
This is a follow up to Private Networking on Hetzner Cloud with Tailscale
66 links

This is a follow up to Private Networking on Hetzner Cloud with Tailscale

This is a follow up to Why I Built My Own Kubernetes Cluster

Open-source observability platform built on OpenTelemetry. Collect, visualize, and analyze distributed traces, logs, and metrics from your services with AI-powered diagnostics.

Mon cheminement pour autoscaler un cluster OVH déployé via la Cluster API, en utilisant Karpenter et son provider cluster-api, avec MKS comme cluster de management.

Tu as un homelab Proxmox, tu as entendu parler de Talos Linux et de Cilium, tu as même développé ton propre module Terraform pour automatiser tout ça. Mais entre le moment où tu te dis “je vais créer un petit cluster K8s” et le moment où tu as un cluster fonctionnel avec kubectl get nodes, il y a tout un chemin de commandes à taper, de fichiers à éditer, de tokens à générer.

I created and maintain Luxury Yacht, a desktop app for managing Kubernetes clusters. Think Headlamp, Lens, and k9s. It's that kind of app. Luxury Yacht is a ...

Recently, a friend of mine asked me what resources I'd recommend to start learning about Kubernetes. He was a victim of the layoffs that seem to be so prevalent right now and has experience as a classic SysOps / SysAdmin engineer but no expose to Kubernetes yet and wanted to learn to help improve his job-hunting prospects.
I wasn't sure what to recommend at first, it's been a long time since I was learning Kubernetes for the first time and wasn't sure what was still useful and relevant but what follows is what I ended up sharing with him, and now with all of you.

So I've been job hunting lately. Reading job postings, doing interviews, talking to engineering teams at like a dozen companies. And I noticed...

I've used Kubernetes for years, and it was time to make the TUI suitable for me. Inspired by k9s and lens.

Open-source Kubernetes UI: topology, events, Helm, GitOps, traffic flows, OpenCost, cluster audit, image filesystem viewer, and MCP for AI agents. Single Go binary, Apache 2.0, no account required.

VCF 9.1 adds VKS multi-network support allowing users to separate management, storage, and data traffic per node.

XO 6.5 is out: QCOW2 GA, bidirectional replication, traffic rules on networks and VIFs, richer Prometheus metrics, plus a fresh Kubernetes CSI release and a Cluster API teaser.

For a long time I wanted a piece of software that usedFirecrackerto create MicroVMs on my Linux hosts. It seemed like it would be really useful for vulnerability research and testing features that wer

When you delete a Kubernetes (K8s) cluster, you can sometimes end up with orphaned disks (persistent volumes) on your datastore. It can be difficult to identify them and they can take up unnecessar…

My VCF homelab runs on GMKTec K8 Plus nodes which have AMD Ryzen CPU with 16 threads – which means the biggest VM that can be powered on can have only 16 vCPUs. However VCF Automation runs on…

Comment Mise arrive à résoudre les problèmes de Krew et du tooling interne des équipes SRE en général

⚡ LFK is a lightning-fast, keyboard-focused, yazi-inspired terminal user interface for navigating and managing Kubernetes clusters. Built for speed and efficiency, it brings a three-column Miller c...

This technical session covers what's new in vSphere as part of VMware Cloud Foundation 9.1. Féidhlim O'Leary walks through lifecycle management, VM management, and Kubernetes enhancements. Dave Morera covers workload acceleration including memory tiering, vMotion encryption offload, NUMA scheduling improvements, and expanded GPU support. Bob Plankers closes with platform security topics.

Comment Kloak intercepte le trafic TLS de vos pods au niveau kernel avec des uprobes eBPF pour injecter vos secrets de façon transparente, sans modifier vos applications ni déployer de sidecar.

L’infographie qui m’a trigger Depuis quelques jours, les infographies se suivent (et se ressemblent) sur Linkedin. Kubernetes 1.36 est sorti et une des features qui fait le plus parler, c’est la sortie en GA des UserNamespaces.\nC’est un sujet que je suis depuis 2018 (talk The Route to rootless container à la kubecon EU de 2018) donc je peux dire que je suis content de voir l’aboutissement de ce long chemin. Cependant, je suis “profondément choqué” de voir la façon dont c’est présenté sur LinkedIn, visiblement par des gens qui n’ont aucune idée de comment ça fonctionne (et qui probablement, s’en fichent).\n

XO 6.4 is out: RBAC/ACL v2 arrives in the REST API, better MCP support, XO 6 gains more XO 5 features, plus Kubernetes CSI v0.2.0 and new DevOps updates.

Comment j'utilise Mise au quotidien pour gérer mes versions d'outils, mes variables d'environnement et mes secrets sur plusieurs projets

The blog outlines deploying the vSphere Supervisor on a vSAN Stretched Cluster, essential for maintaining high availability and disaster recovery of Kubernetes workloads. It details prerequisites, …

Nous exploitons déjà depuis plus de deux ans un cluster Kubernetes basé sur un empilement très complexe de couches OpenShift, mais aussi vSphere/VSAN/NSX-T, qui apporte un niveau de sécurité élevé avec le CNI Antrea (qui s’occupe du réseau du cluster Kube). Cela nécessite aussi un niveau d’expertise globalement très élevé, sans même parler du prix de ces couches…

Talos Linux ne supporte pas nativement l'authentification OIDC. Voici comment j'ai construit talosctl-oidc, un serveur d'échange de certificats éphémères qui ponte SSO et mTLS.

A practical field-focused walkthrough of deploying a Supervisor in VMware Cloud Foundation 9, with emphasis on networking design, VPC versus NSX Classic, Tier-0 architecture, routing, VKS operations, and preparing the platform for namespaces and Supervisor Services.

CRD ou APIService ? Deux façons d'étendre l'API Kubernetes avec des philosophies radicalement différentes. On compare les deux avec des exemples concrets !

A recent independent study, conducted by Principled Technologies, compared Kubernetes pod density and pod readiness speed between two environments – VMware Cloud Foundation (VCF) 9.0 with vSphere Kubernetes Service (VKS) 3.6 and Red Hat OpenShift 4.21 on bare metal. In this blog, we take a look at how the results of that independent study conclude … Continued

Why VMware VKS Is a Stronger Enterprise Choice Than KubeVirt | vmtechie.blog KubeVirt is a capable open-source project and a legitimate choice in the right context. But when the workload is enterpr…

Creating Talos Kubernetes cluster using VMware.

Get early access to our brand-new v4 APIs and SDKs! Covering Python, Java, Javascript, and Go there's an SDK for many of our users, along with client REST APIs for those languages that don't yet have an official SDK.

VCF Automation (VCFA) provides very easy way to deploy vSphere Kubernets Service (VKS) Clusters in a multitenant environments. This can be done via UI, Kubernetes API or CLI. This is in my opinion …

We built an open-source proxy that adds tenant isolation to Prometheus, Loki, and Tempo by rewriting queries based on user identity.

Learn how requests flow through the Kubernetes API server — from authentication to etcd storage.

A quick introduction to VCF 9 Automation in All Apps mode

Découvrez comment déployer un cluster Kubernetes entièrement en IPv6 avec Talos OS.

I recently ran into a claim: Docker Compose is outdated and K3s is the king for my 1Gb VPS. At the same time, docker-compose.py is effectively deprecated, with Compose now shipped as a built-in docker compose command. That alone is not a problem, but it raised a reasonable question: has the role of Docker Compose actually changed, or is this just noise from the Kubernetes church?

vSphere Zones in VMware Cloud Foundation (VCF) 9.0 have been enhanced to offer greater flexibility in resource consumption and isolation for both vSphere Supervisor Control Plane VMs (Management), …

Ten field-tested Kubernetes capabilities - topology spread, disruption budgets, admission policies, autoscaling guardrails, and more - that most teams ignore but instantly boost resilience, velocity.

PVMSS is a lightweight, self-service web portal for Proxmox Virtual Environment. It allows users to create and manage virtual machines without needing direct access to the Proxmox web UI. - julienh...

The Grafana Stack can be an incredible powerful monitoring solution, but through my experience I found out how maintenance intensive it is and how uncertain the…

✳️ IntroductionWith the release of VMware Cloud Foundation 9 (VCF 9), VMware has introduced a major architectural evolution—consolidating Day-2 operations, automation, and lifecycle tasks into VCF Operations (VCF OPS).One of the most notable changes is how Workload Domains (WLDs) are created. Previously, administrators used the SDDC Manager GUI to provision a new WLD. In VCF 9, this process now happens exclusively through VCF OPS, offering more flexibility, automation, and integration with moder

We saved 76% on our cloud bills while tripling our capacity by migrating to Hetzner from AWS and DigitalOcean. Digital Society is a not-for-profit cooperative helping you get your projects off the ground and realise the value of your data.

DSM 9.0.1 aligns with RBAC features that are already in VCF Automation, specifically around multi-tenancy controls

Podman Desktop - An open source graphical tool for developing on containers and Kubernetes

Image Factory generates customized Talos Linux images based on configured schematics.

Real-time monitoring for Proxmox, Docker, and Kubernetes with AI-powered insights, smart alerts, and a beautiful unified dashboard - rcourtman/Pulse

Dive deep into Kubernetes Security Contexts and learn how to manage security settings for your pods and containers.

how to add read-write-many (RWX) volumes to a Pod in VKS which were initially created by the Volume Service

On a few occasions, I have noticed that after the initial deployment of VMware Cloud Foundation (VCF) 9.0 that also includes VCF Automation (VCFA), the VCFA VM can experience a sustained CPU usage …

I recently deployed the latest release of VMware Data Services Manager (DSM) 9.0 in my VMware Cloud Foundation (VCF) 9.0 lab to explore the new integration with VCF Automation (VCFA), allowing orga…

This post is part of a short series that builds on our minimal VMware Cloud Foundation (VCF) 9.0 deployment (2x Minisforum MS-A2) and showcases how to fully leverage the exciting new capabilities i…

In this post, I will show you the steps to create a static volume via the Volume Service, and then create the appropriate manifests in your VKS cluster to make the volume available to Pods running on your cluster.

With the improvements of VCF Automation 9 it now includes a new model which supports developer consumer use cases. In context of the tenancy architecture, it provides 2 different types of organizations: VM-Apps-OrgAn organization which is almost identical to what is known from 8.x versions of Aria Automation. Its main purpose is to support VM-based… Read More »

Octelium is a unified zero trust architecture (ZTA) that is built to be generic enough to operate as a zero-config remote access VPN, a Zero Trust Network…

The purpose of this website is to provide an overview of various Kubernetes networking components with a specific focus on exactly how they implement the required functionality.
The information here can be used for educational purposes, however, the main goal is to provide a single point of reference for designing, operating and troubleshooting cluster networking solutions.
Warning This is not a generic Kubernetes learning resource. The assumption is that the reader is already familiar with basic concepts and building blocks of a Kubernetes cluster – pods, deployments, services.

With additional Kubernetes mode!

Kubetail is a real-time logging dashboard for Kubernetes. View container logs in a terminal or a browser. Run anywhere - desktop, cluster, docker.

A satellite project of labs.iximiuz.com - an indie learning platform to master Linux, Containers, and Kubernetes the hands-on way 🚀

Secure access / PAM for your internal SSH, HTTPS, MySQL, Postgres and Kubernetes servers with SSO and RBAC.

Introduction K8s is already a crucial part in the VMware ecosystem for many years and the level of integration in other products like NSX and AVI changed a lot in the past. That is also true for the naming like “vSphere with Tanzu”, “vSphere IaaS” and “VKS” and perhaps more changes in the future. For this blog post we will bring some spotlight to the integration for VKS with NSX VPCs, which is from my point of view a great enhancement from tenancy point of view.

Dans cet article, j’expose 3 problèmes que j’ai rencontré dans ma carrière avec le DNS sur Kubernetes. Le 3eme est d’ailleurs un bug non corrigé à ce jour sur kube-proxy en mode iptables, et impacte n

A deep dive into KubeVirt for vSphere admins. Learn VM creation, storage, networking, and operations mapped to familiar VMware concepts.

Minimalist doesn't mean Talos isn't extensible. Let's dive into the topic of extensions to customize and adapt it to our needs.

Introduction to the deploy.sh Script The deploy.sh script is a fundamental tool in the VMware Aria Automation ecosystem (formerly vRealize Automation), responsible for deploying, configuring, and managing all components of this advanced environment. Located in the /opt/scripts/ directory on the Aria Automation virtual machine, it serves as the central orchestration point for the entire system....
![Screenshot of [NSX Intelligence] Problème lors du déploiement de NSX Application Platform (NAPP) sous RKE2](/screenshots/nsx-intelligence-probleme-lors-du-deploiement-de-nsx-applica.png)
Lors d’une nouvelle installation de NSX Intelligence (ou plutôt Security Intelligence maintenant), j’ai rencontré un petit problème inattendu !