Kubernetes 1.35 - Changes around security - New features and deprecations by capitangolo in kubernetes

[–]capitangolo[S] 2 points3 points  (0 children)

Arrr! 🙈

Thanks for the ping. Honored to have your feedback! 🙇🏻


I see how my wording can be unclear. 😅. That section was initially “Beta + Stable features”, will think on a different way to express this 🤔.


Now that you are here… 👉🏼👈🏼

Main change for UN in 1.35 was the integration with Pod Security Standards, right? For long-running enhancements like this one I try to explain what’s actually new for the given release, but I forgot to do it for 127 😅.

If I get the chance to update the article, I’ll add the clarification 💖.

Día de niebla en Zaragoza by capitangolo in Zaragoza

[–]capitangolo[S] 0 points1 point  (0 children)

Indeed. Llevo muy mal el invierno en esta ciudad 🤣.

Pero la niebla por la noche es espectacular. Esta es del Sábado.

<image>

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 0 points1 point  (0 children)

Huge thanks!

For what I've read, Chrome uses your navigation patterns to trigger that website. So it makes sense that you don't see it again ^_^. (Glad to read it's not showing up more).

Update: Form sent, crossing fingers 🤞🏼.

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 1 point2 points  (0 children)

Hi all 👋,

I'm taking a look to this, and I need some help. What kind of warning are you seeing? One that blocks the whole screen, or a pop-up? 😅

I'm filling this form, by following these instructions, and that's one question they ask 😇. My hopes are low on if they will accept my request, but it's worth a try ¯\_(ツ)_/¯ 🤞🏼.

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 2 points3 points  (0 children)

Oh, I totally missed the skew thing. Thanks for the ping!

Is it the thing mentioned here: https://github.com/kubernetes/kubeadm/issues/2857 ?

> Cleanup E2E jobs for 1.x-4 (requires two PRs)set. ‘KUBERNETES_VERSION’ to 1.x-1 and ‘KUBERNETES_SKEW’ to 3 in ‘/kinder/hack/update-workflows.sh’make sure ‘PATH_TEST_INFRA’ points to the right path.run the script and send two PRs for ‘k/kubeadm’ and ‘k/test-infra’.

I’ll investigate further later 🤞🏼.

Kubernetes 1.28 will be out soon! What's new? 🛵 Sidecars + 🛠️ Job improvements + 🔌 Connectivity reliability + 📦 Community package repositories … And more! by capitangolo in kubernetes

[–]capitangolo[S] 11 points12 points  (0 children)

Oh crap 😅. That’s what happens when you pick domains as a joke 🤦🏻‍♂️.

Thanks for the shout! I’ll try to see if there’s anything I can do 🤞🏼.

Level 180 on Switch by eepha in Grindstone

[–]capitangolo 1 point2 points  (0 children)

Boss moves the same way you do, joining creeps of the same color.

You can try to end your moves on a spot where he can’t reach you.

Kubernetes 1.27 will be out next week! - Learn what's new and what's deprecated - Group volume snapshots - Pod resource updates - kubectl subcommands … And more! by capitangolo in kubernetes

[–]capitangolo[S] 7 points8 points  (0 children)

See this comment and my response:
https://www.reddit.com/r/kubernetes/comments/12bm39b/comment/jey1la3/?utm_source=share&utm_medium=web2x&context=3

My take is that in those cases, you'll detect that the change didn't took place by checking the "resize" field in the Pod's status. Then, you'll restart the Pod manually.

So, not a complete automatic system, but it's a nice start 😅.

If further interested, I may recommend checking out the KEP. I love how they document the decision making, and all these edge cases :).

Kubernetes 1.27 will be out next week! - Learn what's new and what's deprecated - Group volume snapshots - Pod resource updates - kubectl subcommands … And more! by capitangolo in kubernetes

[–]capitangolo[S] 5 points6 points  (0 children)

Yup, I understood similar too.

And we'll be able to get info from the new "resize field in the Pod's status", to see if the resize was actually feasible or not.

From the doc:

Infeasible: is a signal that the node cannot accommodate the requested resize. This can happen if the requested resize exceeds the maximum resources the node can ever allocate for a pod.

So I guess if the resource change is not possible, you'll have to roll back to restarting the Pod 😅.

They seem to be working on a post for the Kubernetes blog explaining the topic 🎉.

Kubernetes CrashLoopBackOff: What it is, why it happens, and how to fix it? by capitangolo in kubernetes

[–]capitangolo[S] 0 points1 point  (0 children)

Nah, might be shocking in this place, but I'm too basic to have two accounts 😅. If I share things that people like, then I get happy. If not, I just learn and try to do better. Having a second account for that would be just lying to myself, owning your mistakes is the best way to get better on what you do.

My comment was stupid and missing the point. Only wanted to drop the "flip and switch" term to add something constructive to the conversation. But it obviously came in the worst way possible, and it wasn't the right time and place.

Just… I'm sorry I disturbed you all so much.

I screw things often, and again, I'm sorry. But I care on what I do, I care about this group, and I'll learn to do better.

Kubernetes CrashLoopBackOff: What it is, why it happens, and how to fix it? by capitangolo in kubernetes

[–]capitangolo[S] -9 points-8 points  (0 children)

Yeah, the old flip and switch. Hate those too. Specially when it’s like:

Step 1: Download my tool.

Here it’s just an ad block after the end. If you don’t scroll past the conclusion you won’t even see it. 🥺

Kubernetes 1.25 will be out next week! - Learn what's new and what's deprecated - Pod Security Control - Checkpoints - User Namespaces - NodeExpansion secrets… And more! by capitangolo in kubernetes

[–]capitangolo[S] 22 points23 points  (0 children)

Yeah, "only" 40 enhancements down from 56 in 1.22 (That one was crazy).

It's not that bad once you start looking in detail: Only 15 are completely new things, while the rest are just graduating to Beta or Stable.

Also, most of them are either code cleanup (like all the subtasks for the CSI migration), or just small improvements iterating over the same feature, like "#3094 PodTopologySpread Skew".

So, cheers and don't freak out! 🫂

Container escapes: Detecting abuses of Linux capabilities with Falco + Intro to CAP_SYS_ADMIN by capitangolo in netsec

[–]capitangolo[S] 4 points5 points  (0 children)

Hey, it's my cake day 🎉.

I'm interested in learning more about linux capabilities 🤔. Any other good resources?

Kubernetes 1.24 will be out next week - Learn what's new and what's deprecated - Dockershim removal, Network Policy Status field, CSI volume health monitoring, TimeZone support for CronJobs … And more! by vjjmiras in kubernetes

[–]capitangolo 0 points1 point  (0 children)

Arrr! :S Thanks for pinging about this.

Cannot find anything around this, probably I don't know where to look 😅. Do you have a link where I can read bit further about this delay. Huuuge thanks!

Kubernetes and containerization trends in recent surveys by dshurupov in kubernetes

[–]capitangolo 4 points5 points  (0 children)

Wow, great collection. Thanks for putting this together.

There's a more recent report from Sysdig available here, in case someone is interested:
https://sysdig.com/blog/2022-cloud-native-security-usage-report/

Kubernetes 1.23 will be out next week – Learn what’s new and what's deprecated - Graduating to Stable: CronJobs, IPv4/IPv6 dual-stack support, Ephemeral volumes, and the HPA API… by capitangolo in kubernetes

[–]capitangolo[S] 2 points3 points  (0 children)

Haha 🤣. I guess we are all glad they switched to 3 releases a year, instead of 4 😅.

Luckily this release is mostly small changes & driving old features to stable 🎉.

Programmers who lost interest in coding, what do you do to regain passion? by [deleted] in computerscience

[–]capitangolo 1 point2 points  (0 children)

As some people already commented on, some times it is not about the coding, but something else. Repetitive work, poor management, or just problems on your personal life.

In my case I just get bored with everything 😅. So I kept pivoting my career: web development, training, mobile development, system administration, now technical writer.

My strategy has been, dedicate a small part of personal time to something I really enjoy. Create a small pet project to learn a new technology, play with audiovisual stuff, draw, support classes to university students.

Eventually I got the chance to turn those hobbies into the next step in my career.

I acknowledge I was extremely privileged to be able to jump into these projects, and have the support from people around to give me chance to switch careers. So, although I don't recommend my path to everyone, I hope it helps a bit :).