Spotlight
Mohamed Rasvi
This tutorial explains how to build a PCI-DSS focused GKE security framework using:
Rodrigo Campos Catelin
This article explains how Kubernetes user namespaces are implemented through pod UID/GID range allocation, idmap mounts, containerd, runc, and safeguards against privilege escalation.
Aakash Deep
This tutorial teaches how to build a production-like Kubernetes cluster on bare metal using Hyper-V VMs with MetalLB, Ingress NGINX, Longhorn storage, and HPA.
Lormenskyjean
This article explains how Falcon Shield extends CrowdStrike security into SaaS applications through posture management, identity governance, OAuth visibility, permission drift detection, and identity threat response.
Tools and utilities
Kubeswitch is a command-line tool designed to ease switching between different kubectl contexts.
K8up is a Kubernetes Operator that helps you:
PIQC scans Kubernetes clusters for vLLM and Ray Serve workloads, collects GPU, model, cost, utilization, KV cache, and waste facts, then prints an actionable inference cost report.
Kubeswitch is a command-line tool to ease switching between different kubectl contexts.
Okteto is a development platform that creates production-like Kubernetes environments with live code sync, allowing developers to code directly in clusters without local setup or Docker builds.
Events starting soon
August 6, 2026
This is a virtual event
This is a free event.
August 10, 2026
This is a virtual event
This is a free event.
August 13, 2026
Location: Hamburg, DE
This is a free event.
August 13, 2026
Location: Seattle, WA, USA
This is a free event.
August 15, 2026
Location: Rio de Janeiro, BR
This event requires an entrance fee
August 16, 2026
Location: Singapore, SG
This event requires an entrance fee
An unmaintained identity component can remain invisible until a routine Kubernetes upgrade turns it into an incident.
Fabián Sellés Rosa, Platform Engineer and Runtime Tech Lead at Adevinta, explains how his team moved from KIAM to EKS Pod Identities without discarding the security boundaries and application interface that their internal platform depended on.
In this interview:
Learn from production
Leo Blondel
This case study shows how a 3-person team built a Claude-based AI SRE that triages SigNoz alerts, checks Kubernetes, GitLab, logs, traces, and Slack, then ignores noise, escalates, or runs safe fixes.
Alex
This case study explains how one private container registry was shared across six AKS clusters in three regions.
It covers ACR geo-replication, image pull reliability, network access, permissions, and operational breakages.
Gleb Wam
This case study explains how a privileged Kubernetes pod with host access can lead to container escape, control plane disruption, service account theft, and cloud resource takeover.
Nick Georgiou
This case study explains how Plum migrated from ingress-nginx to kgateway and Gateway API in 12 weeks without production downtime.
It covers inventory, staging validation, parallel running, mTLS decisions, and custom observability.
Matching jobs
DevOps Engineer with Mark43
Salary: $155K to $170K a year
Location: remote from
Tech stack: Kubernetes, Docker, Terraform
DevOps Engineer with RobCo
Salary: US$70.74K to US$440K a year
Location: based in the office in Munich, DE
Tech stack: Kubernetes, AWS, Go, Python, Terraform, Datadog, Grafana, Prometheus
Site Reliability Engineer with MyFitnessPal
Salary: $120K to $165K a year
Location: remote from
Tech stack: Kubernetes, AWS, Docker, Go, Python, Typescript, Terraform, GitHub Actions, Datadog
AI Enterprise Technical Program Manager with Redhorse Corporation
Salary: $37 to $485.65K a year
Location: based in the office in Arlington, VA, USA
Tech stack: Kubernetes, AWS, Azure, Docker, Spark
Commercial Account Executive with Vantage
Salary: $100K to $200K a year
Location: remote from
Tech stack: Kubernetes, AWS, CircleCI, Datadog
Build something
Mohamed Rasvi
This tutorial explains how to build a PCI-DSS focused GKE security framework using Workload Identity, Secret Manager, NetworkPolicy, zero trust networking, Binary Authorization, audit logging, and secure access patterns.
Jinalpatel
This tutorial explains how to connect Kubernetes authentication to LDAP through Dex and OIDC.
It covers certificates, OpenLDAP, Dex Helm setup, API server trust, token claims, and RBAC group mapping.
Nahuel Aldrey
This tutorial shows how to automatically create and scale GitHub Actions runners on Kubernetes using Argo CD ApplicationSets that read config files from Git and deploy runner pods with custom resources and autoscaling.
Jeff Rescignano
This tutorial shows how to advertise Kubernetes LoadBalancer IPs to a LAN by configuring Cilium BGP Control Plane, an IP pool, Cilium BGP resources, and FRR on a UniFi Gateway.
Call for Papers closing soon
7
days
Location: Berlin, DE and virtual
Online & in-person conference organized by GitNation.
The conference starts on the 4 December 2026.
9
days
Location: Paris, FR
In-person conference organized by mate.dev.
The conference starts on the 3 December 2026.
10
days
Location: Buenos Aires, AR
In-person conference organized by Cloud Security Space.
The conference starts on the 9 October 2026.
10
days
Kubernetes Community Days Suisse Romande 2026
Location: Geneva, CH
In-person conference organized by KCD Suisse Romande.
The conference starts on the 9 December 2026.
23
days
This is a virtual event
Online conference organized by ScyllaDB.
The conference starts on the 11 March 2027.
25
days
Location: Warsaw, PL
In-person conference organized by Devopsdays.
The conference starts on the 23 November 2026.
25
days
Location: Recife, BR
In-person conference organized by Devopsdays.
The conference starts on the 12 December 2026.
More articles
Ganesh Gurudu
This article explains how to design an AI agent for SRE operations that reads alerts, logs, Kubernetes data, runbooks, deployments, and observability signals to diagnose incidents and propose safe actions.
Matt Brown
This article explains how to build a Kubernetes security console that turns CRD-based security findings and runtime events into one MCP-backed triage surface.
Rakesh Raushan
This article explains why ONNX Runtime can keep gigabytes of memory after inference.
It shows how allocator behavior, session reuse, and runtime tuning affect memory usage, latency, and containerized workloads.
Juliet Security Team
This article explains why Kubernetes PSS Restricted and RuntimeDefault seccomp did not block AF_ALG access during Copy Fail testing.
It shows why kernel attack surface still matters even when pods follow strict runtime defaults.