kubernetes Public Project or Nothing: The Proxy-Cache Setting That Is Not a Preference The kubelet pulls with no imagePullSecrets at all — 32 of 32 pods pull from harbor/dockerhub and it works only because the project is Public. Copying the 'apps' project's Private setting took two workloads down.
vap Phase In a Binding, Not a Policy With native VAP, the grace period lives in the binding's validationActions, never in the policy object. The same four violating Pods still report as failures under [Warn, Audit] — but the run exits 0, and phase 3 is opt-in by namespace label.
vap Native ValidatingAdmissionPolicy vs Kyverno, Same Two Controls The registry allow-list and the digest-pinning control were reimplemented as native CEL ValidatingAdmissionPolicies and run against the identical fixtures. Same verdict on every Pod — and CEL's messageExpression names the offending image.
platform-engineering The Registry Routing Campaign: Two of Nine, and Why It Goes One at a Time Routing upstream registries through Harbor is three separate jobs per registry — create the cache, enable the rule, move the workloads — and the campaign only works done one registry at a time, safest first.
containers Your 12,064 Findings Are Lying to You: Counting Images, Not Reports, with the Trivy Operator Trivy Operator emits one VulnerabilityReport per workload, not per image. Sum the reports and you double-count everything. Here is the jq that gets the real number.
GCP Implement DevOps Workflows in Google Cloud: Challenge Lab This is from the Arcade October 2024 Series and also Implement DevOps Workflows in Google Cloud course. This tutorial covers the Lab "Implement DevOps Workflows in Google Cloud: Challenge Lab", code: GSP330. Overview In a challenge lab, you’re presented with a scenario and a series of tasks.
GCP Continuous Delivery with Jenkins in Kubernetes Engine This is from the Arcade October 2024 Series. This tutorial covers the Lab "Continuous Delivery with Jenkins in Kubernetes Engine", code: GSP051. We will learn how to use Jenkins to set up a continuous delivery pipeline on the Kubernetes engine. Developers who often integrate their code in a