Sign in

kondokentaro

@kondokentaro.bsky.social
44 followers 195 following 26 posts

PdM at Hexabase, building Kubo — deploy anything on Kubernetes, on cloud or on-prem. K3s · Proxmox · GitOps · homelab. Building in public 🛠️ 🔗 kubo.hexabase.io

PostsRepliesMedia
kondokentaro @kondokentaro.bsky.social · 10/09/2026
Metrics, logs, traces: three pillars. Pillars with no beams between them are just posts in the ground. OpenTelemetry is the beams: shared context across Prometheus, Loki and Tempo, exemplars jumping metric to trace, Agent-to-Gateway Collector on K3s. #OpenTelemetry #K8s #Observability
kubo.hexabase.io
Stop Bouncing Between Three Dashboards: Correlating K3s Observability with OpenTelemetry
Are you burning incident-response time checking Prometheus, Loki, and Jaeger separately? Learn how to correlate metrics, logs, and traces with OpenTelemetry to cut investigation time on K3s clusters, ...
110
kondokentaro @kondokentaro.bsky.social · 02/09/2026
That Kubernetes role isn't unfilled because nobody applied. It's unfilled because the job description is four jobs. CNI and eBPF. cert-manager. Istio. ArgoCD. Each is now its own specialty, and 77 CNCF projects keep splitting them further. #Kubernetes #PlatformEngineering #DevOps
kubo.hexabase.io
eBPF, cert-manager, Service Mesh: Why Kubernetes Operations Outgrew What One Engineer Can Handle
Why do Kubernetes operations roles stay unfilled for months? It isn't a lack of tool knowledge — it's that the discipline has splintered into too many specialties. Instead of hiring more heads, absorb...
111
kondokentaro @kondokentaro.bsky.social · 27/08/2026
The fastest way to fix a CVE in your shell is to not ship a shell. Distroless base, Trivy failing the build on Critical/High, Cosign signing, Kyverno verifying at admission. Four gates — each one closes a door the previous one leaves open. #Kubernetes #DevSecOps #SupplyChain
kubo.hexabase.io
'Scanned' Is Not a Production Clearance Certificate: K3s Container Image Security From Signing to Admission Control
Container security guidelines often stop at 'we run a scanner.' This guide walks through the practical checklist you need to pass before production in K3s: minimal base images, vulnerability scanning,...
000
kondokentaro @kondokentaro.bsky.social · 23/08/2026
No error. No alert. No metrics. A broken ServiceMonitor doesn't fail loudly — it just quietly scrapes nothing. Three usual suspects: the label match across Service/ServiceMonitor/Prometheus CR, a missing namespaceSelector, and RBAC that can't list endpoints. #Kubernetes #Prometheus #SRE
kubo.hexabase.io
Prometheus Is Running. The Metrics Aren't. Three Reasons Your ServiceMonitor Fails Silently
Your kubernetes service monitor isn't being scraped and there's no error to explain why. The root cause is almost always one of three things: label mismatches, a missing namespaceSelector, or RBAC. He...
000
kondokentaro @kondokentaro.bsky.social · 20/08/2026
Your SAST scan found the CVE. Your pipeline went green anyway. Your cluster deployed it. Auto DevOps scans are detection, not enforcement — "CI passed" never meant "safe to deploy." The gate has to live in the cluster: Kyverno or OPA Gatekeeper at admission. #Kubernetes #DevSecOps #CICD
kubo.hexabase.io
Why GitLab Auto DevOps' 'It Just Works' CI Is the Closest Threat to Your Production K3s Cluster
GitLab Auto DevOps runs SAST/DAST automatically the moment you turn it on. But a scan 'running' and a vulnerable image never reaching your production K3s cluster are two completely different things. H...
010
kondokentaro @kondokentaro.bsky.social · 18/08/2026
Your H100 costs $13/hour on paper. At 5% average utilization, you're really paying about 20x that per useful GPU-hour. Namespace quotas are cheap but don't isolate VRAM. Dedicated nodes isolate but sit idle. Pick per workload, not per ideology. #Kubernetes #GPU #MLOps
kubo.hexabase.io
Stop Letting One Team Hog Your Expensive GPUs: Why There's No Single Right Answer for Kubernetes Accelerator Sharing
Kubernetes GPU multi-tenancy isn't a binary choice between namespace isolation and dedicated nodes. This article breaks down the cost-vs-isolation trade-off and how to design a hybrid approach.
100
kondokentaro @kondokentaro.bsky.social · 15/08/2026
AI writes the code now. So why are infrastructure engineers getting raises? Generating a model is easy — running it in production isn't: GPU scheduling with DRA, inference queues with Kueue, PodDisruptionBudgets. The PoC-to-production gap is where careers are made. #Kubernetes #MLOps #AI
kubo.hexabase.io
In the Age of AI-Written Code, Why Are Infrastructure Engineers Getting Raises? Inside the 'MLOps Talent Shortage' Fueled by the Corporate AI Adoption Rush
Generative AI has made it possible for almost anyone to write code, yet as more companies adopt AI, demand for MLOps talent who can reliably run GPUs and model serving on Kubernetes keeps rising. Here...
110
kondokentaro @kondokentaro.bsky.social · 14/08/2026
You fixed N+1 queries years ago. Then you built microservices and reinvented them over the network. One checkout click, five chained service calls — latency your profiler won't blame. Chatty calls are an architecture problem, not a code problem. #Kubernetes #Microservices
kubo.hexabase.io
One Order, Five Hidden Service Calls: The Real Cause of Latency in Kubernetes Microservices' "Chatty Calls"
A single checkout request was quietly triggering five separate service calls behind the scenes. The culprit isn't bad code — it's the "chatty call" architecture that Kubernetes microservices tend to f...
100
kondokentaro @kondokentaro.bsky.social · 12/08/2026
Your CI/CD pipeline is the fastest route to production. That's exactly why attackers love it. A practical DevSecOps guide: shift-left scanning (SAST/SCA/DAST), SLSA for supply chain integrity, Sigstore image signing, policy-as-code with Kyverno, runtime detection with Falco. #DevSecOps #CICD
kubo.hexabase.io
ci-cd Pipeline Security: A Practical DevSecOps Guide
A practical guide to ci-cd pipeline security from a DevSecOps perspective. Covers SAST/DAST, supply chain protection, the SLSA framework, and Policy as Code.
000
kondokentaro @kondokentaro.bsky.social · 11/08/2026
Base64 is an encoding, not encryption. Yet by default, Kubernetes stores your Secrets in etcd exactly that way — anyone with etcd access can read every credential in the cluster. Three tiers of fixes: etcd encryption → External Secrets Operator → CSI Secrets Store Driver. #Kubernetes #Security
kubo.hexabase.io
Base64 Isn't Encryption: Why Kubernetes Secrets Pass Right Through, and the RBAC Design Traps That Make It Worse
Kubernetes Secrets are only Base64-encoded, not encrypted. Learn how plaintext-equivalent storage in etcd and over-permissioned RBAC lead to real incidents, plus the concrete Secrets management practi...
100
kondokentaro @kondokentaro.bsky.social · 09/08/2026
QA engineers already think like Kubernetes operators — they just don't know it yet. Quality gates → SLO/SLI design. Test automation → Infrastructure as Code. Failure scenarios → chaos engineering. A 6-month roadmap from QA to K8s ops, backed by salary data. #Kubernetes #DevOps #QA
kubo.hexabase.io
A QA Engineer's 'Instinct to Break Things' Transfers Directly to Kubernetes Operations: The Fastest Path from Test Automation to a DevOps Career
The quality-gate mindset and test automation skills QA engineers already have map directly onto Kubernetes operations aptitude. Here's a realistic six-month roadmap for making the switch, and how to c...
140
kondokentaro @kondokentaro.bsky.social · 06/08/2026
Troubleshooting one edge device is a fun war story. Troubleshooting 1,000 is a business risk. At fleet scale, imperative ops ("what to do") breaks down. The fix: declarative state + GitOps — devices converge on what's in Git. Rancher Fleet makes this work with K3s. #K3s #GitOps #EdgeComputing
kubo.hexabase.io
One Device's Troubleshooting Is a Funny Story. A Thousand Devices Is a Business Risk: How Rancher Fleet Rescues K3s Edge Operations from Tribal Knowledge
Fleet management for K3s edge operations breaks down once you're troubleshooting devices one at a time by hand. Here's how declarative management and Rancher Fleet let you design edge operations that ...
010
kondokentaro @kondokentaro.bsky.social · 04/08/2026
AI can write your Kubernetes YAML in a second — but your cluster won't get any faster. CPU throttling traps, HPA/VPA death spirals, DB connection exhaustion: the real bottleneck is architecture, not manifests. "AI writes" ≠ "AI designs." kubo.hexabase.io/blog/en/ai-m...
kubo.hexabase.io
AI Can Write a YAML File in One Second, But Your Cluster Won't Get Any Faster. Why the Real Bottleneck in Kubernetes Operations Is Architecture, Not Code
Generating Kubernetes manifests at AI speed doesn't make production Kubernetes operations faster. This article breaks down three real bottlenecks — CPU throttling, the HPA/VPA conflict, and database c...
000
kondokentaro @kondokentaro.bsky.social · 02/08/2026
The more you test, the more prod breaks. 🧨 K8s resilience isn't catching every edge case—it's break small, notice fast, roll back quickly. 👇 kubo.hexabase.io/blog/en/kube... #Kubernetes #DevOps #SRE #FeatureFlags #ProgressiveDelivery
kubo.hexabase.io
The More You Test, The More Production Breaks: Why Feature Flags Beat Monitoring in Kubernetes Operations
Stacking more QA tests doesn't reduce production incidents, because it's fundamentally impossible to enumerate every edge case in advance. This article explains the 'design for failure' mindset behind...
020
kondokentaro @kondokentaro.bsky.social · 29/07/2026
"3 replicas" isn't high availability if all three land in the same AZ. Why the World Cup broadcast never goes dark — and what it teaches K8s about Topology Spread Constraints: kubo.hexabase.io/blog/en/broa... #Kubernetes #SRE
kubo.hexabase.io
Why Does the FIFA World Cup Broadcast Never Go Dark? What Broadcast Engineering's Dual-Path Redundancy Teaches Us About Real Kubernetes High Availability
Kubernetes high availability isn't achieved simply by adding more replicas. Using the broadcast industry's SMPTE ST 2022-7 dual-path transmission as a lens, this article unpacks what Topology Spread Constraints and multi-AZ design actually mean.
000
kondokentaro @kondokentaro.bsky.social · 28/07/2026
Average CPU utilization across thousands of K8s clusters: just 8%. The culprit? "Just in case" environments. When namespaces + ResourceQuota beat separate clusters — and when they don't: kubo.hexabase.io/blog/en/kube... #Kubernetes #DevOps #CloudCosts
kubo.hexabase.io
How Many Environments Do You Really Need? Kubernetes Environment Design That Doesn't Break the Bank
Every new dev, test, and staging environment adds to your Kubernetes cloud bill. Learn how namespace isolation, ResourceQuota, and a hybrid dedicated-cluster-for-production model balance cost and isol...
010
kondokentaro @kondokentaro.bsky.social · 21/07/2026
Average CPU use across thousands of Kubernetes clusters: 8%. "Just in case" environments mostly pay for idle. New post: dedicated cluster for prod, namespaces + ResourceQuota for the rest. #Kubernetes #FinOps #DevOps kubo.hexabase.io/blog/en/kube...
kubo.hexabase.io
How Many Environments Do You Really Need? Kubernetes Environment Design That Doesn't Break the Bank
Every new dev, test, and staging environment adds to your Kubernetes cloud bill. Learn how namespace isolation, ResourceQuota, and a hybrid dedicated-cluster-for-production model balance cost and isol...
020
kondokentaro @kondokentaro.bsky.social · 17/07/2026
"You can build your own private cloud" — that's only half true. OpenStack × K3s gets you built. But the real fight is Day 2 ops: ~10 FTE/year, $700K+, upgrade hell, AI workloads… "Can build" ≠ "can run." 🔗 kubo.hexabase.io/blog/en/priv... #Kubernetes #OpenStack #PrivateCloud
kubo.hexabase.io
"You Can Build Your Own Private Cloud" Is Only Half True: What OpenStack × K3s Reveals About the Reality of Day 2 Operations
As VMware migration costs and cloud bills climb in 2026, more companies are reconsidering private cloud. This article examines the real build cost and Day 2 operational burden of self-managed OpenStac...
020
kondokentaro @kondokentaro.bsky.social · 14/07/2026
"DevOps engineers are becoming obsolete" is a lie. 🚀 AI is eating infra, but demand for MLOps + Kubernetes talent is surging (10–15% pay premium). The 5 skills every K8s operator needs to thrive in 2026 👇 kubo.hexabase.io/blog/en/mlop... #Kubernetes #MLOps
kubo.hexabase.io
"DevOps Engineers Are Becoming Obsolete" Is a Lie. 5 MLOps Skills Every Kubernetes Operator Must Master in the AI Era
As AI automates infrastructure, are DevOps engineers really becoming irrelevant? The reality is the opposite — demand for MLOps Kubernetes talent is surging. Here are the 5 skills you need in 2026.
110
kondokentaro @kondokentaro.bsky.social · 11/07/2026
By default, Kubernetes lets every pod talk to every other pod — one compromised container means network access to your entire cluster. Our new guide walks through zero trust with Network Policies: Default Deny, DNS pitfalls, Cilium vs Calico, real YAML. kubo.hexabase.io/blog/en/kube...
kubo.hexabase.io
Zero Trust Security with Kubernetes Network Policies: A Practical Guide
Implement zero trust networking in Kubernetes with Network Policies. From Default Deny to Cilium and Calico advanced policies with real YAML examples.
000
kondokentaro @kondokentaro.bsky.social · 10/07/2026
How much of your #Kubernetes budget is waste? Probably 30%+. New on the Kubo blog: a practical cost optimization guide — VPA right-sizing, spot instances, KEDA scheduling, and a full EKS vs AKS vs GKE cost comparison. kubo.hexabase.io/blog/en/kube...
kubo.hexabase.io
The Complete Kubernetes Cost Optimization Guide: EKS/AKS/GKE vs Kubo Compared
Cut your Kubernetes cloud costs by 30-50% with proven optimization strategies. Includes EKS, AKS, GKE pricing comparison and Kubo's cost advantage analysis.
000
kondokentaro @kondokentaro.bsky.social · 08/07/2026
A green build ≠ a secure image — new CVEs appear after you ship. Scan at build, in the registry, and continuously, and fail CI on criticals. Our guide to Docker image security scanning 👇 🔗 kubo.hexabase.io/blog/en/docker-security-scanning-best-practices #docker #devsecops #kubernetes
kubo.hexabase.io
Docker Container Security: Scanning and Vulnerability Management
A practical guide to integrating vulnerability scanning into your container ci-cd pipeline. Compare Trivy, Snyk, and Grype, implement shift-left security, and build defense-in-depth with Harbor.
000
kondokentaro @kondokentaro.bsky.social · 04/07/2026
K3s vs K8s: A Use-Case Driven Selection Guide kubo.hexabase.io/blog/en/k3s-...
kubo.hexabase.io
K3s vs K8s: A Use-Case Driven Selection Guide
Compare K3s and standard Kubernetes across architecture, resource usage, and use cases. Find out which Kubernetes distribution fits your project best.
010
kondokentaro @kondokentaro.bsky.social · 04/07/2026
Dockerfile Best Practices 2025: Building Lightweight, Secure, and Fast Images kubo.hexabase.io/blog/en/dock...
kubo.hexabase.io
Dockerfile Best Practices 2025: Building Lightweight, Secure, and Fast Images
Comprehensive 2025 Dockerfile best practices guide covering minimal base images, layer optimization, security hardening, BuildKit features, and production-ready container image construction.
000
kondokentaro @kondokentaro.bsky.social · 03/07/2026
Getting Started with ArgoCD GitOps: Practical Kubernetes Declarative Deployment kubo.hexabase.io/blog/en/argo...
kubo.hexabase.io
Getting Started with ArgoCD GitOps: Practical Kubernetes Declarative Deployment
A practical guide to GitOps-based Kubernetes declarative deployment with ArgoCD. Covers repository structure, Sync Waves, ApplicationSets, and multi-cluster management.
020