Kubernetes v1.33 enables user namespaces by default for better isolation
Kubernetes v1.33 enables Linux user namespaces by default, allowing pods to run as root internally while remaining unprivileged on the host.
Daily coverage of AI, developer tools and infrastructure. Each story explains what happened and why it matters, with a link to the original source.
Kubernetes v1.33 enables Linux user namespaces by default, allowing pods to run as root internally while remaining unprivileged on the host.
Kubernetes 1.32 graduates watch lists to beta, allowing clients to stream large resource collections and prevent API server out-of-memory crashes.
Kubernetes v1.32 re-enables the QueueingHint feature by default, allowing plugins to precisely determine when unschedulable pods should be retried, reducing wasted scheduler cycles.
Cozystack engineers explain how they used the Kubernetes API aggregation layer to create dynamic, imperative endpoints and bypass etcd storage limitations.
A 2024 deep dive explains the unique URL-based streaming architecture behind Kubernetes Container Runtime Interface commands.
A technical guide details how to construct a self-hosted cloud platform using Kubernetes, Talos Linux, and GitOps tools to manage bare metal infrastructure.
A 2023 analysis argues that setting CPU and memory limits in Kubernetes improves performance predictability, even if it reduces raw cluster efficiency.
A 2023 Kubernetes Blog post argues that all microservices are vulnerable. It proposes security-behavior analytics to detect and block exploits by monitoring client and service patterns.
Kubernetes v1.25 removed the deprecated PodSecurityPolicy admission controller. This article explains its history, flaws, and the simpler Pod Security Admission replacement.
Box engineers built a custom admission controller and kubectl plugin to detect runtime container changes and enforce pod eviction policies.
A 2021 guide explains how to bypass namespace restrictions by importing cloud provider snapshots as golden images for fast, isolated development environments.
A 2021 guide explains how finalizers block resource removal and how owner references manage cascading deletes in Kubernetes clusters.