#K8s

Anyone know if `system:apiserver` user should be allowed `create` action on `nodes/proxy`?

It's supposed to be the well-known user for the API server as a client to the kubelet (see source link) but it sure seems to be failing. I'd prefer not to just give system:masters

github.com/kubernetes/kubernet

`Internal error occurred: unable to upgrade connection: Forbidden (user=system:apiserver, verb=create, resource=nodes, subresource(s)=[proxy])`

#Kubernetes #k8s #K8sAdmin #KubernetesAdmin

2025-06-20
2025-06-20

It took a few hours, but I've managed to move one of my clients from DigitalOcean to Scaleway.

Perhaps this is also a testiment that Kubernetes is truly cloud agnostic and makes these things easy.

#LessUSMoreEU #kubernetes #k8s #WebDev

Ismail Kovvuruismailkovvuru
2025-06-20

Boosting Kubernetes Performance by 60% with externalTrafficPolicy & sessionAffinity
Learn how fine-tuning just two settings can drastically reduce latency & improve throughput.
🔬 Includes benchmarks, diagrams & when to apply (or avoid) these options.
🔗 medium.com/@ismailkovvuru/boos

2025-06-20

Just had a power outage which took down my lab. Recovery was...fun 😅:

- Pi-hole was down because it couldn't locate its secret.
- My secrets are managed by External Secrets, and that
was failing because it couldn't resolve the dns name for Infisical because.... Pi-hole was down

2025-06-19

Love these scenarios (from a Kubernetes, CKAD, certification sample question). Adding a little bit of realism, you know?

"Listen up rookie, Team SUN ☀️ needs FOUR Nginx servers exposed on port 9999 STAT! No we don't need a volume! Lets get those "Welcome to nginx!"-pages rolling!!"

#Kubernetes #K8s #CKAD #Certification

Preview Question 2
Solve this question on instance: ssh ckad9043

Team Sun needs a new Deployment named sunny with 4 replicas of image nginx:1.17.3-alpine in Namespace sun. The Deployment and its Pods should use the existing ServiceAccount sa-sun-deploy.

Expose the Deployment internally using a ClusterIP Service named sun-srv on port 9999. The nginx containers should run as default on port 80. The management of Team Sun would like to execute a command to check that all Pods are running on occasion. Write that command into file /opt/course/p2/sunny_status_command.sh. The command should use kubectl.
2025-06-19

Dur de choisir son ingress-controller, entre @projectcontour @traefik @thekonginc @apacheapisix @ingressnginx… et j'en passe!

Vient découvrir la #GatewayAPI, interface officielle de #k8s pour les contrôler tous!

link.davinkevin.fr/GwAPI-rivie

Hâte de vous retrouver à @rivieradev

Pont qui se scinde en plusieurs branches
2025-06-19

Vault8s: доставляем секреты из HashiCorp Vault в Kubernetes

Мы все знаем, что Hashicorp Vault — это фактический стандарт для хранения секретов, а Kubernetes — для размещения приложений. Но как подружить их вместе? Существует множество инструментов для интеграции Vault с Kubernetes, и каждый из них имеет свои плюсы и минусы. Как выбрать подходящий? В этой статье, созданной по мотивам выступления на DevOpsConf’25, вы узнаете о самых популярных инструментах доставки секретов из Hashicorp Vault в Kubernetes, таких как External Secrets Operator, Hashicorp Vault Secrets Operator, Hashicorp Vault Agent Injector, Hashicorp Vault CSI Provider, Bank Vaults-Vault Secrets Webhook. Для каждого инструмента будет приведён пример настройки, объяснено, как именно секрет попадает в приложение, а также мы с вами сравним их с точки зрения ротации секретов и удобства использования. Меня зовут Михаил Кажемский , я Lead DevOps из Hilbert Team . Я в IT уже больше 10 лет и пришёл в DevOps из разработки, поэтому побывал по обе стороны баррикад. Соавтор ряда курсов для инженеров на Яндекс Практикум по направлениям DevOps, Security и Data. Hilbert Team — провайдер IT-решений для крупного и среднего бизнеса в области облачных технологий, DevOps, DevSecOps, DataOps, MLOps и FinOps. Партнёр Yandex Cloud со специализацией Yandex Cloud Professional по направлениям DevOps и Data Platform.

habr.com/ru/companies/oleg-bun

#secrets #hashicorp_vault #kubernetes #vault #k8s #secretsmanagement #External_Secrets_Operator #HashiCorp_Vault_Secrets_Operator #HashiCorp_Vault_CSI_Provide #HashiCorp_Vault_Agent_Injector

Kubernetes Releasesk8s_releases@k8s.social
2025-06-18

New Kubernetes Release

:kubernetes: Kubernetes v1.30.14 :kubernetes:

github.com/kubernetes/kubernet

#Kubernetes #k8s #kube

Kubernetes Releasesk8s_releases@k8s.social
2025-06-18

New Kubernetes Release

:kubernetes: Kubernetes v1.31.10 :kubernetes:

github.com/kubernetes/kubernet

#Kubernetes #k8s #kube

Kubernetes Releasesk8s_releases@k8s.social
2025-06-18

New Kubernetes Release

:kubernetes: Kubernetes v1.32.6 :kubernetes:

github.com/kubernetes/kubernet

#Kubernetes #k8s #kube

Kubernetes Releasesk8s_releases@k8s.social
2025-06-18

New Kubernetes Release

:kubernetes: Kubernetes v1.33.2 :kubernetes:

github.com/kubernetes/kubernet

#Kubernetes #k8s #kube

Arnar Ingasonarnar@floss.social
2025-06-18

This was revealed to me in a dream

#Kubernetes #k8s

"there's no difference" Office meme but it's "the pod is the atomic unit of scaling" and "the mitochondria is the powerhouse of the cell"

Kubernetes going Discord lol

> ... they have already explored what a Kubernetes Discord would look like. Discord would allow us to implement new tools and integrations which would help the community, such as GitHub group membership synchronization.

kubernetes.io/blog/2025/06/16/

#k8s #Kubernetes

The CNCF Projects Staff have proposed that our community look at migrating to Discord. Because of existing issues where we have been pushing the limits of Slack, they have already explored what a Kubernetes Discord would look like. Discord would allow us to implement new tools and integrations which would help the community, such as GitHub group membership synchronization. The Steering Committee will discuss and decide on our future platform.
Kubernetes Releasesk8s_releases@k8s.social
2025-06-16

New Kubernetes Alpha Release

:kubernetes: Kubernetes v1.34.0-alpha.1 :kubernetes:

github.com/kubernetes/kubernet

#Kubernetes #k8s #kube

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst