Learn Kubernetes Weekly issue 193 · 22 Jul 2026

Chainguard Containers, One Forgotten Notebook on A100, Syncing Clusters with GitOps, Spark Cost Optimization, Migrating to Kgateway

This newsletter is brought to you by LearnKube — master Kubernetes with hands-on training designed for engineers who want to learn the smart way.

Articles

  1. Which of our Containers are Chainguard?

    breakglass.hashnode.dev

    This article explains how to detect which running Kubernetes containers use Chainguard or other base images by reading runtime OS data through node-level proc inspection.

  2. One forgotten notebook on an A100. $1,800 a month.

    medium.com

    This article explains how kube-gpu-top helps Kubernetes teams find idle or compute-idle GPUs by mapping NVIDIA GPU metrics to owning pods and estimating monthly waste without Prometheus or Grafana.

  3. How an Admin Cluster Keeps Application Clusters in Sync with GitOps

    medium.com

    This case study shows how Deloitte built a multi-cluster Kubernetes platform on STACKIT with an admin cluster, Argo CD ApplicationSets, GitLab pipelines, and shared platform tooling.

  4. Cost Optimization of Spark on Kubernetes Batch Workloads on Public Clouds

    medium.com

    This case study shows how Spark on Kubernetes batch workloads cut cloud costs by colocating executors with drivers, reducing inter-zone shuffle costs, and moving executors to Spot VMs safely.

  5. ingress-nginx Is Archived: How We Migrated to kgateway (and Didn’t Break Prod)

    medium.com

    This case study explains how Plum migrated from ingress-nginx to kgateway and Gateway API in 12 weeks without production downtime.

    It covers inventory, staging validation, parallel running, mTLS decisions, and custom observability.

  6. I Fine-Tuned a 7B Model to Be a Cloud Security Expert On My Local Machine, For $0

    blog.valqore.io

    This article explains how a local 7B model was fine-tuned to answer cloud security, Kubernetes, Terraform, and compliance questions from a rule-based dataset.

Advanced Kubernetes Course

This four-day advanced kubernetes course teaches you:

  • networking,
  • autoscaling,
  • security,
  • and scheduling

through hands-on labs, led by engineers who run Kubernetes clusters in production every day.

Join us, Sep 10

Advanced Kubernetes Course

Tutorials

  1. 5 Kubernetes gotchas that break Laravel deploys in production

    deploysfordevs.substack.com

    This tutorial explains five Laravel-on-Kubernetes production gotchas, covering immutable migration Jobs, managed databases, worker shutdown timeouts, queue worker flags, and better autoscaling signals.

  2. Catching Helm Drift Before It Catches You

    techexpertise.medium.com

    This tutorial explains how to catch Helm drift in Kubernetes before manual kubectl changes break GitOps source-of-truth workflows.

  3. The Split-Brain Health Check: Fixing 502 Bad Gateway in GKE & Istio

    medium.com

    This tutorial explains why standard GKE Ingress breaks under Istio STRICT mTLS and shows how to replace it with an Istio Ingress Gateway, Gateway resource, and VirtualService.

  4. Building a PCI-DSS Compliant GKE Framework for Financial Institutions: Data Protection, Governance & Audit Logging

    blog.devops.dev

    This tutorial explains how to build a PCI-DSS focused GKE security framework using:

    • Workload Identity,
    • Secret Manager,
    • Binary Authorization,
    • NetworkPolicy,
    • VPC Service Controls,
    • Private Service Connect,
    • Istio mTLS,
    • and audit logging.

Kubernetes jobs

    • DevOps Engineer with Nexxen

    • Salary: US$76.5K to US$288.2K a year

    • Location: based in the office (and remote from home) in Tel Aviv, IL

    • Tech stack: Kubernetes, Kubernetes, AWS EC2, EKS, AWS, On-premise, Datadog, Grafana, Prometheus, DNS

    • Site Reliability Engineer with Lightning AI

    • Salary: $180K to $200K a year

    • Location: based in the office (and remote from home) in New York, NY, USA

    • Tech stack: Kubernetes, Kubernetes, AWS EC2, EKS, AKS, GKE, Docker, On-premise, Promtail, alerting

    • Operations Engineer with Lightning AI

    • Salary: US$84.15K to US$170.5K a year

    • Location: based in the office (and remote from home) in London, GB

    • Tech stack: Kubernetes, Kubernetes, AWS, Monitoring systems, ELK stack, Prometheus, GitOps, Ansible, Terraform, Ceph

    • Engineering Manager with Synctera

    • Salary: $86.4K to $421.3K a year

    • Location: remote from

    • Tech stack: Kubernetes, Cloud Run, Google Cloud Platform, Kubernetes, Terraform, compliance, authentication, security, Redis, Postgres

    • Software Engineer with ATOMS Careers page

    • Salary: $110.19K to $440K a year

    • Location: based in the office in Los Angeles, CA, USA

    • Tech stack: Kubernetes, Kubernetes, AWS, Docker, testing, observability, Terraform, asynchronous workflows, Vue, design reviews

Discover more Kubernetes jobs on Kube Careers →

Code & tools

  1. Rūsternetes: Kubernetes reimplemented in Rust

    github.com/calfonso

    Rūsternetes is a from-scratch Rust reimplementation of Kubernetes with its own:

    • API server,
    • scheduler,
    • controller manager,
    • kubelet,
    • kube-proxy,
    • controllers,
    • and conformance tests.
  2. kubectl-mcp-server – Kubernetes Management via MCP

    github.com/rohitg00

    kubectl-mcp-server lets AI assistants use natural language to inspect and manage Kubernetes clusters through kubectl operations, Docker support, kubeconfig mounting, and MCP-compatible tooling.

  3. Webernetes

    github.com/ngrok

    Webernetes is a browser-based Kubernetes simulator that allows users to run a subset of Kubernetes features, including Pods, Services, and Deployments, entirely in the Browser without backend infrastructure.

  4. Cardamon: Prometheus Metric Cleanup Tool

    github.com/dominikhei

    Cardamon audits Prometheus metrics against query logs, rules, and Grafana dashboards, then finds unused series and generates drop relabeling rules to reduce TSDB storage and cardinality waste.

  5. Nomos: AI Agent Execution Firewall

    github.com/safe-agentic-world

    Nomos governs AI agent actions for Claude Code, Codex, Cursor, and MCP by enforcing allow, deny, or approval decisions before file, shell, Kubernetes, GitHub, HTTP, or secret access runs.

Other interesting projects:

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 193 issues and counting.

or subscribe via

Upcoming Kubernetes events

  1. Jul

    22

    From Containers to AI: Empowering Developers with Red Hat Desktop

    Online webinar organized by Red Hat.

    • This is a virtual event

    • This is a free event.

  2. Jul

    22

    Kubernetes as a platform for AI

    In-person meetup organized by Cloud Native - Kubernetes - Bratislava.

    • Location: Bratislava, SK

    • This is a free event.

  3. Jul

    23

    ChatLoopBackOff Episode 79: Capsule

    Online meetup organized by CNCF Online Programs.

    • This is a virtual event

    • This is a free event.

  4. Jul

    25

    Kubernetes Community Days Vietnam 2026

    In-person conference organized by KCD x OpenInfra Day Vietnam.

    • Location: Hanoi, VN

    • This is a free event.

  5. Sept

    10

    Advanced Kubernetes course

    Online workshop organized by LearnKube.

    • This is a virtual event

    • This event requires an entrance fee

Discover more Kubernetes events on Kube Events →

Thanks to our sponsors who make Kube Today possible

  • LearnKube
  • Akamai
  • Fairwinds
  • Densify
Find out more about being a sponsor →

Kubernetes call for papers

  1. 9

    days

    ContainerDays & AI Context Singapore

    The Call For Paper is open until 31 July 2026 at UTC. More info →
    • Location: Singapore, SG

    • In-person conference organized by ContainerDays.

    • The conference starts on the 28 October 2026.

    • Apply here
  2. 25

    days

    Kubernetes Community Days Suisse Romande 2026

    The Call For Paper is open until 16 August 2026 at UTC. More info →
    • Location: Geneva, CH

    • In-person conference organized by KCD Suisse Romande.

    • The conference starts on the 9 December 2026.

    • Apply here
  3. 40

    days

    OmniOpenCon 2026

    The Call For Paper is open until 31 August 2026 at UTC. More info →
    • Location: Bucharest, RO

    • In-person conference organized by OmniOpenCon.

    • The conference starts on the 18 October 2026.

    • Apply here
  4. 23

    days

    Cloud Native AI Summit Europe

    The Call For Paper is open until 14 August 2026 at UTC. More info →
    • Location: Paris, FR

    • In-person conference organized by mate.dev.

    • The conference starts on the 3 December 2026.

    • Apply here
  5. 24

    days

    Cloud Security Space 2026

    The Call For Paper is open until 15 August 2026 at UTC. More info →
    • Location: Buenos Aires, AR

    • In-person conference organized by Cloud Security Space.

    • The conference starts on the 9 October 2026.

    • Apply here
  6. 37

    days

    Monster Scale Summit 2027

    The Call For Paper is open until 28 August 2026 at UTC. More info →
    • This is a virtual event

    • Online conference organized by ScyllaDB.

    • The conference starts on the 11 March 2027.

    • Apply here
  7. 70

    days

    UbuCon India 2026

    The Call For Paper is open until 30 September 2026 at UTC. More info →
    • Location: Bengaluru, IN

    • In-person conference organized by Canonical.

    • The conference starts on the 15 November 2026.

    • Apply here
  8. 85

    days

    Global Summit on Data Science and Cloud Computing

    The Call For Paper is open until 15 October 2026 at UTC. More info →
    • Location: Rome, IT

    • In-person conference organized by Noveltics Group.

    • The conference starts on the 20 October 2026.

    • Apply here
  9. 71

    days

    SREday Amsterdam 2026

    The Call For Paper is open until 1 October 2026 at UTC. More info →
    • Location: Amsterdam, NL

    • In-person conference organized by SREDay.

    • The conference starts on the 29 September 2026.

    • Apply here

That's all for this week!

See you next week.

— Gulcan

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 193 issues and counting.

or subscribe via