real Team's Terraform-Retiring Migration, Step by Step

A production Rails site left Heroku for Linode plus Kamal in three days across four tracked issues, ending with the Heroku provider deleted from Terraform. This walkthrough covers each cutover step, the before/after bill, and what the team's no-fallback decision costs the week DNS flips.

self-hosting
PaaS
migration
cost-optimization
+1
Your Operator's /readyz Is Lying: The controller-runtime Cache-Sync Trap Behind Green Dashboards and Stalled Reconciles
·Dora Noda·8 min

Your Operator's /readyz Is Lying: The controller-runtime Cache-Sync Trap Behind Green Dashboards and Stalled Reconciles

A kubebuilder operator's scaffolded readyz check returns 200 before the informer cache syncs, before leader election completes, and before webhooks serve. The three readiness checks that close the gap, the RBAC stall that makes them necessary, and the audit to run this week.

Kubernetes
engineering
infrastructure
tutorial
GitHub's Egress Firewall Won't Cover Your Self-Hosted Runners — Here's the Blueprint That Will
·Dora Noda·11 min

GitHub's Egress Firewall Won't Cover Your Self-Hosted Runners — Here's the Blueprint That Will

GitHub's 2026 roadmap adds a root-proof egress firewall for hosted runners only. Replicate that guarantee on self-hosted ARC runners with ephemeral pods, default-deny egress, Cilium DNS allowlists, and SHA-pinned actions.

cybersecurity
Kubernetes
developer tools
self-hosting
+1
Showing 1–9 of 21 posts