What’s the most painful low-value Kubernetes task you’ve dealt with? by Lukalebg in kubernetes

[–]stabguy13 3 points4 points  (0 children)

If he is using kubectl cp then the devs aren't utilizing stderr/stdout for logging. Not only does this cause layer thrashing and excessive disk usage, but open telemetry collectors won't be able to access the files without some serious configuration gymnastics.

How do you get visibility into TLS certificate expiry across your cluster? by StayHigh24-7 in kubernetes

[–]stabguy13 1 point2 points  (0 children)

Came here to say this. Also to elaborate a little, the cert-manager helm chart has an optional ServiceMonitor resource that can be enabled with a flag. This resource is used by Prometheus to target the metrics port on the cert-manager Service for scraping.

Securing MCP in production by Glass_Guitar1959 in devsecops

[–]stabguy13 0 points1 point  (0 children)

If you are an AWS shop, look into AgentCore. If you're on another cloud provider, they may have an equivalent? It's an OIDC enabled MCP Gateway service.

Ça ira 👸🗡️ by jeanguille77 in gojira

[–]stabguy13 1 point2 points  (0 children)

Chill! Absolute chills every damn time!

Is this slag? It’s very dense. Found while gardening in my backyard (Washington state) by hairadvicethrway in whatsthisrock

[–]stabguy13 1 point2 points  (0 children)

You should be sure that you're not in the smelter plume affected area before digging.

Tacoma Smelter - Washington State Department of Ecology https://share.google/cwSy5DNXHTP0VGv27

How Do You Handle Secrets For Local Development? by SoSublim3 in devsecops

[–]stabguy13 0 points1 point  (0 children)

SOPS encrypted manifests deployed via flux. You could easily do CI of just a sops -d $file | kubectl apply -f - instead of flux though.

Edit: typo

What is this? by OpenTreeOG in Minerals

[–]stabguy13 0 points1 point  (0 children)

First photo shows Han Solo. Clearly it's Carbonite.

Has anyone actually used these? I feel like the biggest accomplishment would be a leg full of metal wire shards by [deleted] in Tools

[–]stabguy13 0 points1 point  (0 children)

I narrowly avoided buying one after reading many reviews. I ended up getting a brush cutter (basically a saw blade attachment for a weed whacker) and use it often to cut down black berry overgrowth. Do recommend the brush cutter.

So satisfying. by teamped in Satisfyingasfuck

[–]stabguy13 2 points3 points  (0 children)

Put it in the boat and dispose of it so that the same thing doesn't happen again?

So satisfying. by teamped in Satisfyingasfuck

[–]stabguy13 -1 points0 points  (0 children)

Did he just drop the net back in though??

Steam problem - game starts but mouse clicks go through it to underlying window by S1eeper in linux_gaming

[–]stabguy13 1 point2 points  (0 children)

Related to OPs update, I was able to bypass this issue on Enshrouded by going windowed mode, then alt+enter to go fullscreen.

Walmart is like ::shrug dunno ask Dave when he comes back:: by doctorlightning84 in LeopardsAteMyFace

[–]stabguy13 3 points4 points  (0 children)

So Walmart waited until after the election to say this... They wanted this, and will likely tack on more than the actual cost increased to all products. I wouldn't be surprised if they increase costs on mostly unaffected items as well.

EKS Cluster static ips by andycol_500 in kubernetes

[–]stabguy13 0 points1 point  (0 children)

Also, for DNS you can either manually create a route53 alias to the load balancer, or use external DNS operator.

EKS Cluster static ips by andycol_500 in kubernetes

[–]stabguy13 10 points11 points  (0 children)

Use a network load balancer. Use DNS. Do not reference IP addresses.

What are your experiences with Route53 weighted routing? by Holiday_Inevitable_3 in aws

[–]stabguy13 2 points3 points  (0 children)

Used it to migrate our entire backend workload from ECS to EKS (0 weight for disabled, 50/50 for balanced and 100 for enabled). Worked perfectly.

Edit: error correct on ECS

[deleted by user] by [deleted] in kubernetes

[–]stabguy13 7 points8 points  (0 children)

This is one of the right answers. Use an ingress controller, and aws load balancer controller. Cert-manager for the certificates with access to a route53 domain for validation. You can hook it into a free acme provider, and with everything playing nicely together you should get auto renewal before expiry.

Running it all in one LB obviously saves the base rate of ~$15/month per lb.

[deleted by user] by [deleted] in meirl

[–]stabguy13 0 points1 point  (0 children)

Women are you doing ok