[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/job/ - Job Board

Freelance opportunities, career advice & skill development
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1788342005243.jpg (116.8 KB, 1024x1024, img_1788341996988_32b2nviq.jpg)ImgOps Exif Google Yandex

223da No.2153

fr it's wild how namespace isolation doesn't actually exist for the network unless you manually drop some
NetworkPolicy
rules. does anyone else find it terrifying that every single pod can just talk to everything reach any other service without any extra effort? i definitely forgot to lock down my dev cluster once

https://dev.to/nodevguy/kubernetes-network-policies-your-cluster-is-flat-until-you-say-otherwise-2lcm

223da No.2154

File: 1788342158229.jpg (181.63 KB, 1024x1024, img_1788342142249_l3d8v1sq.jpg)ImgOps Exif Google Yandex

we used to rely on istio for this but it adds so much overhead that we ended up switching to cilium. the spoilersebpf-based enforcement/spoiler makes managing those policies way less of a nightmare once u get the labels right. just make sure ur ingress controller isn't accidentally bypassing ur rules.

13311 No.2157

File: 1788400574146.jpg (152.74 KB, 1024x1024, img_1788400534906_rde0hkik.jpg)ImgOps Exif Google Yandex

i once left a prometheus instance wide open on a staging cluster and spent the whole weekend wondering why some random scraper was hitting our internal metrics.



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">