Sign in

Ivan Velichko

@iximiuz.bsky.social
1.3K followers 196 following 110 posts

Software Engineer. Educator. Entrepreneur. Bootstrapping labs.iximiuz.com - a learning platform to help you master Linux, Containers, and Kubernetes 🚀

PostsRepliesMedia
Reposted by Ivan Velichko
David Flanagan @rawkode.dev · 22/05/2026
I've deployed a couple of challenges, #Klustered style, to @iximiuz.bsky.social's Labs. I hope you have fun trying to fix them, though there is a guide provided if toy want to learn rather than debug. Have fun out there!
labs.iximiuz.com
Klustered: Level One | Challenge
The cluster is broken. Fix the plumbing to bring the app to life (you'll know it's working when Rawkode taps his watch at you), then ship the v2 image to unlock his victory dance.
142
Reposted by Ivan Velichko
Márk Sági-Kazár @sagikazarmark.com · 24/06/2025
Following up on my etcd playgrounds, here is a sneak peek of my latest work: a @containerd.dev‬ playground. As usual, it will be available on @iximiuz.bsky.social labs soon.
141
Reposted by Ivan Velichko
Rory McCune @mccune.org.uk · 30/05/2025
Starting some more looking into k8s things the way I usually do now, with a nice ephemeral k8s-omni playground from @iximiuz.bsky.social
screenshot of a terminal running the labctl playground start command to create a new kubernetes cluster
041
Reposted by Ivan Velichko
Márk Sági-Kazár @sagikazarmark.com · 19/05/2025
Following up on my previous post, here is another tutorial about operating @openbao-official.bsky.social and @hashicorp.com Vault on @iximiuz.bsky.social Labs. Auto Unseal OpenBao/Vault with the Transit Secrets Engine: labs.iximiuz.com/tutorials/o... bsky.app/profile/did...
bsky.app
Márk Sági-Kazár (@sagikazarmark.com)
1/4 Secret management is a critical yet often overlooked aspect of DevOps. (Raise your hand if you've ever intentionally committed secrets to a Git repository.) This is why I've begun creating a series of educational content on the subject.
041
Reposted by Ivan Velichko
Márk Sági-Kazár @sagikazarmark.com · 17/05/2025
1/4 Secret management is a critical yet often overlooked aspect of DevOps. (Raise your hand if you've ever intentionally committed secrets to a Git repository.) This is why I've begun creating a series of educational content on the subject.
111
Reposted by Ivan Velichko
Rory McCune @mccune.org.uk · 21/04/2025
TIL that adding CAP_SYS_ADMIN to a k8s pod has different behaviour depending on the backing CRI. With Containerd it does nothing (you need to call it SYS_ADMIN) but on CRI-O it will add ok. Also TIL k8s doesn't validate the capabilities you add to pods!
2232
Ivan Velichko @iximiuz.bsky.social · 22/04/2025
Great research! Looking forward to a blog post!
010
Ivan Velichko @iximiuz.bsky.social · 08/04/2025
Well done! It would be nice to see a custom cover image for this post. I'm a big fan of colorful diagrams, you know :)
110
Reposted by Ivan Velichko
Rory McCune @mccune.org.uk · 08/04/2025
Experimenting with using @iximiuz.bsky.social labs for interactive blog content, so I re-worked one of my container security fundamentals blogs labs.iximiuz.com/tutorials/co... . Interested in any feedback on what people reckon to the format :)
labs.iximiuz.com
Containers are processes | iximiuz Labs
In this brief tutorial we'll explore the idea that Docker containers are just processes, from the perspective of the operating system. Based on this Securitylabs blog post https://securitylabs.datadog...
261
Ivan Velichko @iximiuz.bsky.social · 02/04/2025
This is the way! 🚀
030
Reposted by Ivan Velichko
Laurent Cheylus @lcheylus.bsky.social · 28/03/2025
A Visual Guide to SSH Tunnels: Local and Remote Port Forwarding - Article by Ivan Velichko @iximiuz.bsky.social #Network #SysAdmin
iximiuz.com
A Visual Guide to SSH Tunnels: Local and Remote Port Forwarding
SSH port forwarding explained in a clean and visual way. How to use local and remote port forwarding. What sshd settings may need to be adjusted. How to memorize the right flags.
1105
Ivan Velichko @iximiuz.bsky.social · 27/03/2025
That’s great news! Looking forward to dive 2.0!
000
Ivan Velichko @iximiuz.bsky.social · 26/03/2025
Great question! Not really. I'm looking for a good tool like that myself. Dive is aging, and its more or less maintained fork was also archived a couple of days ago github.com/joschi/dive. And ima.ge.cx/ghcr.io/eda-... fails for your image, too :)
ima.ge.cx
Page title
100
Reposted by Ivan Velichko
cloudnativeboy.bsky.social @cloudnativeboy.bsky.social · 23/03/2025
labs.iximiuz.com a browser-based env's where anyone, from beginners to experienced engineers, can get hands-on experience with containers, K8S, DevOps tools, CI/CD pipelines, observability & loads more. Listen to @iximiuz.bsky.social how it's all started, current adaption: youtu.be/kHjAW7f0EPo
041
Reposted by Ivan Velichko
Jseguillon@CuistOps @jseguillon.bsky.social · 03/03/2025
Please join me and thank @iximiuz.bsky.social for giving us a bunch of free premium accounts we can give away to our viewers on our twitch channel ! First two will be offered today !! @iximiuz.bsky.social really rocks ! Please take a look at his amazing labs !
063
Reposted by Ivan Velichko
cloudnativeboy.bsky.social @cloudnativeboy.bsky.social · 24/02/2025
Most of the issues with container images are not b/c of the app being containerized but a poorly written/structured docker file @iximiuz.bsky.social Kyle Quest will offer optimizations for improvements in size, security, & build speed, check out: gooddockerfiles.com
022
Reposted by Ivan Velichko
cloudnativeboy.bsky.social @cloudnativeboy.bsky.social · 19/02/2025
@iximiuz.bsky.social's journey of transitioning from traditional textual and visual explanations in his blog posts to creating interactive, reproducible tutorials -> labs.iximiuz.com has attracted 18,000 registered users, with around 2,000 active users per month. Full Ep -> youtu.be/kHjAW7f0EPo
011
Ivan Velichko @iximiuz.bsky.social · 18/02/2025
Kubernetes "native" sidecars are slated for GA in 1.33, so it's a good time to brush up on how (and why) to use them. Solve this practical challenge by reworking a flawed pod, making it use a native sidecar: > Kubernetes Pod With a Faulty Init Sequence labs.iximiuz.com/challenges/k...
061
Ivan Velichko @iximiuz.bsky.social · 13/02/2025
Trying my best :) It’s simply a matter of iterating on it long enough
000
Ivan Velichko @iximiuz.bsky.social · 13/02/2025
Thank you for the shoutout, Martin!
110
Reposted by Ivan Velichko
Martin Perez @martin.arume.cloud · 13/02/2025
If you are into #docker and #containers you must check @iximiuz.bsky.social feed. His content is amazing.
161
Ivan Velichko @iximiuz.bsky.social · 09/02/2025
Works for me 🙈
010
Ivan Velichko @iximiuz.bsky.social · 09/02/2025
Unpopular opinion: The main value of CKA, CKAD, and CKS is not in the certificate itself but in the preparation phase. Having said that, allow me to present a new iximiuz Labs challenge by Adam Leskis 👏 CKA Practice: Upgrade Multi-Node Kubernetes Cluster labs.iximiuz.com/challenges/c...
labs.iximiuz.com
CKA Practice: Upgrade Multi-Node Kubernetes Cluster | Challenge
This exercise tests your ability to safely upgrade a multi-node Kubernetes cluster from version 1.30 to 1.31 following the standard upgrade procedure.
184
Ivan Velichko @iximiuz.bsky.social · 05/02/2025
It's very easy to start a Docker container: docker run nginx ☑️ But can you explain what actually happens when you run this command? I prepared a Docker 101 challenge that helps you explore the internals of Linux containers - check it out: labs.iximiuz.com/challenges/s...
020
Ivan Velichko @iximiuz.bsky.social · 03/02/2025
How to Limit CPU and Memory Usage of a Linux Process 🔽 Of course, using cgroups! But there is a number of ways to do it: - Manually editing the cgroupfs filesystem - Using libcgroup's cgcreate and cgexec - Using the mighty systemd-run Practice here 👉 labs.iximiuz.com/challenges/l...
labs.iximiuz.com
Limit CPU and Memory Usage of a Linux Process | Challenge
Start a Linux process and limit its CPU and memory usage with cgroups.
041
Reposted by Ivan Velichko
MadeWithVueJS @madewithvuejs.com · 02/02/2025
k'exp by @iximiuz.bsky.social is a visual Kubernetes explorer #madewithvuejs that lets you explore Kubernetes capabilities & helps you with application development ✨ - madewithvuejs.com/kexp
021
Ivan Velichko @iximiuz.bsky.social · 01/02/2025
How do you containerize a Python app the right way? 🤔 Building small and secure images for Python projects is surprisingly hard: - Which base image to choose? - How to manage dependencies? - How to structure the Dockerfile? Learn more (with solutions): labs.iximiuz.com/challenges/d...
061
Ivan Velichko @iximiuz.bsky.social · 27/01/2025
Container images to avoid in production - part II: python:3 Yes, it's a Docker Official Image, and it's a good image to build your app, but: - It has TWO pythons inside 🐍 x 2 = 🤯 - It brings 800MB+ of dev/build packages. What to use instead in production 👉 python:3-slim
020
Ivan Velichko @iximiuz.bsky.social · 24/01/2025
SSH Tunnels: An age-old trick that's still widely used - Expose a local service to the Internet - Map a remote service to a local port - Query an AWS RDS database with a local GUI client - Access a server in your private VPC from a dev machine ...and a lot more. Visual memo 👇
161
Ivan Velichko @iximiuz.bsky.social · 23/01/2025
Learn more about distroless container images in my latest post: labs.iximiuz.com/tutorials/gc...
labs.iximiuz.com
What's Inside Distroless Container Images: Taking a Closer Look | iximiuz Labs
What are these distroless images, really? Why are they needed? What's the difference between a container image built from a distroless base and a container image built from scratch? Let's take a deepe...
010
Ivan Velichko @iximiuz.bsky.social · 23/01/2025
What's Inside Distroless Container Images: Taking a Closer Look 🧐 Distroless images come in many flavors, and it might not be obvious which one (if any!) is the best fit for your application. Here is my attempt to explain the difference and use cases on a single diagram:
150
Ivan Velichko @iximiuz.bsky.social · 20/01/2025
An 80/20 solution combined with situational awareness is the key. I always vet my dependencies, but I also trust my docker daemon and the Docker Hub (more like GHCR, actually) addresses I enter. But this is because my projects aren't super sensitive. Banking or health care industries are different.
000
Ivan Velichko @iximiuz.bsky.social · 19/01/2025
Pulling and Pushing Container Images 🔽 Did you know that the below commands: docker pull nginx docker pull nginx:latest docker pull library/nginx:latest docker pull docker[.]io/library/nginx:latest ...pull exactly the same Docker Hub image? Learn more 👉 labs.iximiuz.com/skill-paths/...
170
Ivan Velichko @iximiuz.bsky.social · 14/01/2025
Building container images FROM scratch? Then you need to be aware of these pitfalls 👇 By default, scratch containers lack: - Rootfs layout - CA certificates - Time zone info - Shared libraries - /etc/{passwd,group} Learn more in my new blog post: labs.iximiuz.com/tutorials/pi...
labs.iximiuz.com
Building Container Images FROM Scratch: 6 Pitfalls That Are Often Overlooked | iximiuz Labs
While "FROM scratch" containers may seem functional, they often lack essential components that programs expect to find in their execution environment. Discover the most common pitfalls of building con...
050
Ivan Velichko @iximiuz.bsky.social · 12/01/2025
Makes sense. Different platform, different mechanics.
000
Ivan Velichko @iximiuz.bsky.social · 12/01/2025
Feeds or people? 🙈
100
Ivan Velichko @iximiuz.bsky.social · 11/01/2025
Haha, I’m no fan of tags :) Destined to fail this game, probably 😂
000
Ivan Velichko @iximiuz.bsky.social · 11/01/2025
Frankly, I've no idea how these feeds work :) Is there something I should do? Or is it just because no one added me to some cool "Cloud Native" list?
110
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
How To Build a Production-Ready Container Image For a Go App 🔽 Is "FROM scratch" good enough for you? Check out these hands-on challenges to learn about the most typical Go container pitfalls: - static linking labs.iximiuz.com/challenges/d... - dynamic linking labs.iximiuz.com/challenges/d...
272
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
6/6: Port publishing and dNAT (optional ingress) Port publishing is a form of traditional Port Forwarding implemented with iptables (kernel). When the host receives a packet on a "published" port, its destination address (i.e., the host's IP) is replaced with the container's IP.
010
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
5/6: Routing and sNAT (egress) An IP address is assigned to the bridge device, and each container connected to this bridge gets a Default Gateway route with this IP. For outgoing (from containers) packets, the source IPs get replaced ("translated") with the bridge IP (via iptables).
110
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
4/6: Virtual switch (bridge device) The host's ends of the veth pairs are connected to a virtual switch (a.k.a. bridge) device. One bridge forms one container network, where containers can intercommunication on L2/L3 (Ethernet/IP).
110
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
3/6: Container addressing (IP) An IP address is assigned to the container's end of the veth pair. For the container, it creates a route table record to access its network. However, the host's ends of the veth pairs remain without addresses to avoid introducing routing conflicts.
110
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
2/6: Virtual Ethernet Devices (veth) A pair of connected virtual network devices is used to access an otherwise isolated container. One end of the veth pair is moved to the container's network namespace, and the other end remains in the host's network context.
110
Ivan Velichko @iximiuz.bsky.social · 10/01/2025
How Container Networking Works 🧵 1/6: Network namespaces (netns) A separate network namespace gives a Linux container its own virtualized (and fully isolated from the host) network "context" - a loopback device, a route table, netfilter/iptables rules, etc.
1180
Reposted by Ivan Velichko
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/01/2025
Have big and slow containers? Not keeping up with CVEs in your images? We (me and @iximiuz.bsky.social ) can try to help! Send over your Dockerfile, and we’ll provide a refined version in return. A limited time offer 🙂
421
Ivan Velichko @iximiuz.bsky.social · 08/01/2025
Computer Networking 101: Forward Ports Like a Pro 🧙‍♂️ The only way to mastery is through practice. Can you map one port to another using: - socat labs.iximiuz.com/challenges/p... - netcat labs.iximiuz.com/challenges/p... - iptables labs.iximiuz.com/challenges/p... Happy hacking!
040
Ivan Velichko @iximiuz.bsky.social · 06/01/2025
62 practical exercises if you're preparing for a DevOps, SRE, or Platform Engineer interview 🔽 All challenges: - Have automated solution checking - Packed with hints and theory references - Based on real-life problems I've encountered Check them out: labs.iximiuz.com/challenges
labs.iximiuz.com
Challenges 🏆 | iximiuz Labs
Practical DevOps problems for all skill levels and interests
051
Ivan Velichko @iximiuz.bsky.social · 05/01/2025
If you want to start building better container images for your Node.js applications, I've got some hands-on resources for you 👇 Check out my latest DevOps challenge, packed with practical tips: > Build a Production-Ready Next.js Application Image labs.iximiuz.com/challenges/d...
labs.iximiuz.com
Build a Production-Ready Node.js Application Image: Next.js | Challenge
Learn how to build a secure, lightweight, and production-ready Node.js application image in this hands-on challenge.
030
Ivan Velichko @iximiuz.bsky.social · 03/01/2025
Are your Docker images huge and full of CVEs? 🐳 Multi-stage builds and careful base image selection can fix that. Read my multi-stage builds intro to understand the How's and the Why's and get practical examples for Node.js, Go, Java, Rust, and PHP: labs.iximiuz.com/tutorials/do...
labs.iximiuz.com
How to Build Smaller Container Images: Docker Multi-Stage Builds | iximiuz Labs
Learn how to build smaller, more secure Docker container images using Multi-Stage Builds. This guide explains common sources of image bloat, best practices for slimming down production images, and pra...
020