DevOps&SRE Library
19.3K subscribers
427 photos
2 videos
2 files
5.25K links
Библиотека статей по теме DevOps и SRE.

Реклама: @ostinostin
Контент: @mxssl

РКН: https://www.gosuslugi.ru/snet/67704b536aa9672b963777b3
Download Telegram
Upgrade AWS CSI Drivers in your Multi-Tenant Kubernetes Cluster

Since 2023, AWS CSI drivers can be misused to bypass node isolation in multi-tenant clusters.


https://soc-inspiration.medium.com/upgrade-aws-csi-drivers-in-your-multi-tenant-kubernetes-cluster-a2cbc47e47f8
CoreDNS in OpenShift

Understanding CoreDNS, Forwarders, ndots, and Name Resolution Flow


https://medium.com/@arjun0451/coredns-in-openshift-01f3142bde25
crd-bootstrap

Continuously reconcile CRDs in the cluster with template validation before apply.


https://github.com/Skarlso/crd-bootstrap
uncloud

A lightweight tool for deploying and managing containerised applications across a network of Docker hosts. Bridging the gap between Docker and Kubernetes


https://github.com/psviderski/uncloud
dockadvisor

Lightweight Dockerfile linter that helps you write better Dockerfiles. Get instant feedback with quality scores, security checks, and 60+ best practice rules.


https://github.com/deckrun/dockadvisor
kaniop

Kaniop is a Kubernetes operator for managing Kanidm.

Kanidm is a modern, secure identity management system that provides authentication and authorization services with support for POSIX accounts, OAuth2, and more.


https://github.com/pando85/kaniop
kured

Kured (KUbernetes REboot Daemon) is a Kubernetes daemonset that performs safe automatic node reboots when the need to do so is indicated by the package management system of the underlying OS.


https://github.com/kubereboot/kured
tns-csi

A Kubernetes CSI (Container Storage Interface) driver for TrueNAS Scale 25.10+.


https://github.com/fenio/tns-csi
witr (Why Is This Running?)

witr helps inspect why processes are running by PID, name, or port with a terminal UI.


https://github.com/pranshuparmar/witr
Git's Magic Files

A practical guide to Git control files like .gitignore and .gitmessage and how they affect behavior.


https://nesbitt.io/2026/02/05/git-magic-files.html
Terraform, Feature Flags and Configurability

Terraform has been my bread and butter for the past few years as the tool for Infrastructure as Code. I’ve dealt with a variety of patterns while working with Terraform, and noticed one pattern that is rarely discussed, but super useful. Feature flags are a way to write code that can behave differently based on how we configure things, and is as old as writing code for computers. It gives the author of the code flexibility to have different implementations, safely migrate systems from one approach or capability to a new one and choose behaviour based on the target context. Mature codebases find tooling or affordances that give them the ability to evolve and adapt, and feature flags are one pattern to achieve that. However, the public internet has very few examples about how to achieve this for Infrastructure as Code tools, including Terraform.


https://ninad.pundaliks.in/blog/2026/02/terraform-and-feature-flags
Kubernetes egress control with squid proxy

Shows how to enforce and observe Kubernetes egress traffic with Squid plus NetworkPolicy without adding a service mesh.


https://interlaye.red/kubernetes_002degress_002dsquid.html
How We Turned a Forced OS Migration into a 30% Infrastructure Reduction

Scout24 used an Amazon Linux 2 migration window to adopt Karpenter and cut EKS node count by about 30%.


https://scout24.medium.com/infinity-transformation-how-we-turned-a-forced-os-migration-into-a-30-infrastructure-reduction-1a41237307b8
Auto-scaling and Load-based Scaling

Explains reactive metric-based scaling versus scheduled scaling and where each approach fits.


https://blog.felipefr.dev/auto-scaling-and-load-based-scaling
rtk

CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies


https://github.com/rtk-ai/rtk
Integration testing with Kubernetes

Shows a Rust-based integration testing workflow on kind with Terraform and cleanup policies for parallel runs.


https://mikamu.substack.com/p/integration-testing-with-kubernetes
Vault: secure Kubernetes authentication with hashicorp Vault OIDC

Explains how to use Vault as an OIDC provider to replace static kubeconfig credentials with short-lived tokens.


https://phuchoang.sbs/posts/gitops-kubernetes-oidc-vault
Security Inside Kubernetes: Admission & Runtime Guardrails with Kyverno and KubeArmor

Covers layered Kubernetes security by combining Kyverno admission policies with KubeArmor runtime enforcement.


https://medium.com/globant/security-inside-kubernetes-admission-runtime-guardrails-with-kyverno-and-kubearmor-6d2f97264cbc