<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Daniel Cosenza&apos;s Blog — SRE &amp; DevOps</title><description>Containers, orchestration, cloud infrastructure, and the practices that keep production reliable.</description><link>https://danielcosenza.com/</link><language>en-us</language><lastBuildDate>Fri, 17 Jul 2026 00:00:00 GMT</lastBuildDate><atom:link href="https://danielcosenza.com/categories/devops/rss.xml" rel="self" type="application/rss+xml"/><item><title>Amazon ECR in Production: IAM, Digests, Scanning, Lifecycle Rules, and Replication</title><link>https://danielcosenza.com/posts/devops-amazon-ecr/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-amazon-ecr/</guid><description>How to operate Amazon ECR as a controlled OCI artifact supply point with least-privilege access, immutable identity, scanning, retention, and recovery.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>aws</category><category>ecr</category><category>container-registry</category></item><item><title>Amazon ECS Architecture: Tasks, Services, Capacity, and Operational Boundaries</title><link>https://danielcosenza.com/posts/devops-amazon-ecs-architecture/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-amazon-ecs-architecture/</guid><description>A practical model of ECS task definitions, services, capacity providers, networking, IAM, deployments, and the responsibilities AWS does not remove.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>aws</category><category>ecs</category><category>containers</category></item><item><title>Amazon EKS in Production: Control Plane, Compute, IAM, Networking, and Upgrades</title><link>https://danielcosenza.com/posts/devops-amazon-eks/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-amazon-eks/</guid><description>What AWS manages in EKS, what remains in your account, and how node choices, VPC networking, identity, observability, availability, and cost interact.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>aws</category><category>eks</category><category>kubernetes</category></item><item><title>AWS App Runner: From Source or Container Image to a Managed Web Service</title><link>https://danielcosenza.com/posts/devops-aws-app-runner/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-aws-app-runner/</guid><description>How App Runner builds, deploys, scales, secures, and observes HTTP services—and where its simplified platform stops being the right abstraction.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>aws</category><category>app-runner</category><category>paas</category></item><item><title>AWS Fargate: Serverless Container Compute for ECS and EKS</title><link>https://danielcosenza.com/posts/devops-aws-fargate-serverless-containers/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-aws-fargate-serverless-containers/</guid><description>What Fargate manages, how task-level isolation and resource sizing work, and when its operational simplicity outweighs reduced host control.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>aws</category><category>fargate</category><category>containers</category></item><item><title>AWS Step Functions: Reliable Workflow Orchestration Without a Custom Coordinator</title><link>https://danielcosenza.com/posts/devops-aws-step-functions-workflows/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-aws-step-functions-workflows/</guid><description>How Step Functions state machines coordinate distributed work, where retries and execution history help, and where orchestration cost and service limits matter.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>aws</category><category>step-functions</category><category>orchestration</category></item><item><title>Azure Container Apps: Environments, Revisions, KEDA Scaling, and Managed Ingress</title><link>https://danielcosenza.com/posts/devops-azure-container-apps/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-azure-container-apps/</guid><description>A production-focused guide to Azure Container Apps architecture, revisions, jobs, networking, identity, observability, scaling, and platform limits.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>azure</category><category>container-apps</category><category>keda</category></item><item><title>Azure Container Registry: Identity, OCI Artifacts, Geo-Replication, and Governance</title><link>https://danielcosenza.com/posts/devops-azure-container-registry/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-azure-container-registry/</guid><description>A production operating model for ACR authentication, repository permissions, digests, scanning integrations, retention, private networking, and global replicas.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>azure</category><category>acr</category><category>container-registry</category></item><item><title>Azure Kubernetes Service: Managed Control Plane, Node Pools, Identity, and Networking</title><link>https://danielcosenza.com/posts/devops-azure-kubernetes-service/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-azure-kubernetes-service/</guid><description>A production model for AKS architecture, Entra authentication, node pools, CNI choices, upgrades, observability, availability, and shared responsibility.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>azure</category><category>aks</category><category>kubernetes</category></item><item><title>Container Tags, Digests, SBOMs, and Provenance: Building a Verifiable Release Chain</title><link>https://danielcosenza.com/posts/devops-container-tags-digests-provenance/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-container-tags-digests-provenance/</guid><description>Why latest is not an identity, how OCI digests anchor releases, and how signatures, attestations, SBOMs, and admission policy work together.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>oci</category><category>sbom</category><category>sigstore</category></item><item><title>Google Artifact Registry: Repository Modes, IAM, Cleanup, and Deployment Integration</title><link>https://danielcosenza.com/posts/devops-google-artifact-registry/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-google-artifact-registry/</guid><description>How Artifact Registry manages container images and language packages with explicit locations, repository-level access, vulnerability analysis, and cleanup policies.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>google-cloud</category><category>artifact-registry</category><category>oci</category></item><item><title>Google Cloud Run: Services, Jobs, Revisions, and the Container Runtime Contract</title><link>https://danielcosenza.com/posts/devops-google-cloud-run/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-google-cloud-run/</guid><description>How Cloud Run turns containers into managed services and jobs, including scaling, traffic splitting, IAM, networking, observability, and cold-start tradeoffs.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>google-cloud</category><category>cloud-run</category><category>serverless</category></item><item><title>Google Container Registry After Shutdown: What GCR Was and How Migration Works</title><link>https://danielcosenza.com/posts/devops-google-container-registry-shutdown/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-google-container-registry-shutdown/</guid><description>Why legacy Container Registry is no longer the service to design around, what remains true about gcr.io URLs, and how to move safely to Artifact Registry.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>google-cloud</category><category>gcr</category><category>artifact-registry</category></item><item><title>Google Kubernetes Engine: Autopilot, Standard, Cluster Architecture, and Operations</title><link>https://danielcosenza.com/posts/devops-google-kubernetes-engine/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-google-kubernetes-engine/</guid><description>How GKE divides control between Google and the customer across Autopilot and Standard modes, including scaling, identity, networking, upgrades, security, and cost.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>google-cloud</category><category>gke</category><category>kubernetes</category></item><item><title>Helm Architecture and Release Lifecycle: Charts, Values, Hooks, Rollbacks, and Supply Chain</title><link>https://danielcosenza.com/posts/devops-helm-release-lifecycle/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-helm-release-lifecycle/</guid><description>A deep guide to Helm charts and releases, value precedence, dependencies, lifecycle operations, GitOps, secrets, validation, and Helm 4 compatibility.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>helm</category><category>kubernetes</category><category>gitops</category></item><item><title>Karpenter Node Lifecycle: NodePools, NodeClaims, Scheduling, Consolidation, and Disruption</title><link>https://danielcosenza.com/posts/devops-karpenter-node-lifecycle/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-karpenter-node-lifecycle/</guid><description>How Karpenter provisions right-sized Kubernetes nodes for pending pods and safely manages Spot, expiration, consolidation, IAM, and production disruption on EKS.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>karpenter</category><category>eks</category><category>autoscaling</category></item><item><title>KEDA Event-Driven Autoscaling: ScaledObjects, ScaledJobs, HPA, and Safe Scale-to-Zero</title><link>https://danielcosenza.com/posts/devops-keda-event-driven-autoscaling/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-keda-event-driven-autoscaling/</guid><description>How KEDA turns queue and event metrics into pod or Job scaling, with authentication, timing controls, observability, backpressure, and production safeguards.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>keda</category><category>kubernetes</category><category>autoscaling</category></item><item><title>Kubernetes Gateway API: Separating Infrastructure, Routing, and Application Ownership</title><link>https://danielcosenza.com/posts/devops-kubernetes-gateway-api/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-kubernetes-gateway-api/</guid><description>How GatewayClass, Gateway, and typed Route resources improve multi-team traffic management beyond a single overloaded Ingress object.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>kubernetes</category><category>gateway-api</category><category>networking</category></item><item><title>OpenTelemetry Collector Pipelines: Receivers, Processors, Exporters, and Failure Control</title><link>https://danielcosenza.com/posts/devops-opentelemetry-collector-pipelines/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-opentelemetry-collector-pipelines/</guid><description>How to design Collector pipelines for metrics, logs, and traces without creating an unbounded queue, telemetry leak, or new single point of failure.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>opentelemetry</category><category>observability</category><category>telemetry</category></item><item><title>Terraform State in Production: Backends, Locking, Drift, Import, and Recovery</title><link>https://danielcosenza.com/posts/devops-terraform-state-complete-guide/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-terraform-state-complete-guide/</guid><description>A complete operational model for tfstate files: what they contain, how remote backends coordinate teams, and how to migrate or recover state without corrupting it.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>terraform</category><category>tfstate</category><category>infrastructure-as-code</category></item><item><title>Fixing a Failed or Stuck Helm Release</title><link>https://danielcosenza.com/posts/devops-fix-helm-release-failed/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-helm-release-failed/</guid><description>Recover a failed or pending Helm release by preserving evidence, inspecting revisions and resources, testing rollback, and avoiding unsafe secret edits.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>helm</category><category>kubernetes</category></item><item><title>Fixing ImagePullBackOff in Kubernetes</title><link>https://danielcosenza.com/posts/devops-fix-imagepullbackoff/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-imagepullbackoff/</guid><description>Resolve Kubernetes ImagePullBackOff by classifying event errors, verifying immutable image identity, credentials, node networking, and runtime health.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>kubernetes</category><category>containers</category></item><item><title>Fixing a Kubernetes Node Stuck NotReady</title><link>https://danielcosenza.com/posts/devops-fix-node-not-ready/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-node-not-ready/</guid><description>Diagnose a Kubernetes NotReady node through conditions, leases, kubelet, runtime, storage, networking, and safe workload evacuation with evidence intact.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>kubernetes</category><category>nodes</category></item><item><title>Fixing OOMKilled Containers with Correct Resource Limits</title><link>https://danielcosenza.com/posts/devops-fix-oomkilled-containers/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-oomkilled-containers/</guid><description>Investigate Kubernetes OOMKilled containers with termination evidence, time-series memory data, runtime ceilings, node pressure, and load validation.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>kubernetes</category><category>memory</category><category>resource-limits</category></item><item><title>Fixing Pods Stuck in Pending State in Kubernetes</title><link>https://danielcosenza.com/posts/devops-fix-pending-pods/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-pending-pods/</guid><description>Diagnose Kubernetes Pending pods from scheduler events, requests, affinity, taints, storage, topology, quota, and admission without weakening safeguards.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>kubernetes</category><category>scheduling</category></item><item><title>Fixing Terraform Provider Version Conflicts</title><link>https://danielcosenza.com/posts/devops-fix-terraform-provider-conflicts/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-terraform-provider-conflicts/</guid><description>Resolve Terraform provider constraint conflicts using the requirement tree, required_providers, committed lock selections, checksums, and tested upgrades.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>terraform</category><category>providers</category></item><item><title>How to Set Up Canary Analysis with Automated Rollback</title><link>https://danielcosenza.com/posts/devops-howto-canary-automated-rollback/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-canary-automated-rollback/</guid><description>Configure Flagger canaries with metric gates, controlled traffic shifts, load tests, and automatic rollback while preserving operational safeguards.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>canary</category><category>flagger</category><category>kubernetes</category></item><item><title>How to Implement GitOps with ArgoCD</title><link>https://danielcosenza.com/posts/devops-howto-gitops-argocd/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-gitops-argocd/</guid><description>Implement GitOps with Argo CD using pinned installation assets, constrained projects, safe automated sync, drift detection, and tested recovery.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>gitops</category><category>argocd</category><category>kubernetes</category></item><item><title>How to Set Up Kubernetes NetworkPolicies</title><link>https://danielcosenza.com/posts/devops-howto-network-policies/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-network-policies/</guid><description>Deploy Kubernetes NetworkPolicies with verified CNI enforcement, default-deny baselines, explicit DNS access, namespace labels, and negative tests.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>networkpolicy</category><category>kubernetes</category><category>security</category></item><item><title>How to Configure Pod Disruption Budgets in Kubernetes</title><link>https://danielcosenza.com/posts/devops-howto-pod-disruption-budgets/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-pod-disruption-budgets/</guid><description>Configure and test Kubernetes PodDisruptionBudgets for safe drains and upgrades without mistaking eviction limits for an availability guarantee.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>kubernetes</category><category>pdb</category><category>availability</category></item><item><title>How to Set Up Prometheus and Grafana Monitoring for Kubernetes</title><link>https://danielcosenza.com/posts/devops-howto-prometheus-grafana/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-prometheus-grafana/</guid><description>Deploy and validate kube-prometheus-stack with persistent storage, secure Grafana access, bounded cardinality, alert routing, and recovery tests.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>prometheus</category><category>grafana</category><category>monitoring</category></item><item><title>How to Write a Helm Chart from Scratch</title><link>https://danielcosenza.com/posts/devops-howto-write-helm-chart/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-write-helm-chart/</guid><description>Build a reusable Helm chart with safe templates, documented values, schema validation, immutable images, release tests, and OCI packaging checks.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>helm</category><category>kubernetes</category><category>packaging</category></item><item><title>Docker Donates containerd to the Cloud Native Computing Foundation</title><link>https://danielcosenza.com/posts/devops-news-containerd-donated/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-containerd-donated/</guid><description>Docker donated containerd to the CNCF in 2017, giving the ecosystem a neutral, focused runtime foundation later adopted directly by Kubernetes.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>containerd</category><category>cncf</category></item><item><title>Kubernetes Removes Dockershim in Version 1.24</title><link>https://danielcosenza.com/posts/devops-news-dockershim-removed/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-dockershim-removed/</guid><description>Kubernetes 1.24 removed dockershim after a long deprecation, moving nodes to CRI-native runtimes without invalidating Docker-built OCI images.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>kubernetes</category><category>dockershim</category></item><item><title>Helm Is Born at the First KubeCon, Modeled on Homebrew and apt</title><link>https://danielcosenza.com/posts/devops-news-helm-created/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-helm-created/</guid><description>Helm began at Deis in 2015, merged ideas with Deployment Manager, removed Tiller in Helm 3, and matured into Kubernetes package management.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>helm</category><category>kubernetes</category><category>packaging</category></item><item><title>The Open Container Initiative Launches, Standardizing Container Formats</title><link>https://danielcosenza.com/posts/devops-news-oci-founded/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-oci-founded/</guid><description>The OCI launched in 2015 to standardize container images, runtime bundles, execution, and distribution across competing tools and vendors.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>oci</category><category>containers</category><category>standards</category></item><item><title>Prometheus Joins the CNCF as Its Second Hosted Project</title><link>https://danielcosenza.com/posts/devops-news-prometheus-cncf/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-prometheus-cncf/</guid><description>Prometheus became the CNCF&apos;s second hosted project in 2016, placing metrics and alerting beside orchestration at the center of cloud native systems.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>prometheus</category><category>cncf</category><category>observability</category></item><item><title>How to Set Up Centralized Logging for Kubernetes with the EFK Stack</title><link>https://danielcosenza.com/posts/devops-howto-centralized-logging-elk/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-centralized-logging-elk/</guid><description>Build a production-minded Kubernetes logging pipeline with Fluent Bit, Elasticsearch, Kibana, secure transport, retention, and failure controls.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>logging</category><category>elasticsearch</category><category>kubernetes</category></item><item><title>How to Set Up Secrets Management with HashiCorp Vault</title><link>https://danielcosenza.com/posts/devops-howto-vault-secrets/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-vault-secrets/</guid><description>Integrate Kubernetes workloads with HashiCorp Vault using scoped authentication, safe initialization, agent injection, rotation, and audit controls.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>vault</category><category>secrets</category><category>security</category></item><item><title>HashiCorp&apos;s License Change Sparks the OpenTofu Fork</title><link>https://danielcosenza.com/posts/devops-news-opentofu-fork/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-opentofu-fork/</guid><description>HashiCorp&apos;s 2023 Terraform license change triggered the OpenTF fork, soon renamed OpenTofu and placed under Linux Foundation stewardship.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>terraform</category><category>opentofu</category><category>licensing</category></item><item><title>Kubernetes Admission Controllers and Policy Enforcement</title><link>https://danielcosenza.com/posts/devops-admission-control/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-admission-control/</guid><description>How admission controllers intercept API requests before they&apos;re persisted, and how OPA/Gatekeeper turn that hook into cluster-wide policy enforcement.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>kubernetes</category><category>security</category><category>policy</category></item><item><title>Container Runtime Internals: containerd, CRI-O, and the OCI Spec</title><link>https://danielcosenza.com/posts/devops-container-runtime/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-container-runtime/</guid><description>How the OCI runtime and image specs standardized what a &apos;container&apos; actually is, and how containerd/CRI-O/runc fit together beneath Docker and Kubernetes.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>containers</category><category>containerd</category><category>oci</category><category>kubernetes</category></item><item><title>Docker vs. Podman: Rootless Containers and the Daemon-less Architecture</title><link>https://danielcosenza.com/posts/devops-docker-podman/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-docker-podman/</guid><description>How Podman&apos;s daemon-less, fork-exec architecture differs from Docker&apos;s client-daemon model, and what that means for rootless containers in production.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>docker</category><category>podman</category><category>containers</category></item><item><title>Diagnosing and Fixing CrashLoopBackOff in Kubernetes</title><link>https://danielcosenza.com/posts/devops-fix-crashloopbackoff/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-crashloopbackoff/</guid><description>Diagnose Kubernetes CrashLoopBackOff from events, previous logs, exit status, probes, configuration, and controlled debugging without erasing evidence.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>kubernetes</category><category>containers</category></item><item><title>Fixing &apos;No Space Left on Device&apos; from Docker Image and Container Buildup</title><link>https://danielcosenza.com/posts/devops-fix-docker-disk-space/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-docker-disk-space/</guid><description>Recover Docker disk space methodically by measuring images, containers, caches, volumes, and logs before pruning, then add safe recurrence controls.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>docker</category><category>containers</category></item><item><title>Recovering from a Stuck Terraform State Lock</title><link>https://danielcosenza.com/posts/devops-fix-terraform-state-lock/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-fix-terraform-state-lock/</guid><description>terraform plan or apply hangs, then fails with &apos;Error acquiring the state lock.&apos; Here&apos;s how to confirm it&apos;s genuinely stale before force-unlocking it.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>fix</category><category>terraform</category><category>iac</category></item><item><title>The History of DevOps and SRE: Two Separate Movements That Converged</title><link>https://danielcosenza.com/posts/devops-history/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-history/</guid><description>How Google&apos;s SRE practice in 2003 and the DevOps movement in 2009 emerged independently, solved related delivery problems, and later converged.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>history</category><category>devops</category><category>sre</category></item><item><title>How to Implement Blue-Green and Canary Deployments in Kubernetes</title><link>https://danielcosenza.com/posts/devops-howto-blue-green-canary/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-blue-green-canary/</guid><description>A practical Kubernetes guide to blue-green cutovers and cautious canary releases, with health gates, rollback checks, and routing caveats.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>kubernetes</category><category>deployments</category></item><item><title>How to Set Up a CI/CD Pipeline with GitHub Actions</title><link>https://danielcosenza.com/posts/devops-howto-github-actions-cicd/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-github-actions-cicd/</guid><description>Create a secure GitHub Actions pipeline that tests, builds, attests, and deploys immutable container images through OIDC and protected environments.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>cicd</category><category>github-actions</category></item><item><title>How to Set Up Horizontal Pod Autoscaling in Kubernetes</title><link>https://danielcosenza.com/posts/devops-howto-hpa/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-hpa/</guid><description>Configure Kubernetes HPA with verified metrics, resource requests, scaling behavior, load tests, and capacity safeguards for reliable autoscaling.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>kubernetes</category><category>autoscaling</category></item><item><title>How to Set Up a Local Kubernetes Cluster with kind</title><link>https://danielcosenza.com/posts/devops-howto-kind-local-cluster/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-howto-kind-local-cluster/</guid><description>Create a reproducible local Kubernetes cluster with kind, load development images safely, expose services, test multiple nodes, and clean up.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>howto</category><category>kubernetes</category><category>kind</category><category>local-development</category></item><item><title>Infrastructure as Code: Terraform State, Drift, and Idempotency</title><link>https://danielcosenza.com/posts/devops-iac-terraform/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-iac-terraform/</guid><description>Why Terraform&apos;s state file is the actual source of truth behind every plan and apply, and how drift, locking, and idempotency all follow from that design.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>terraform</category><category>iac</category><category>cloud</category></item><item><title>Container Image Vulnerabilities: Scanning, CVEs, and Supply Chain Risk</title><link>https://danielcosenza.com/posts/devops-image-vulnerabilities/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-image-vulnerabilities/</guid><description>How vulnerability scanners actually inspect container image layers, how to read a scan report, and the practices that reduce real supply-chain risk.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>security</category><category>containers</category><category>vulnerabilities</category><category>supply-chain</category></item><item><title>Understanding Kubernetes Networking: Services, kube-proxy, and CNI Plugins</title><link>https://danielcosenza.com/posts/devops-k8s-networking/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-k8s-networking/</guid><description>How pod-to-pod networking, Services, and kube-proxy&apos;s packet rewriting fit together to make Kubernetes&apos; flat network model actually work.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>kubernetes</category><category>networking</category><category>containers</category></item><item><title>How the Kubernetes Scheduler Actually Places Workloads</title><link>https://danielcosenza.com/posts/devops-k8s-scheduling/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-k8s-scheduling/</guid><description>The two-phase filter-and-score process the Kubernetes scheduler uses to decide which node a pod lands on, and how to influence it.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>kubernetes</category><category>scheduling</category><category>containers</category></item><item><title>Building Minimal, Secure Container Images</title><link>https://danielcosenza.com/posts/devops-minimal-images/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-minimal-images/</guid><description>How multi-stage builds, distroless bases, secret-safe caching, non-root execution, and layer inspection produce smaller, auditable runtime images.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>containers</category><category>docker</category><category>security</category></item><item><title>Solomon Hykes Demos Docker Publicly for the First Time</title><link>https://danielcosenza.com/posts/devops-news-docker-pycon/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-docker-pycon/</guid><description>At PyCon on March 15, 2013, dotCloud co-founder Solomon Hykes introduced Docker to the world, ahead of the company&apos;s later pivot to focus on it entirely.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>docker</category><category>containers</category></item><item><title>dotCloud Renames Itself Docker, Inc.</title><link>https://danielcosenza.com/posts/devops-news-docker-rename/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-docker-rename/</guid><description>On October 29, 2013, dotCloud announced it was scaling back its original PaaS business and renaming the company entirely around its container tooling.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>docker</category><category>containers</category></item><item><title>Kubernetes 1.0 Ships, and Google Donates It to the New CNCF</title><link>https://danielcosenza.com/posts/devops-news-k8s-10/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-news-k8s-10/</guid><description>Kubernetes 1.0 arrived in July 2015 as Google placed the project with the newly launched CNCF, anchoring a vendor-neutral ecosystem.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>news</category><category>kubernetes</category><category>cncf</category></item><item><title>Observability in Cloud-Native Systems: Metrics, Logs, and Traces</title><link>https://danielcosenza.com/posts/devops-observability/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-observability/</guid><description>How the three pillars of observability complement each other, and why having all three matters more than maximizing any single one.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>observability</category><category>monitoring</category><category>cloud-native</category></item><item><title>SLOs, SLIs, and Error Budgets: The Math Behind SRE Decision-Making</title><link>https://danielcosenza.com/posts/devops-slo-error-budget/</link><guid isPermaLink="true">https://danielcosenza.com/posts/devops-slo-error-budget/</guid><description>How Service Level Indicators, Objectives, and error budgets turn &apos;be reliable&apos; into a concrete, measurable number that actually drives engineering decisions.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>SRE &amp; DevOps</category><category>sre</category><category>slo</category><category>reliability</category></item></channel></rss>