DevOps&SRE Library
18.3K subscribers
456 photos
5 videos
2 files
4.93K links
Библиотека статей по теме DevOps и SRE.

Реклама: @ostinostin
Контент: @mxssl

РКН: https://www.gosuslugi.ru/snet/67704b536aa9672b963777b3
Download Telegram
peirates

Peirates, a Kubernetes penetration tool, enables an attacker to escalate privilege and pivot through a Kubernetes cluster. It automates known techniques to steal and collect service accounts, obtain further code execution, and gain control of the cluster.

https://github.com/inguardians/peirates
youki

youki is an implementation of the OCI runtime-spec in Rust, similar to runc.

https://github.com/containers/youki
Reverse Proxy, HTTP Keep-Alive Timeout, and sporadic HTTP 502s

https://iximiuz.com/en/posts/reverse-proxy-http-keep-alive-and-502s
automated-cloud-advisor

Automated Cloud Advisor is an extensible tool that aims at facilitating cost optimization in AWS, by collecting data for resources that are under utilized. In addition, this is a great learning tool for new DevOps/Cloud engineers that want to start automating things in AWS.

https://github.com/disneystreaming/automated-cloud-advisor
The Speed of Time

How long does it take to read the time? How would you time time? These strange questions came to the fore back in 2014 when Netflix was switching services from CentOS Linux to Ubuntu, and I helped debug several weird performance issues including one I'll describe here.

https://www.brendangregg.com/blog/2021-09-26/the-speed-of-time.html
pgmetrics

pgmetrics is an open-source, zero-dependency, single-binary tool that can collect 350+ metrics from a running PostgreSQL server and display it in easy-to-read text format or export it as JSON and CSV for scripting.

https://pgmetrics.io
10 Trends in real-world container use

Updated October 2021.

1. Nearly 90 percent of Kubernetes users leverage cloud-managed services
2. Amazon ECS users are shifting to AWS Fargate
3. The average number of pods per organization has doubled
4. Host density is 3 times higher on Kubernetes than on Amazon ECS
5. Pod auto-scaling is becoming more popular
6. Organizations are deploying more stateful workloads on containers
7. Organizations running container environments create more monitors
8. Organizations are starting to replace Docker with containerd as their preferred runtime for Kubernetes
9. OpenShift adoption is growing rapidly
10. NGINX, Redis, and Postgres are the top three container images

https://www.datadoghq.com/container-report
Deploy without credentials with GitHub Actions and OIDC

https://blog.alexellis.io/deploy-without-credentials-using-oidc-and-github-actions
CloudGraph

An instant GraphQL API to query your cloud infrastructure and configuration so that you can solve a host of complex security, compliance, and governance challenges 10x faster.

https://github.com/cloudgraphdev/cli
parca

Continuous profiling for analysis of CPU, memory usage over time, and down to the line number. Saving infrastructure cost, improving performance, and increasing reliability.

https://github.com/parca-dev/parca
Trigger a Kubernetes HPA with Prometheus metrics

https://sysdig.com/blog/kubernetes-hpa-prometheus
What is under the hood of Kubernetes? - Part 1

https://blog.softwheel.io/what-is-under-the-hood-of-kubernetes-1
Changing the tires on a moving bus

Adventures in refactoring a decade-old feature without ruining it for everyone

https://mailchimp.com/developer/blog/changing-the-tires-on-a-moving-bus
algo

Algo VPN is a set of Ansible scripts that simplify the setup of a personal WireGuard and IPsec VPN. It uses the most secure defaults available and works with common cloud providers. See our release announcement for more information.

https://github.com/trailofbits/algo
A Lap around Kubernetes Security & Vulnerability scanning Tools — checkov, kube-hunter, kube-bench & Starboard

https://aninditabasak.medium.com/a-lap-around-kubernetes-security-vulnerability-scanning-tools-checkov-kube-hunter-kube-bench-4ffda92c4cf1
Learn TypeScript in 5 minutes

Useful for tools like Pulumi

https://swizec.com/blog/learn-typescript-in-5-minutes
Infrastructure monitoring: An introduction

The ability to understand at a glance the current state of your infrastructure is an essential yet often underappreciated aspect of modern infrastructures. Regardless of the architecture, from dockerized microservices to monoliths and physical servers, knowing what’s going on is an essential part of avoiding unexpected downtime.

https://mrintegrity.medium.com/monitoring-from-scratch-ea2b83a8f8a5
kuberlogic

KuberLogic is an open-source platform that deploys and manages software on top of the Kubernetes cluster and turns infrastructure into a managed PaaS. It allows running managed databases and popular applications deploying on-premises or at any cloud. The solution provides API, monitoring, backups, and integration with SSO right out of the box.

https://github.com/kuberlogic/kuberlogic