Fixing a Kubernetes Namespace Stuck in Terminating Without Hiding the Root Cause
A safe namespace-termination investigation covering discovery failures, remaining objects, finalizers, APIService health, and last-resort finalization.
whoami
Deep technical notes on operating systems, virtualization, cloud infrastructure, kernels, filesystems, emulation, and the history behind essential tools.
A safe namespace-termination investigation covering discovery failures, remaining objects, finalizers, APIService health, and last-resort finalization.
How to identify high-cardinality metrics and labels, stop unsafe ingestion, preserve evidence, and redesign instrumentation without masking outages.
How GitHub's OIDC tokens, cloud trust policies, audience and subject claims replace static CI keys while keeping workflows and environments constrained.
A deterministic Argo CD rollout using phases, integer waves, health gates, idempotent hooks, selective-sync caveats, and observable failure recovery.
A fail-safe Sigstore workflow for signing immutable image digests, constraining identities, enforcing admission policy, and preserving rollback access.
A recovery-first etcd procedure covering consistent snapshots, encryption keys, revision bumps, restore topology, and proof that Kubernetes reconciles.
A precise guide to Guaranteed, Burstable, and BestEffort Pods, including request math, cgroup enforcement, OOM behavior, and node-pressure eviction.
How Kubernetes impersonation headers and RBAC verbs support least-privilege authorization tests while preserving identity, scope, and audit evidence.
How Server-Side Apply records field ownership, detects conflicting intent, supports shared objects, and differs from replacement and merge patch workflows.
How tail sampling buffers complete traces, evaluates outcome-aware policies, controls memory, and preserves representative telemetry during failures.
Posts revised with new sources, corrected facts, or fixed links — not just new posts.