category

uncategorized

40 articles

A Briefer History of Argo Project from the Founding Engineers

Argo is a popular open-source project that helps engineers unleash the full power of Kubernetes and significantly increase productivity. The project consists of four main products that focus on various use cases and together comprise a powerful application delivery platform. The

A Visual Guide on Troubleshooting Kubernetes Deployments

Troubleshooting in Kubernetes can be daunting if you don't know where to start. I attached a visual guide to help you troubleshoot Kubernetes deployments. It covers:🔹 Connecting Deployment and Service🔹 Connecting Service and Ingress🔹 Troubleshooti

Advertising IoT Devices as Extended Resources in Kubernetes w/ Akri

Kubernetes is powerfully declarative. When deploying a Pod, you can specify memory and CPU resource limits, so your application will have all the resources it needs. A few years ago, Kubernetes created the Device Plugin framework to allow other resources to be requested. It was c

Architecting your Stack: Why Video Platform, Mux, Went All in on Kubernetes

Kubernetes is hard, so making the decision to run it on your own, in a multi-cloud environment may seem like a bold choice. At Mux, it's a choice we've made to help power our Video API and quality of experience analytics, and it's served us well. At this meetup, Ad

Automate Microservice to API by using Kubernetes Operator Pattern

The recent constraints on businesses have pushed organizations to accelerate their plans for moving operations to the digital world—often shrinking timelines from years to months to weeks. Microservices architecture (MSA) is critical to accomplish fast innovation, and the AP

Building an Application-centric Kubernetes Platform for Enterprise Scale

Building an Application-centric Kubernetes Platform for Enterprise Scale, w/ Todd Ekenstam of Intuit, and our host will be Michael Bowen of BlackRock. 📅 Date: Tuesday, February 22nd, 2022📍 Time: 10 am PST to 11:30 am PST (1:00 - 2:30 pm EST) Over the past se

Building and running a world-class observability function

Observability teams as a centralized function within SRE or IT Operations are a relatively recent phenomenon. These teams are responsible for managing the monitoring and observability toolset and empowering developer and engineering teams to push the right data into the systems t

CNCF Incubating projects showcase: NATS, Thanos and Flux

In this showcase event, we will be discussing the value proposition, key features, and latest updates on the following popular incubating projects. 🔶 NATS.io: https://nats.io/Colin Sullivan, Product Manager (Synadia)NATS is a connective technology built for the ever in

Event Driven and Cloud Native Systems: Solving the interoperability puzzle

CloudEvents is a CNCF backed specification for describing event data in a common way that makes sense for enterprises. In this Meetup, Rajesh Iyer will deep dive into this new spec and looks into how CloudEvents can simplify event declaration and delivery across services, platfor

Events first: cloud-native patterns beyond request/response

Going cloud-native is about how we design our applications, not just how we deploy them — and one key choice in distributed systems design is how our applications interact with each other. Request/response-based protocols are ubiquitous in software today, but the industry is

GitOps and Progressive Delivery with Flux, Istio, and Flagger

Having in our minds the very high level of service expected by our customers, we were urged to build our architecture as resilient and reliable as we could. That brought us many challenges, from scalability to observability, from multi-cluster and multi-region deployments to mana

GitOps on Kubernetes: Deciding Between Argo CD and Flux

Argo CD and Flux both have their uses, and both are pretty well maintained and have active communities. Similarities:🔹 Secrets Management🔹 Webhook Receivers🔹 Alerting and Notifications🔹 Image Updates Automation Differences:🔸

GitOps One-Stop Shop Event!

⭐️ ⭐️ This is a cross promotional post from the GitOps Community Meetup Group ⭐️ ⭐️ (https://www.meetup.com/GitOps-Community) Please register in advance at www.gitopsdays.com or via zoom:https://weaveworks.zoom.us/webinar/register/WN_iBK5tO

Integrate OPA (Open Policy Agent) with Istio & Styra DAS

In this blog, you will learn how OPA embedded in the Istio data plane can be used as an authorization service to enforce security policies over API requests received by Istio. What is Istio? Istio is an open-source service mesh that layers transparently onto existing distributed

Integrating Kong Mesh with Styra DAS

In this blog, you will learn how to add a policy in Styra DAS to Integrate Kong Mesh With Styra DAS. What Is Kong Mesh? Kong Mesh is an enterprise-grade service mesh that runs on both Kubernetes and VMs on any cloud. Built on top of CNCF's Kuma and Envoy and focused on simpl

Integrating Kubernetes with Styra DAS – Enforcing users to create pods in the default namespace.

In this article, you will learn how to enforce users to create pods by default Kubernetes namespace using OPA and Styra DAS. Pre-requisites: Styra-DAS Account (You can sign-up and create a free Styra DAS account here)Kubernetes cluster (You can create a Kubernetes cluster using K

Integrating Kuma with Styra DAS

In this blog, you will learn how to install Kuma on a Kubernetes cluster and add ingress policies in Styra DAS to integrate Kuma with Styra DAS. What is Kuma? Kuma is a platform-agnostic open-source control plane for service mesh and microservices management, with support for Kub

Integrating OPA With Envoy on Styra DAS

Styra DAS: The Styra Declarative Authorization Service (DAS), built on top of the open-source project Open Policy Agent (OPA), provides a single pane of glass for authorization and policy across the cloud-native ecosystem of software systems. Using the DAS allows you to use a sin

Integration of Envoy with OPA and Styra DAS

In this blog, you will learn how to add a policy in Styra DAS to Integrate Envoy with OPA and Styra. OPA (Open Policy Agent): The Open Policy Agent (OPA, pronounced 'oh-pa') is an open-source, general-purpose policy engine that unifies policy enforcement across the stac

Introduction to Kubernetes Components and K8s Architecture

When you have hundreds to thousands of containers serving a lot of microservices, K8s allows you to monitor and manage (orchestrate) all those containers in an easy way allowing fault-tolerance, high availability, disaster recovery, and high performance. There are two ways to int

MOVING TO THE CLOUD – Unlearning Modern Techniques

In the times during and after the pandemic, technology is driving change. Businesses are forced to reinvent themselves to be relevant. Cloud-native technologies make scaling easier, deployments faster, and computing costs lower. In this meetup, Kevin Hoffman, Distinguished Engine

Not Your Grandma Gossip: Node Failure Detection at Scale

Several distributed protocols are predicated on a large number of nodes relying on each other to complete transactions; for example, highly durable persistence storage depends on data being replicated several times across nodes: while this improves the system's resilience to

OPA, Styra and Terraform: protect your cloud

Introduction to Styra DAS: Styra Declarative Authorization Service (DAS), built on top of the open-source project Open Policy Agent (OPA), provides a single pane of glass for authorization and policy across the cloud-native ecosystem of software systems. Using the DAS allows you

Open Policy Agent: What Is OPA and How It Works (Examples)

Open Policy Agent is an open-source engine that provides a way of declaratively writing policies as code and then using those policies as part of a decision-making process. OPA can be used for several purposes:🔹 Authorization of REST API endpoints.🔹 Allowing

Scaling Kubernetes across BlackRock's Aladdin Platform

📅 Date: Tuesday, January 11th, 2022📍 Time: 10 am PST to 11:30 am PST (1:00 - 2:30 pm EST) BlackRock has always pushed technical boundaries and innovation to deliver asset management capabilities to clients through the investment and risk management platform,

Scaling Observability: GRAFANA LABS, POLAR SIGNALS, & PIXIE LABS

Tales from the front lines of scaling observability panel discussion w/ GRAFANA LABS, POLAR SIGNALS, & PIXIE LABS 📅 Date: Tuesday, March 22nd, 2022📍 Time: 10 am PST to 11:30 am PST (1:00 - 2:30 pm EST)📺Venue: Zoom Webinar Speakers: 🔶 Jo

Security & Compliance Showcase w/ FALCO, KYNERO, CURIEFENSE, & MORE

CNCF Security & Compliance Product Showcase w/ FALCO, KYNERO, CURIEFENSE, & MORE This meetup will look at some of the most popular security and compliance projects under the CNCF umbrella. These tools can help teams apply policy management, check CVEs, ensure regulatory complianc

Security & Policy Configurations for Infrastructure as Code

When you use cloud infrastructure, you might find yourself accidentally applying a configuration for an open storage bucket, unencrypted queue, or unrestricted access control. At worst, these misconfigurations can be exploited by bad actors. At best, they get duplicated across an

Shared components in a Cloud-Native world

Engineering orgs aim to create the thinnest viable platform to reduce the cognitive load on their dev teams. The role of a TVP is critical if you want to scale your team, abstract 'meaningful' components with libraries and ship security patches to production in a breeze

Styra DAS, OPA, and Envoy Integration Give You Fine-Grained Access Control Over Microservice API Authorization.

What is Envoy? Envoy is an L7 proxy and communication bus designed for large modern service-oriented architectures. Envoy supports an External Authorization filter which calls an authorization service to check if the incoming request is authorized or not. This feature makes it po

SUPPLY CHAIN SECURITY: Securing Integrity of Software Supply Chains

📅 Date: Tuesday, March 8th, 2021📍 Time: 10 am PST to 11:30 am PST (1:00 - 2:30 pm EST) Securing a software supply chain is a complex task. There are many moving parts, external dependencies, difficulties to ensure all holes are plugged tight and sometimes it

Tales from the Branches – GitOps in the Real World

Panel Discussion: Tales from the Branches - GitOps in the Real World This panel discussion will explore GitOps from an end-user perspective, discussing what works as well as the new challenges GitOps creates. If your organization is considering a move to a GitOps model, this pane

[Talk #13] Where's my container? Visualizing the GitOps Container Journey

GitOps has become the de facto approach for enabling simple, secure, and auditable deployments. However, when you deploy to multiple Kubernetes clusters, knowing where your services are in the GitOps journey can be challenging. It can be almost impossible to track permutations of

[Talk #14] Observability showcase: Jaeger, OpenSearch, OpenTelemetry

In this showcase event, we will be discussing the value proposition, key features, and latest updates on the following popular Observability projects. 🔶 [Speaker 1] Jaeger: https://www.jaegertracing.io/Joe Elliott, Principal Engineer @ Grafana LabsJoe Elliott has been

[Talk #16] Helm + Flux: Feature Showcase & Demo

Martin Hickey (Helm maintainer) and Scott Rigby (Helm and Flux maintainer) present a feature showcase and demos of both Helm and Flux, reasons for the overwhelming community use of Helm for application packaging and deployment on k8s, and how Helm is extended by Flux for teams mo

[Talk #17] Open source ELK with OpenSearch

In this talk, we will explain the background and history of ELK and how open source is changing for the worse. This is very relevant to the users of CNCF projects and how it will impact the technologies they use. We will go into detail about the OpenSearch community, contributors

[Talk #18] Firecracker + Liquid Metal: Intros & Edge Use Case

Come see how Firecracker and Liquid Metal can be used to get the most out of your bare-metal and transform your edge or data-centre. We'll start by covering Firecracker, the engine powering the AWS Lambda & Fargate service, a technology with security, isolation and efficienc

[Talk #19] Taming microservices through an evolved DevOps Pipeline

Microservices are a critical part of the overall Cloud-Native journey. They are key to achieving the promise of agility that this modern platform offers. The problem with microservices is that they are a major disruption to how we design, develop and release software. In addition

[Talk#15] The Power of Three: Flux, Flagger, & Linkerd

Join us for this exciting event where you'll get an overview and update on CNCF Projects Flux and Flagger (Incubating), and Linkerd (Graduated), then see the power of three when these projects are combined (in a live demo) to offer a robust and automated GitOps experience!

The Evolution of Distributed Systems on Kubernetes

Future distributed systems on Kubernetes will be composed of multiple runtimes. The business logic forms the application's core, and sidecar 'mecha' components offer robust out-of-the-box distributed primitives. What about what comes after microservices? According to Bilgin Ibr