DevOps. Self-hosted. Security.
RSS FeedNotes on DevOps, infrastructure, self-hosting and cybersecurity — practical guides from real-world operations.
Read the posts below or head over to the About page.
Recent Posts
-
SPIFFE/SPIRE: cryptographic workload identity instead of static secrets
SPIFFE standardizes workload identity through short-lived SVID certificates, and SPIRE — its reference implementation — issues and rotates them via two-tier attestation (node + workload) with no pre-shared secret anywhere. We break down how it differs from external-secrets-operator, how federation works across clusters, and deploy SPIRE to fetch a real X.509-SVID for a test pod.
-
SpinKube: running WebAssembly workloads on Kubernetes without a custom runtime
SpinKube schedules WebAssembly modules as regular pods — the same kubectl apply, the same HPA, but startup in single-digit milliseconds with no container warm-up. We break down the containerd-shim-spin architecture, install the SpinKube operator, deploy a SpinApp next to a regular Deployment and measure the difference — while being honest about which workloads WASM still isn't a fit for.
-
ValidatingAdmissionPolicy: moving admission control into the API server with CEL
Kyverno 1.17 deprecates classic ClusterPolicy in favor of CEL-native ValidatingPolicy, with removal planned for v1.20. ValidatingAdmissionPolicy has been stable since Kubernetes 1.30 and runs CEL directly inside kube-apiserver — no webhook, no network hop, no separate pod. We break down the CEL expression model, migrate a real policy, and measure the latency before/after.
-
Renovate: dependency updates that don't drive you mad
Renovate instead of a flood of one-off PRs per dependency: packageRules grouping, schedules, automerge with a cooldown, and a self-hosted GitLab CI run. We cover the flow, the config, and where the automerge trust boundary sits.