✕ Clear all filters
41 articles
▶ Videos →

📰 Dev.to · david

41 articles · Updated every 3 hours · View all reads

All Articles 173,167Blog Posts 163,817Tech Tutorials 46,199Research Papers 33,874News 21,839 ⚡ AI Lessons
Self-Hosted SSO for 25 Services: Authelia OIDC on Kubernetes
Dev.to · david 🔧 Backend Engineering ⚡ AI Lesson 3w ago
Self-Hosted SSO for 25 Services: Authelia OIDC on Kubernetes
How a single Authelia instance protects Proxmox, PBS, Grafana, ArgoCD, Headscale, and 20+ web apps with OIDC — CNPG-managed Postgres, Redis sessions, hmac_secre
A 7.5B model beat a 24B on my coding benchmark.
Dev.to · david 📐 ML Fundamentals ⚡ AI Lesson 1mo ago
A 7.5B model beat a 24B on my coding benchmark.
16 local model configurations, 56 hidden-test coding tasks, 36 full runs, one 16 GB...
How a Single Volume Was 65% of My Velero Backup and What I Almost Excluded Instead
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
How a Single Volume Was 65% of My Velero Backup and What I Almost Excluded Instead
The nfs-provisioner's root-mount volume was backing up the entire shared NFS export as one 33.4GB blob every night — redundant because every app's PVC was alrea
Zero NetworkPolicies on Vault: How I Found the Biggest Gap in My Cluster and a GitOps Tracking Bug That Hid It
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
Zero NetworkPolicies on Vault: How I Found the Biggest Gap in My Cluster and a GitOps Tracking Bug That Hid It
Vault is the trust root every ExternalSecret reads from. Its namespace had zero NetworkPolicies — any pod in the cluster could reach it. The investigation also
Renovate OOMKilled Three Times: Why the Fix Wasn't More Memory
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
Renovate OOMKilled Three Times: Why the Fix Wasn't More Memory
Two GiB wasn't enough, so I bumped to 3 GiB. Still OOMKilled. Bumped to 4 GiB. Still OOMKilled. The real fix wasn't memory at all — it was Terraform hash concur
Kubernetes Health Probes: The Host Header Trap That Restarts Healthy Pods
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
Kubernetes Health Probes: The Host Header Trap That Restarts Healthy Pods
Adding health probes to 20+ workloads taught me that kubelet sends the Pod IP as the Host header — and apps with host-validation reject it. Here's the full swee
Zero NetworkPolicies on the Database Namespace: The Gap That Let Any Pod Reach Authelia's Postgres
Dev.to · david 🔐 Cybersecurity ⚡ AI Lesson 1mo ago
Zero NetworkPolicies on the Database Namespace: The Gap That Let Any Pod Reach Authelia's Postgres
The database namespace holding Authelia's session storage had no network restrictions. Any pod in the cluster could reach it. Here's the audit that found it, th
Migrating Atlantis to an LXC Accidentally Made It Fully Public
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
Migrating Atlantis to an LXC Accidentally Made It Fully Public
Moving Atlantis from Kubernetes to a dedicated LXC involved repointing the Cloudflare Tunnel. The new tunnel pointed straight at the LXC's IP, bypassing Traefik
310 Restarts in 21 Days: CNPG's Silent PodMonitor Failure and the Leader-Election Trap
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
310 Restarts in 21 Days: CNPG's Silent PodMonitor Failure and the Leader-Election Trap
CloudNativePG's auto-generated PodMonitor was missing a single label — Prometheus never scraped it. The same I/O fragility that causes etcd timeouts was trigger
Beszel: Lightweight Host Monitoring That Doesn't Deserve Its Own Server
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 1mo ago
Beszel: Lightweight Host Monitoring That Doesn't Deserve Its Own Server
Why I replaced a heavyweight monitoring stack for host-level metrics with a single container, how Kyverno caught my first deploy before it hit production, and w
The .gitleaks-baseline.json That Suppressed Live Production Secrets
Dev.to · david 🔐 Cybersecurity ⚡ AI Lesson 1mo ago
The .gitleaks-baseline.json That Suppressed Live Production Secrets
A gitleaks baseline file is supposed to suppress known-false-positive findings. It turned out to be suppressing the live rpc_secret and admin_token for a produc
Redis Killed Nextcloud and Nobody Noticed for Hours
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
Redis Killed Nextcloud and Nobody Noticed for Hours
Redis running without a PVC still has persistence enabled by default. When it can't write RDB snapshots to a read-only rootfs, it doesn't crash — it silently re
kubectl Said Everything Was Correct. Traefik 404'd Anyway.
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
kubectl Said Everything Was Correct. Traefik 404'd Anyway.
Migrating Jellyfin off k3s onto a GPU-passthrough LXC meant pointing a Service at an external IP. The EndpointSlice looked completely correct via kubectl — Serv
SLO Burn-Rate Alerting with Prometheus: Beyond Threshold Alerts
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
SLO Burn-Rate Alerting with Prometheus: Beyond Threshold Alerts
Most teams alert when availability drops below a threshold. Burn-rate alerting tells you how fast you're spending your error budget — so you page on trajectory,
I Hardened Pod securityContext and Broke 9 Containers in Production
Dev.to · david 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
I Hardened Pod securityContext and Broke 9 Containers in Production
capabilities.drop: [ALL] and runAsNonRoot: true passed schema validation cleanly. Within minutes of merge, nine containers — including both Postgres instances b
Hardening Unattended Raspberry Pi Edge Nodes: Watchdog, fail2ban, nftables, and the Mistakes That Take Down DNS
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
Hardening Unattended Raspberry Pi Edge Nodes: Watchdog, fail2ban, nftables, and the Mistakes That Take Down DNS
Two Raspberry Pis run DNS for an entire network with no one watching them most of the time. A hardware watchdog, fail2ban, an additive nftables host firewall th
My Firewall Had 77 Rules. Terraform Knew About 22 of Them.
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
My Firewall Had 77 Rules. Terraform Knew About 22 of Them.
Multiple rounds of 'reconstruct the firewall' work each added a fresh generation of rules without removing the old one. Because RouterOS evaluates rules in orde
Kyverno: Supply Chain Security as Admission Control on Kubernetes
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
Kyverno: Supply Chain Security as Admission Control on Kubernetes
Most Kubernetes clusters accept any container image, any privilege level, and any resource configuration by default. Kyverno lets you enforce policies at admiss
I Ran Gitleaks Against My Own Repo and Found 12 Real Secrets
Dev.to · david 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
I Ran Gitleaks Against My Own Repo and Found 12 Real Secrets
A full-history gitleaks scan of a homelab repo that had been running for months turned up 12 distinct plaintext secrets — including an OIDC signing key. Here's
ArgoCD Gotchas: Cache Staleness and the SharedResourceWarning Nobody Explains
Dev.to · david ☁️ DevOps & Cloud ⚡ AI Lesson 2mo ago
ArgoCD Gotchas: Cache Staleness and the SharedResourceWarning Nobody Explains
kubectl apply succeeds, the field reverts within seconds, and there's no error anywhere. Two ArgoCD debugging patterns that hit the same homelab three times in