Blog Entries

01. 10. 2026 Daniel Vedovato DevOps, Kubernetes, NetEye

Planning Kubernetes Networking for a NetEye 4.49 Upgrade: The Service LoadBalancer CIDR

Upgrading an existing NetEye cluster to 4.49 introduces a networking question that’s easy to underestimate. The existing environment may already have everything we normally associate with a NetEye cluster: a corporate network for frontend access and integrations, a private trusted network for internal cluster communication, and the corresponding virtual IPs. With Kubernetes entering the architecture…

Read More
30. 09. 2026 Davide Sbetti Automation, Development, Kubernetes, NetEye

Fewer Builds, More Testing: The New CI Behind the NetEye Operator

At NetEye we’re always working towards more and more integration with Kubernetes. The NetEye Operator is the first piece of that journey we’re working on, with the goal of obtaining a component that ships as a Kubernetes operator rather than as an RPM. The process of building it gave us a rare opportunity, a chance…

Read More
30. 09. 2026 Alessandro Taufer DevOps, Kubernetes

How Kubernetes Pods Actually End Up on a Node

Scheduling Roulette Imagine you’ve applied a deployment, run kubectl get pods, and now there they are: Every Pod is neatly sitting on some node. It feels a bit like roulette. You spin the wheel, and the Pod lands wherever it happens to land. The good news is that wheel is not as random as it…

Read More
30. 09. 2026 Luigi Miazzo Development, Kubernetes

Who Really Owns a Kubernetes LoadBalancer IP with Cilium?

When using Kubernetes on bare metal, exposing a LoadBalancer Service usually requires some mechanism to make the Service IP reachable from the surrounding network. With Cilium, one possible solution is L2 Announcements. Cilium can answer ARP or NDP requests for the LoadBalancer IP, effectively making that IP reachable from the local network. At first sight,…

Read More
24. 09. 2026 Gabriele Bocchi Automation, Development, DevOps

Why Your Dotfiles Deserve Version Control

If you spend enough time working on Linux, your home directory slowly becomes a reflection of how you like to work. A few aliases are added to your shell. Git gets its own configuration. Your editor starts accumulating plugins and custom keybindings. The terminal gets some additional settings, and eventually even tools you barely remember…

Read More
03. 07. 2026 Oscar Zambotti Development, DevOps, Kubernetes

Building a Local AWS Dev Environment with Floci – Part 1: EKS and ECR

We’re developing a software product whose production environments run entirely on AWS. Keeping local development as close as possible to those environments is important to us: It reduces surprises when deploying, shortens the feedback loop when debugging infrastructure-related issues, and means developers can work confidently without needing access to a shared cloud account. To achieve…

Read More
30. 06. 2026 Alessandro Taufer APM, DevOps, Kubernetes

Simplifying Multi-cluster Kubernetes Monitoring with EDOT

There’s a particular kind of irony in watching your observability stack become the thing you most need to observe. That’s more or less our day job, and it’s why we tend to be unusually deliberate about tooling decisions: The small ones have a habit of compounding over time. So when it came to choosing a…

Read More
30. 06. 2026 Alessandro Valentini Automation, DevOps, Kubernetes

K8s Secrets: Why We Migrated from SealedSecrets to ExternalSecrets

For a long time, Sealed Secrets was our go-to solution for managing confidential data like database credentials, tokens and private keys within Kubernetes. However, as our operations grew, the operational overhead of this approach led us to migrate to External Secrets. This transition has significantly streamlined our workflow, enhanced our security posture during credential rotations,…

Read More
30. 06. 2026 Davide Sbetti AI, Kubernetes

Load-balancing Requests to LLMs in Kubernetes: A KV-cache Approach with llm-d!

Hi everyone 😃 Today I’d like to walk you through some experiments we ran about load-balancing requests to LLMs in Kubernetes. Let’s dive deep into it! Why Deploy LLMs in Kubernetes? Well, Kubernetes has now established itself as a leading technology when it comes to workloads orchestration. And with time the increasing support for accelerators…

Read More
29. 06. 2026 Luigi Miazzo APM, Kubernetes

Beyond Utilization: Understanding Pressure Stall Information

One of your servers is reporting moderate CPU usage, enough available memory, and storage that’s busy but not saturated. The dashboard looks healthy, the application does not. Requests to it are slowing down, background jobs are taking longer, and latency is rising even though no resource appears fully exhausted. The problem here is that most…

Read More
22. 06. 2026 Gabriele Bocchi Automation, Development, DevOps

Your GitHub Organization Is Infrastructure Too

In a previous post, I wrote about the challenges of building a public GitHub organization correctly: The need for structure, consistency, and enforcement rather than relying on memory. What I didn’t cover was how we actually solved it. The short answer: We treat the organization as infrastructure. Repositories, teams, branch protection rules, labels, permissions, all…

Read More
21. 05. 2026 Francesco Penasa APM, Kubernetes

Observability on OpenShift: A Case Study with Red Hat OpenTelemetry and eBPF

How we adapted our monitoring approach when the default choice didn’t fitand what we learned along the way. You’ve probably been there. You walk into a new observability project, playbook in hand, only to realize that no two projects are ever really the same. Every team has its own tools, its own platform quirks, and…

Read More
31. 03. 2026 Alessandro Taufer DevOps, Kubernetes

Abusing Trust Boundaries between TLS and HTTP

A Simple Reverse Proxy Might Turn out to Be Dangerous Sometimes we inadvertently make assumptions that undermine our infrastructure security. In today’s article I want to share with you one of the most common mistakes that are made when setting up a reverse proxy. As always, real world use cases are the best ones to…

Read More
27. 03. 2026 Gabriele Bocchi Automation, Development, DevOps, NetEye

From Private to Public: Building a Secure GitHub Organization

Creating a GitHub organization is easy. Creating a public one that is actually well-structured, secure, and maintainable over time… not so much. At the beginning, it feels like a simple task: create the org, push some repositories, maybe define a couple of teams, and you’re done. But as soon as things become public, the whole…

Read More
27. 01. 2026 Simone Ragonesi Automation, Development, DevOps, Offensive Security, Red Team, SEC4U

Architecting a Portable Red Team Engine

This is the first article in the RTO series The Problem Red team and penetration testing activities are full of repetition: the network scans, reconnaissance, OSINT collection, and routine validation tasks are all necessary, but they’re also time-consuming and error-prone when executed manually. Over time, most teams end up with a zoo of scripts, half-maintained…

Read More

Archive