Blog posts about devops

K8s-native Dev. (Part 2): AWS EKS & Skaffold

Skaffold is an open source project from Google handling the workflow for building, pushing and deploying your application to Kubernetes. It's client-side only, with no on-cluster component and has a highly optimized tight inner loop, giving you instant feedback while developing.

Read More

Security Scanning Built Into Your Pipeline: GitLab Ultimate in Practice

SQL injection in the application code, an RSA private key in version control, 5941 vulnerabilities in the base image. These are not hypothetical risks — they are findings from a real pipeline run. In this post, we show how GitLab Ultimate catches all of them automatically, across seven scanner types, without a single third-party tool.

Read More

Locking Down a Fresh Ubuntu Box: SSH, netfilter, Fail2Ban & a Deploy User That Can't Do Too Much

You just booted a fresh Ubuntu VPS and it has a public IP, a root password and nothing else standing between it and the internet's background noise. Here's the hardening pass I run on every box before it does anything useful: SSH locked to keys, netfilter on IPv4 and IPv6, Fail2Ban, automatic security patches and a deploy user that can restart exactly three things.

Read More

K8s-native Dev. (Part 1): Mocking APIs

Consider the following: You're migrating some microservices to Kubernetes with certain API dependencies, which are not *yet* reachable. There can be plenty of reasons for that: Some dependent services run in a highly secured data center on-prem and are not yet migrated, some APIs may not be fully developed yet.

Read More