applicationset
The ApplicationSet controller is a Kubernetes controller that adds support for a new custom ApplicationSet CustomResourceDefinition (CRD). This controller/CRD enables both automation and greater flexibility when managing Argo CD Applications across a large number of clusters and within monorepos, plus it makes self-service usage possible on multitenant Kubernetes clusters.https://github.com/argoproj-labs/applicationset
How to audit and secure an AWS account
https://acloudguru.com/blog/engineering/how-to-audit-and-secure-an-aws-account
https://acloudguru.com/blog/engineering/how-to-audit-and-secure-an-aws-account
KUR8
A visual overview of Kubernetes architecture and Prometheus metrics.https://github.com/oslabs-beta/KUR8
Focusing on What Matters: Using SLOs to Pursue User Happiness
Proper reliability is the greatest operational requirement for any service. If the service doesn’t work as intended, no user (or engineer) will be happy. This is where SLOs come in.https://www.betterment.com/resources/service-level-objectives-slo
chezmoi
Manage your dotfiles across multiple diverse machines, securely.https://github.com/twpayne/chezmoi
Prometheus Blackbox: What? Why? How?
https://medium.com/codex/prometheus-blackbox-what-why-how-28290dbb22ce
https://medium.com/codex/prometheus-blackbox-what-why-how-28290dbb22ce
k8s-vault-webhook
k8s-vault-webhook is a Kubernetes admission webhook which listen for the events related to Kubernetes resources for injecting secret directly from secret manager to pod, secret, and configmap. The motive of creating this project is to provide a dynamic secret injection to containers/pods running inside Kubernetes from different secret managers for enhanced security.https://github.com/OT-CONTAINER-KIT/k8s-vault-webhook
Unpacking Observability: The Observability Stack
https://adri-v.medium.com/unpacking-observability-the-observability-stack-93d4733e2a72
https://adri-v.medium.com/unpacking-observability-the-observability-stack-93d4733e2a72
kubescape
Kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by NSA and CISAhttps://github.com/armosec/kubescape
Securing Prometheus Scrapes with the Kuma Service Mesh
https://medium.com/@austin.ce/securing-prometheus-scrapes-with-the-kuma-service-mesh-7bb4d1b0ef99
https://medium.com/@austin.ce/securing-prometheus-scrapes-with-the-kuma-service-mesh-7bb4d1b0ef99
gopass
gopass is a password manager for the command line written in Go. It supports all major operating systems (Linux, MacOS, BSD) as well as Windows.https://github.com/gopasspw/gopass
Time series forecasting for Prometheus & Grafana with BigQuery ML
Use BigQuery ML for adding forecasting capabilities to Prometheus and make your monitoring smarterhttps://anttihavanko.medium.com/time-series-forecasting-for-prometheus-grafana-with-bigquery-ml-2154f7cd48b5
monika
Connecting Monika with Prometheus
https://medium.com/hyperjump-tech/collecting-monika-with-prometheus-9faa7d484a30
Monika is a command line application to monitor every part of your web app using a simple JSON configuration file. Get alert not only when your site is down but also when it's slow.https://github.com/hyperjumptech/monika
Connecting Monika with Prometheus
https://medium.com/hyperjump-tech/collecting-monika-with-prometheus-9faa7d484a30
DNS Security: Threat Modeling DNSSEC, DoT, and DoH
https://www.netmeister.org/blog/doh-dot-dnssec.html
https://www.netmeister.org/blog/doh-dot-dnssec.html
How to detect security threats in your systems' Linux processes
https://www.datadoghq.com/blog/linux-security-threat-detection-datadog
https://www.datadoghq.com/blog/linux-security-threat-detection-datadog
Email Authenticity 101: DKIM, DMARC, and SPF
https://www.alexblackie.com/articles/email-authenticity-dkim-spf-dmarc
https://www.alexblackie.com/articles/email-authenticity-dkim-spf-dmarc
DevOps&SRE Library
SRE Teams #8: Loggi Loggi is a logistics company with the mission of connecting Brazil. They recently raised USD 212 million to connect 100% of the Brazilian population; they ended last year reaching 54% of people in Brazil, up from 43% in the year before.…
SRE Teams #9: Delivery Center
DeliveryCenter has about 600 employees. Their primary mission is to be OneStepToSell to restaurants and marketplaces. They connect the restaurants with many food apps, managing everything through a single platform. One hundred twenty people work in the experience area, split between product, technology, data, and growth.https://sreteams.substack.com/p/sre-teams-9-delivery-center
Overview of UI Tools for Monitoring and Management of Apache Kafka Clusters
https://towardsdatascience.com/overview-of-ui-tools-for-monitoring-and-management-of-apache-kafka-clusters-8c383f897e80
https://towardsdatascience.com/overview-of-ui-tools-for-monitoring-and-management-of-apache-kafka-clusters-8c383f897e80
Wildcard LetsEncrypt certificates with Traefik and Cloudflare
Re-use the same wildcard TLS certificate for multiple containers running behind traefik.https://major.io/2021/08/16/wildcard-letsencrypt-certificates-traefik-cloudflare
Error Budgets and their Dependencies
https://www.squadcast.com/blog/error-budgets-and-their-dependencies
https://www.squadcast.com/blog/error-budgets-and-their-dependencies