How to use Docker Security Scan Locally
How the new Docker security tool Docker Scan helps to push left and find bugs before they hit productionhttps://brianchristner.io/how-to-use-docker-scan
Google Kubernetes Engine (GKE) Module
This repo contains a Terraform module for running a Kubernetes cluster on Google Cloud Platform (GCP) using Google Kubernetes Engine (GKE).https://github.com/gruntwork-io/terraform-google-gke
TimescaleDB 2.0: A multi-node, petabyte-scale, completely free relational database for time-series
https://blog.timescale.com/blog/timescaledb-2-0-a-multi-node-petabyte-scale-completely-free-relational-database-for-time-series
https://blog.timescale.com/blog/timescaledb-2-0-a-multi-node-petabyte-scale-completely-free-relational-database-for-time-series
Platforms on k8s with Golang - Watch any CRD
https://hackernoon.com/platforms-on-k8s-with-golang-watch-any-crd-0v2o3z1q
https://hackernoon.com/platforms-on-k8s-with-golang-watch-any-crd-0v2o3z1q
kubergrunt
kubergrunt is a standalone go binary with a collection of commands that attempts to fill in the gaps between Terraform, Helm, and Kubectl for managing a Kubernetes Cluster.https://github.com/gruntwork-io/kubergrunt
How to Analyze a PostgreSQL Crash Dump File
https://www.highgo.ca/2020/11/07/how-to-analyze-a-postgresql-crash-dump-file
https://www.highgo.ca/2020/11/07/how-to-analyze-a-postgresql-crash-dump-file
Terratest
Terratest is a Go library that makes it easier to write automated tests for your infrastructure code. It provides a variety of helper functions and patterns for common infrastructure testing tasks, including:https://github.com/gruntwork-io/terratest
- Testing Terraform code
- Testing Packer templates
- Testing Docker images
- Executing commands on servers over SSH
- Working with AWS APIs
- Working with Azure APIs
- Working with GCP APIs
- Working with Kubernetes APIs
- Testing Helm Charts
- Making HTTP requests
- Running shell commands
- And much more
Traefik: canary deployments with weighted load balancing
https://iximiuz.com/en/posts/traefik-canary-deployments-with-weighted-load-balancing
https://iximiuz.com/en/posts/traefik-canary-deployments-with-weighted-load-balancing
kubei
Kubei is a vulnerabilities scanning tool that allows users to get an accurate and immediate risk assessment of their kubernetes clusters. Kubei scans all images that are being used in a Kubernetes cluster, including images of application pods and system pods. It doesn’t scan the entire image registries and doesn’t require preliminary integration with CI/CD pipelines.https://github.com/Portshift/Kubei
Running Percona Kubernetes Operator for Percona XtraDB Cluster with Kata Containers
https://www.percona.com/blog/2020/11/04/running-percona-kubernetes-operator-for-percona-xtradb-cluster-with-kata-containers
https://www.percona.com/blog/2020/11/04/running-percona-kubernetes-operator-for-percona-xtradb-cluster-with-kata-containers
Bare Metal Operator
The Bare Metal Operator implements a Kubernetes API for managing bare metal hosts.https://github.com/metal3-io/baremetal-operator
Correlation in Latency Analysis
This article was my response to Amazon’s writing assessment when I was interviewed.https://rakyll.medium.com/correlation-in-latency-analysis-419357b93287
11 facts about real-world container use
Containers enable organizations to accelerate delivery cycles and rapidly scale their operations to meet the demands of today's fast-paced market. As more organizations migrate their workloads to containers, the container ecosystem is expanding and evolving to accommodate these increasingly dynamic environments. In this report, we examined more than 1.5 billion containers run by tens of thousands of Datadog customers to understand how image registries, service meshes, networking, and other technologies are being used in real-world container environments.https://www.datadoghq.com/container-report
PostgreSQL Benchmarks: Apple ARM M1 MacBook Pro 2020
https://info.crunchydata.com/blog/postgresql-benchmarks-apple-arm-m1-macbook-pro-2020
https://info.crunchydata.com/blog/postgresql-benchmarks-apple-arm-m1-macbook-pro-2020
Series: Deploying ASP.NET Core applications to Kubernetes
https://andrewlock.net/series/deploying-asp-net-core-applications-to-kubernetes
Part 1 - An Introduction to Kubernetes: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-1-an-introduction-to-kubernetes
Part 2 - Configuring resources with YAML manifests: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-2-configuring-resources-with-yaml-manifests
Part 3 - An introduction to deploying applications with Helm: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-3-deploying-applications-with-helm
Part 4 - Creating a Helm chart for an ASP.NET Core app: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-4-creating-a-helm-chart-for-an-aspnetcore-app
Part 5 - Setting environment variables for ASP.NET Core apps in a Helm chart: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-5-setting-environment-variables-in-a-helm-chart
Part 6 - Adding health checks with Liveness, Readiness, and Startup probes: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-6-adding-health-checks-with-liveness-readiness-and-startup-probes
Part 7 - Running database migrations when deploying to Kubernetes: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-7-running-database-migrations
Part 8 - Running database migrations using jobs and init containers: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-8-running-database-migrations-using-jobs-and-init-containers
Part 9 - Monitoring Helm releases that use jobs and init containers: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-9-monitoring-helm-releases-that-use-jobs-and-init-containers
Part 10 - Creating an 'exec-host' deployment for running one-off commands: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-10-creating-an-exec-host-deployment-for-running-one-off-commands
Part 11 - Avoiding downtime in rolling deployments by blocking SIGTERM: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-11-avoiding-downtime-in-rolling-deployments-by-blocking-sigterm
Part 12 - Tips, tricks, and edge cases: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-12-tips-tricks-and-edge-cases
https://andrewlock.net/series/deploying-asp-net-core-applications-to-kubernetes
Part 1 - An Introduction to Kubernetes: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-1-an-introduction-to-kubernetes
Part 2 - Configuring resources with YAML manifests: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-2-configuring-resources-with-yaml-manifests
Part 3 - An introduction to deploying applications with Helm: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-3-deploying-applications-with-helm
Part 4 - Creating a Helm chart for an ASP.NET Core app: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-4-creating-a-helm-chart-for-an-aspnetcore-app
Part 5 - Setting environment variables for ASP.NET Core apps in a Helm chart: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-5-setting-environment-variables-in-a-helm-chart
Part 6 - Adding health checks with Liveness, Readiness, and Startup probes: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-6-adding-health-checks-with-liveness-readiness-and-startup-probes
Part 7 - Running database migrations when deploying to Kubernetes: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-7-running-database-migrations
Part 8 - Running database migrations using jobs and init containers: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-8-running-database-migrations-using-jobs-and-init-containers
Part 9 - Monitoring Helm releases that use jobs and init containers: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-9-monitoring-helm-releases-that-use-jobs-and-init-containers
Part 10 - Creating an 'exec-host' deployment for running one-off commands: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-10-creating-an-exec-host-deployment-for-running-one-off-commands
Part 11 - Avoiding downtime in rolling deployments by blocking SIGTERM: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-11-avoiding-downtime-in-rolling-deployments-by-blocking-sigterm
Part 12 - Tips, tricks, and edge cases: https://andrewlock.net/deploying-asp-net-core-applications-to-kubernetes-part-12-tips-tricks-and-edge-cases
kraken
Kraken is a P2P-powered Docker registry that focuses on scalability and availability. It is designed for Docker image management, replication, and distribution in a hybrid cloud environment. With pluggable backend support, Kraken can easily integrate into existing Docker registry setups as the distribution layer.https://github.com/uber/kraken
Kraken has been in production at Uber since early 2018. In our busiest cluster, Kraken distributes more than 1 million blobs per day, including 100k 1G+ blobs. At its peak production load, Kraken distributes 20K 100MB-1G blobs in under 30 sec.
Network-layer DDoS attack trends for Q3 2020
https://blog.cloudflare.com/network-layer-ddos-attack-trends-for-q3-2020
https://blog.cloudflare.com/network-layer-ddos-attack-trends-for-q3-2020
Getting to the Core: Benchmarking Cloudflare’s Latest Server Hardware
https://blog.cloudflare.com/getting-to-the-core
https://blog.cloudflare.com/getting-to-the-core
Не хотелось бы оказаться Наташей в подобной ситуации? Как многие уже знают, этой осенью «Флант» представил свой Managed Kubernetes. Теперь можно получить кластеры K8s как услугу, размещая их в любой удобной инфраструктуре: у любимых российских и зарубежных облачных провайдеров, на своем железе (on-premises) и даже комбинируя эти варианты.
Все эти кластеры настраиваются согласно лучшим практикам известных специалистов и поставляются в по-настоящему готовом виде: внутри не просто «голый» Kubernetes, а интегрированная платформа, чтобы сразу запускать приложения в production. Продуманные (преднастроенные) метрики Prometheus и графики Grafana, автомасштабирование, усовершенствованный Nginx Ingress и балансировка трафика, автовыпуск SSL-сертификатов, веб-панель Kubernetes Dashboard… и вот это всё.
Плюс, конечно, поддержка от инженеров, которые специализируются именно на этом (а не ищут новую возможность продать свои облачные ресурсы). Всё это — по очень разумной цене, доступной не только для enterprise, но и небольшим компаниям и стартапам, уже понимающим, как им поможет Kubernetes.
Подробности (основные компоненты кластеров, онлайн-калькулятор, тарифы и уровни SLA) см. на сайте компании.
Все эти кластеры настраиваются согласно лучшим практикам известных специалистов и поставляются в по-настоящему готовом виде: внутри не просто «голый» Kubernetes, а интегрированная платформа, чтобы сразу запускать приложения в production. Продуманные (преднастроенные) метрики Prometheus и графики Grafana, автомасштабирование, усовершенствованный Nginx Ingress и балансировка трафика, автовыпуск SSL-сертификатов, веб-панель Kubernetes Dashboard… и вот это всё.
Плюс, конечно, поддержка от инженеров, которые специализируются именно на этом (а не ищут новую возможность продать свои облачные ресурсы). Всё это — по очень разумной цене, доступной не только для enterprise, но и небольшим компаниям и стартапам, уже понимающим, как им поможет Kubernetes.
Подробности (основные компоненты кластеров, онлайн-калькулятор, тарифы и уровни SLA) см. на сайте компании.
flant.ru
DevOps as a Service: обслуживание под ключ / Услуги / Флант
DevOps as a Service от компании Флант. Поддерживаем инфраструктуру, создаем комфортную среду для разработки, внедряем лучшие DevOps-практики.