Skip to content
#devops 64 #kubernetes 61 #aws 55 #terraform 31 #security 31 #networking 25 #platform-engineering 15 #engineering-culture 13 #career 11 #containers 11 #eks 10 #observability 10 #docker 8 #vpc 7 #ecs 7 #migration 7 #leadership 6 #finops 6 #gitops 6 #cicd 6 #iac 6 #fargate 6 #cost-optimization 6 #production 5 #infrastructure 5 #automation 5 #github-actions 5 #sre 5 #cilium 5 #linux 5 #dns 5 #gke 5 #zero-trust 5 #productivity 4 #iam 4 #ci-cd 4 #testing 4 #privatelink 4 #reliability 4 #oidc 4 #mtls 4 #database 4 #advice 4 #localstack 4 #postgresql 4 #kind 4 #performance 4 #lambda 4 #control-tower 3 #service-catalog 3 #organizations 3 #backstage 3 #rds 3 #incident-management 3 #developer-experience 3 #ebpf 3 #clawdbot 3 #s3 3 #databases 3 #k8s 3 #traefik 3 #metrics 3 #monitoring 3 #ec2 3 #deployment 3 #deployments 3 #cni 3 #elasticsearch 3 #debugging 3 #kubectl 3 #gateway-api 3 #helm 3 #homelab 3 #on-call 3 #aks 3 #autoscaling 3 #opa 3 #remote-work 3 #opentelemetry 3 #serverless 3 #karpenter 2 #sso 2 #multi-account 2 #scps 2 #spacelift 2 #act 2 #governance 2 #bgp 2 #hybrid-cloud 2 #post-mortems 2 #idp 2 #github 2 #service-mesh 2 #hetzner 2 #vps 2 #tutorial 2 #saas 2 #sigstore 2 #contracting 2 #salary 2 #crossplane 2 #storage 2 #kafka 2 #interviews 2 #engineering 2 #alerting 2 #falco 2 #architecture 2 #java 2 #blue-green 2 #dynamodb 2 #state-management 2 #twingate 2 #private 2 #calico 2 #logging 2 #prometheus 2 #development 2 #cloud 2 #ingress 2 #traffic-management 2 #cluster-management 2 #k3s 2 #coredns 2 #pods 2 #gatekeeper 2 #documentation 2 #nat 2 #messaging 2 #policy-as-code 2 #packer 2 #ami 2 #principal-engineer 2 #api-gateway 2 #azure 2 #vpn 2 #canary 2 #spiffe 2 #spire 2 #startups 2 #teams 1 #account-factory 1 #ack 1 #prefix-lists 1 #security-groups 1 #mlops 1 #machine-learning 1 #aws-config 1 #compliance 1 #ssm 1 #iam-identity-center 1 #endpoints 1 #cognito 1 #developer-portal 1 #react 1 #typescript 1 #direct-connect 1 #routing 1 #psychological-safety 1 #cdn 1 #cloudfront 1 #trainline 1 #chaos-engineering 1 #litmus 1 #google-workspace 1 #notion 1 #integrations 1 #oauth 1 #whatsapp 1 #clickhouse 1 #tagging 1 #cloud-costs 1 #multi-tenant 1 #unit-economics 1 #namespaces 1 #netns 1 #bridge 1 #cosign 1 #backup 1 #cronjob 1 #stateful 1 #operators 1 #strimzi 1 #operator 1 #roadmap 1 #platform 1 #udp 1 #cloudmap 1 #service-discovery 1 #dora 1 #dragonfly 1 #redis 1 #caching 1 #dynatrace 1 #ansible 1 #kernel 1 #tetragon 1 #eni 1 #ip 1 #task-sets 1 #network 1 #ip-exhaustion 1 #prefix-delegation 1 #ipip 1 #elastic-cloud 1 #managed-services 1 #elk 1 #kibana 1 #logstash 1 #etl 1 #python 1 #airflow 1 #data-engineering 1 #external-secrets 1 #secrets-manager 1 #grafana 1 #firecracker 1 #kubecost 1 #opencost 1 #consulting 1 #tech-industry 1 #lessons-learned 1 #argocd 1 #cluster 1 #access 1 #google-cloud 1 #workload-identity 1 #rollback 1 #fluxcd 1 #hashicorp-vault 1 #identity-aware-proxy 1 #oauth2 1 #ebs 1 #disk 1 #port 1 #kratix 1 #self-service 1 #jenkins 1 #jvm 1 #memory 1 #threads 1 #raspberry-pi 1 #socks5 1 #pg_dump 1 #arp 1 #net_raw 1 #mitm 1 #networkpolicy 1 #sidecars 1 #kyverno 1 #policy 1 #lab 1 #container 1 #meetings 1 #gateway 1 #instance 1 #cost 1 #savings 1 #nats 1 #jetstream 1 #streaming 1 #microservices 1 #negotiation 1 #tools 1 #nginx 1 #incident 1 #log-rotation 1 #war-stories 1 #admission-control 1 #traces 1 #logs 1 #collector 1 #tracing 1 #immutable-infrastructure 1 #internal-platforms 1 #pod-security 1 #psp 1 #admission-controller 1 #hardening 1 #scheduling 1 #high-availability 1 #private-cluster 1 #flagger 1 #progressive-delivery 1 #apache-pulsar 1 #pubsub 1 #devtools 1 #pulsar 1 #rds-proxy 1 #connection-pooling 1 #management 1 #resource-management 1 #route53 1 #failover 1 #latency-routing 1 #secretless 1 #secrets-management 1 #sidecar 1 #gitlab 1 #self-hosted 1 #startup 1 #technical-writing 1 #istio 1 #linkerd 1 #slo 1 #soc 1 #cribl 1 #siem 1 #rego 1 #modules 1 #spot-instances 1 #sql-server 1 #oracle 1 #dms 1 #event-sourcing 1 #agile 1 #team-management 1 #certifications 1 #learning 1 #supply-chain 1 #slsa 1 #sbom 1 #tailscale 1 #wireguard 1 #hcl2 1 #best-practices 1 #state 1 #refactoring 1 #sigv4 1 #tls 1 #certificates 1 #smallstep 1 #pki 1 #vault 1 #aurora 1 #vitess 1 #mysql 1 #sharding 1 #scaling 1 #vpa 1 #hpa 1 #keda 1 #api-server 1 #etcd 1 #controllers 1 #scheduler 1 #kubelet 1 #hot-takes 1

#devops 64 posts

#kubernetes 61 posts

Cilium in Kubernetes

Hands-on with Cilium CNI on a local kind cluster — installation, eBPF datapath verification, network policies and Hubble observability.

#cilium

AWS Controllers for Kubernetes

Manage AWS resources from Kubernetes manifests using AWS Controllers for Kubernetes (ACK). End-to-end demo on kind covering setup, RDS provisioning and the trade-offs vs Terraform.

#aws#ack

#aws 55 posts

Why I replaced AWS NAT Gateway with a NAT Instance - and saved 20$ of dollar per month

AWS offers NAT Gateways as the default, fully managed solution for letting private subnet resources reach the internet. However, NAT Gateways can be pricey: Hourly cost: ~₹3.75/hour (varies by region) Data transfer cost: Additional ₹3.75/GB on top of standard data transfer For small dev/test environments or personal labs, these costs can add up quickly. In contrast, a NAT Instance is just a normal EC2 instance configured to perform IP forwarding and NAT. It’s typically much cheaper to run a small instance (`t3.micro`) than a NAT Gateway, especially if your traffic volume is modest.

#nat#gateway#instance#cost#savings

EKS IP Exhaustion: Running out of IPs, one way to fix it

Running out of IP addresses in AWS EKS can be a subtle yet critical issue. It often manifests as pods stuck in a pending state or nodes failing to join the cluster, leading to deployment bottlenecks and potential downtime. Understanding the root cause and implementing effective solutions is essential for maintaining cluster health and scalability. Now, there are many ways to fix this, but this is one way.

#eks#networking#cni#ip-exhaustion#prefix-delegation

AWS Controllers for Kubernetes

Manage AWS resources from Kubernetes manifests using AWS Controllers for Kubernetes (ACK). End-to-end demo on kind covering setup, RDS provisioning and the trade-offs vs Terraform.

#kubernetes#ack

#terraform 31 posts

#security 31 posts

#networking 25 posts

EKS IP Exhaustion: Running out of IPs, one way to fix it

Running out of IP addresses in AWS EKS can be a subtle yet critical issue. It often manifests as pods stuck in a pending state or nodes failing to join the cluster, leading to deployment bottlenecks and potential downtime. Understanding the root cause and implementing effective solutions is essential for maintaining cluster health and scalability. Now, there are many ways to fix this, but this is one way.

#aws#eks#cni#ip-exhaustion#prefix-delegation

#platform-engineering 15 posts

#engineering-culture 13 posts

#career 11 posts

#containers 11 posts

#eks 10 posts

EKS IP Exhaustion: Running out of IPs, one way to fix it

Running out of IP addresses in AWS EKS can be a subtle yet critical issue. It often manifests as pods stuck in a pending state or nodes failing to join the cluster, leading to deployment bottlenecks and potential downtime. Understanding the root cause and implementing effective solutions is essential for maintaining cluster health and scalability. Now, there are many ways to fix this, but this is one way.

#aws#networking#cni#ip-exhaustion#prefix-delegation

#observability 10 posts

#docker 8 posts

#vpc 7 posts

#ecs 7 posts

#migration 7 posts

#leadership 6 posts

#finops 6 posts

#gitops 6 posts

#cicd 6 posts

#iac 6 posts

#fargate 6 posts

#cost-optimization 6 posts

#production 5 posts

#infrastructure 5 posts

#automation 5 posts

#github-actions 5 posts

#sre 5 posts

#cilium 5 posts

Cilium in Kubernetes

Hands-on with Cilium CNI on a local kind cluster — installation, eBPF datapath verification, network policies and Hubble observability.

#kubernetes

#linux 5 posts

#dns 5 posts

#gke 5 posts

#zero-trust 5 posts

#productivity 4 posts

#iam 4 posts

#ci-cd 4 posts

#testing 4 posts

#reliability 4 posts

#oidc 4 posts

#mtls 4 posts

#database 4 posts

#advice 4 posts

#localstack 4 posts

#postgresql 4 posts

#kind 4 posts

#performance 4 posts

#lambda 4 posts

#control-tower 3 posts

#service-catalog 3 posts

#organizations 3 posts

#backstage 3 posts

#rds 3 posts

#incident-management 3 posts

#developer-experience 3 posts

#ebpf 3 posts

#clawdbot 3 posts

#s3 3 posts

#databases 3 posts

#k8s 3 posts

#traefik 3 posts

#metrics 3 posts

#monitoring 3 posts

#ec2 3 posts

#deployment 3 posts

#deployments 3 posts

#cni 3 posts

EKS IP Exhaustion: Running out of IPs, one way to fix it

Running out of IP addresses in AWS EKS can be a subtle yet critical issue. It often manifests as pods stuck in a pending state or nodes failing to join the cluster, leading to deployment bottlenecks and potential downtime. Understanding the root cause and implementing effective solutions is essential for maintaining cluster health and scalability. Now, there are many ways to fix this, but this is one way.

#aws#eks#networking#ip-exhaustion#prefix-delegation

#elasticsearch 3 posts

#debugging 3 posts

#kubectl 3 posts

#gateway-api 3 posts

#helm 3 posts

#homelab 3 posts

#on-call 3 posts

#aks 3 posts

#autoscaling 3 posts

#opa 3 posts

#remote-work 3 posts

#opentelemetry 3 posts

#serverless 3 posts

#karpenter 2 posts

#sso 2 posts

#multi-account 2 posts

#scps 2 posts

#spacelift 2 posts

#act 2 posts

#governance 2 posts

#bgp 2 posts

#hybrid-cloud 2 posts

#post-mortems 2 posts

#idp 2 posts

#github 2 posts

#service-mesh 2 posts

#hetzner 2 posts

#vps 2 posts

#tutorial 2 posts

#saas 2 posts

#sigstore 2 posts

#contracting 2 posts

#salary 2 posts

#crossplane 2 posts

#storage 2 posts

#kafka 2 posts

#interviews 2 posts

#engineering 2 posts

#alerting 2 posts

#falco 2 posts

#architecture 2 posts

#java 2 posts

#blue-green 2 posts

#dynamodb 2 posts

#state-management 2 posts

#twingate 2 posts

#private 2 posts

#calico 2 posts

#logging 2 posts

#prometheus 2 posts

#development 2 posts

#cloud 2 posts

#ingress 2 posts

#traffic-management 2 posts

#cluster-management 2 posts

#k3s 2 posts

#coredns 2 posts

#pods 2 posts

#gatekeeper 2 posts

#documentation 2 posts

#nat 2 posts

Why I replaced AWS NAT Gateway with a NAT Instance - and saved 20$ of dollar per month

AWS offers NAT Gateways as the default, fully managed solution for letting private subnet resources reach the internet. However, NAT Gateways can be pricey: Hourly cost: ~₹3.75/hour (varies by region) Data transfer cost: Additional ₹3.75/GB on top of standard data transfer For small dev/test environments or personal labs, these costs can add up quickly. In contrast, a NAT Instance is just a normal EC2 instance configured to perform IP forwarding and NAT. It’s typically much cheaper to run a small instance (`t3.micro`) than a NAT Gateway, especially if your traffic volume is modest.

#aws#gateway#instance#cost#savings

#messaging 2 posts

#policy-as-code 2 posts

#packer 2 posts

#ami 2 posts

#principal-engineer 2 posts

#api-gateway 2 posts

#azure 2 posts

#vpn 2 posts

#canary 2 posts

#spiffe 2 posts

#spire 2 posts

#startups 2 posts

#teams 1 post

#account-factory 1 post

#ack 1 post

AWS Controllers for Kubernetes

Manage AWS resources from Kubernetes manifests using AWS Controllers for Kubernetes (ACK). End-to-end demo on kind covering setup, RDS provisioning and the trade-offs vs Terraform.

#kubernetes#aws

#prefix-lists 1 post

#security-groups 1 post

#mlops 1 post

#machine-learning 1 post

#aws-config 1 post

#compliance 1 post

#ssm 1 post

#iam-identity-center 1 post

#endpoints 1 post

#cognito 1 post

#developer-portal 1 post

#react 1 post

#typescript 1 post

#direct-connect 1 post

#routing 1 post

#psychological-safety 1 post

#cdn 1 post

#cloudfront 1 post

#trainline 1 post

#chaos-engineering 1 post

#litmus 1 post

#google-workspace 1 post

#notion 1 post

#integrations 1 post

#oauth 1 post

#whatsapp 1 post

#clickhouse 1 post

#tagging 1 post

#cloud-costs 1 post

#multi-tenant 1 post

#unit-economics 1 post

#namespaces 1 post

#netns 1 post

#bridge 1 post

#cosign 1 post

#backup 1 post

#cronjob 1 post

#stateful 1 post

#operators 1 post

#strimzi 1 post

#operator 1 post

#roadmap 1 post

#platform 1 post

#udp 1 post

#cloudmap 1 post

#service-discovery 1 post

#dora 1 post

#dragonfly 1 post

#redis 1 post

#caching 1 post

#dynatrace 1 post

#ansible 1 post

#kernel 1 post

#tetragon 1 post

#eni 1 post

#ip 1 post

#task-sets 1 post

#network 1 post

#ip-exhaustion 1 post

EKS IP Exhaustion: Running out of IPs, one way to fix it

Running out of IP addresses in AWS EKS can be a subtle yet critical issue. It often manifests as pods stuck in a pending state or nodes failing to join the cluster, leading to deployment bottlenecks and potential downtime. Understanding the root cause and implementing effective solutions is essential for maintaining cluster health and scalability. Now, there are many ways to fix this, but this is one way.

#aws#eks#networking#cni#prefix-delegation

#prefix-delegation 1 post

EKS IP Exhaustion: Running out of IPs, one way to fix it

Running out of IP addresses in AWS EKS can be a subtle yet critical issue. It often manifests as pods stuck in a pending state or nodes failing to join the cluster, leading to deployment bottlenecks and potential downtime. Understanding the root cause and implementing effective solutions is essential for maintaining cluster health and scalability. Now, there are many ways to fix this, but this is one way.

#aws#eks#networking#cni#ip-exhaustion

#ipip 1 post

#elastic-cloud 1 post

#managed-services 1 post

#elk 1 post

#kibana 1 post

#logstash 1 post

#etl 1 post

#python 1 post

#airflow 1 post

#data-engineering 1 post

#external-secrets 1 post

#secrets-manager 1 post

#grafana 1 post

#firecracker 1 post

#kubecost 1 post

#opencost 1 post

#consulting 1 post

#tech-industry 1 post

#lessons-learned 1 post

#argocd 1 post

#cluster 1 post

#access 1 post

#google-cloud 1 post

#workload-identity 1 post

#rollback 1 post

#fluxcd 1 post

#hashicorp-vault 1 post

#identity-aware-proxy 1 post

#oauth2 1 post

#ebs 1 post

#disk 1 post

#port 1 post

#kratix 1 post

#self-service 1 post

#jenkins 1 post

#jvm 1 post

#memory 1 post

#threads 1 post

#raspberry-pi 1 post

#socks5 1 post

#pg_dump 1 post

#arp 1 post

#net_raw 1 post

#mitm 1 post

#networkpolicy 1 post

#sidecars 1 post

#kyverno 1 post

#policy 1 post

#lab 1 post

#container 1 post

#meetings 1 post

#gateway 1 post

Why I replaced AWS NAT Gateway with a NAT Instance - and saved 20$ of dollar per month

AWS offers NAT Gateways as the default, fully managed solution for letting private subnet resources reach the internet. However, NAT Gateways can be pricey: Hourly cost: ~₹3.75/hour (varies by region) Data transfer cost: Additional ₹3.75/GB on top of standard data transfer For small dev/test environments or personal labs, these costs can add up quickly. In contrast, a NAT Instance is just a normal EC2 instance configured to perform IP forwarding and NAT. It’s typically much cheaper to run a small instance (`t3.micro`) than a NAT Gateway, especially if your traffic volume is modest.

#aws#nat#instance#cost#savings

#instance 1 post

Why I replaced AWS NAT Gateway with a NAT Instance - and saved 20$ of dollar per month

AWS offers NAT Gateways as the default, fully managed solution for letting private subnet resources reach the internet. However, NAT Gateways can be pricey: Hourly cost: ~₹3.75/hour (varies by region) Data transfer cost: Additional ₹3.75/GB on top of standard data transfer For small dev/test environments or personal labs, these costs can add up quickly. In contrast, a NAT Instance is just a normal EC2 instance configured to perform IP forwarding and NAT. It’s typically much cheaper to run a small instance (`t3.micro`) than a NAT Gateway, especially if your traffic volume is modest.

#aws#nat#gateway#cost#savings

#cost 1 post

Why I replaced AWS NAT Gateway with a NAT Instance - and saved 20$ of dollar per month

AWS offers NAT Gateways as the default, fully managed solution for letting private subnet resources reach the internet. However, NAT Gateways can be pricey: Hourly cost: ~₹3.75/hour (varies by region) Data transfer cost: Additional ₹3.75/GB on top of standard data transfer For small dev/test environments or personal labs, these costs can add up quickly. In contrast, a NAT Instance is just a normal EC2 instance configured to perform IP forwarding and NAT. It’s typically much cheaper to run a small instance (`t3.micro`) than a NAT Gateway, especially if your traffic volume is modest.

#aws#nat#gateway#instance#savings

#savings 1 post

Why I replaced AWS NAT Gateway with a NAT Instance - and saved 20$ of dollar per month

AWS offers NAT Gateways as the default, fully managed solution for letting private subnet resources reach the internet. However, NAT Gateways can be pricey: Hourly cost: ~₹3.75/hour (varies by region) Data transfer cost: Additional ₹3.75/GB on top of standard data transfer For small dev/test environments or personal labs, these costs can add up quickly. In contrast, a NAT Instance is just a normal EC2 instance configured to perform IP forwarding and NAT. It’s typically much cheaper to run a small instance (`t3.micro`) than a NAT Gateway, especially if your traffic volume is modest.

#aws#nat#gateway#instance#cost

#nats 1 post

#jetstream 1 post

#streaming 1 post

#microservices 1 post

#negotiation 1 post

#tools 1 post

#nginx 1 post

#incident 1 post

#log-rotation 1 post

#war-stories 1 post

#admission-control 1 post

#traces 1 post

#logs 1 post

#collector 1 post

#tracing 1 post

#immutable-infrastructure 1 post

#internal-platforms 1 post

#pod-security 1 post

#psp 1 post

#admission-controller 1 post

#hardening 1 post

#scheduling 1 post

#high-availability 1 post

#private-cluster 1 post

#flagger 1 post

#progressive-delivery 1 post

#apache-pulsar 1 post

#pubsub 1 post

#devtools 1 post

#pulsar 1 post

#rds-proxy 1 post

#connection-pooling 1 post

#management 1 post

#resource-management 1 post

#route53 1 post

#failover 1 post

#latency-routing 1 post

#secretless 1 post

#secrets-management 1 post

#sidecar 1 post

#gitlab 1 post

#self-hosted 1 post

#startup 1 post

#technical-writing 1 post

#istio 1 post

#linkerd 1 post

#slo 1 post

#soc 1 post

#cribl 1 post

#siem 1 post

#rego 1 post

#modules 1 post

#spot-instances 1 post

#sql-server 1 post

#oracle 1 post

#dms 1 post

#event-sourcing 1 post

#agile 1 post

#team-management 1 post

#certifications 1 post

#learning 1 post

#supply-chain 1 post

#slsa 1 post

#sbom 1 post

#tailscale 1 post

#wireguard 1 post

#hcl2 1 post

#best-practices 1 post

#state 1 post

#refactoring 1 post

#sigv4 1 post

#tls 1 post

#certificates 1 post

#smallstep 1 post

#pki 1 post

#vault 1 post

#aurora 1 post

#vitess 1 post

#mysql 1 post

#sharding 1 post

#scaling 1 post

#vpa 1 post

#hpa 1 post

#keda 1 post

#api-server 1 post

#etcd 1 post

#controllers 1 post

#scheduler 1 post

#kubelet 1 post

#hot-takes 1 post