Operations | Monitoring | ITSM | DevOps | Cloud

December 2022

How to Deploy a D2iQ Kubernetes Platform Cluster Using ClusterAPI

This video will demonstrate how CAPI is used as part of the D2iQ Kubernetes Platform (DKP) installation, while deploying a DKP cluster. By simplifying Kubernetes deployment and management, DKP enables your organization to gain all the benefits of cloud-native Kubernetes while establishing a future-proof foundation for smart cloud-native innovation.

Multi-Cluster Lifecycle Management With DKP and ClusterAPI (CAPI)

This video will demonstrate how a D2iQ Kubernetes Platform (DKP) management cluster can be used to deploy new DKP clusters. In addition, we will also demonstrate how to attach an existing DKP cluster to a DKP management cluster, and put it under the management cluster's control, and how to detach and delete clusters under management control.

7 Best Docker Container Monitoring Tools in 2023

Monitoring tools aid DevOps teams in finding and resolving performance issues more quickly. With the popularity of Kubernetes and Docker continuing to grow, it's critical to establish proper container monitoring and log management practices early on. This is no simple task. Docker container monitoring is quite difficult. Creating a strategy and a suitable monitoring system is not at all easy.

Qovery now supports AWS STS: Protect your resources with temporary access keys

We are excited to announce that Qovery now supports AWS Security Token Service (STS) for all our plans! AWS STS is a web service that enables you to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for federated users who sign in using Single Sign-On (SSO). These credentials are then used to access AWS resources and services.

Mind the Gap: Managing Air-gapped Kubernetes

Easily create and use bundles for air-gapped environments. In this video, you will learn: What is the use case for air-gapped computing? Who uses air-gapped environments? We know government does, but what are some good use cases for commercial customers? What are the challenges for managing Kubernetes in a secured environment?" mindthegap is an open-source project, sponsored by D2iQ, which provides utilities to manage air-gapped image bundles, both creating image bundles and seeding images from a bundle into an existing OCI registry.

2022 Retrospective - Looking ahead to 2023

2022 was a year of tremendous growth for us here at Qovery. We released Qovery V3, grew our customer base, saw our platform use grow exponentially, met our target revenue, and more! Thanks to the Qovery team for their hard work, we achieved an impressive amount in 2022. It’s truly a joy to work with brilliant people who live out our daily values - humility, hard work, and customer obsession! Thanks to our customers’ faith in us, we can do what we love and continue to grow. So, thank you!

Qovery Demo Day Summary - December 2022

Our last Qovery Demo Day took place on a live on Tuesday, 20th of December. This event aims to give you some insights into what we did during the past month and what’s next and showcase some of our new features. This Demo Day was a bit special, as it was the last of the year, and to celebrate, we brought the entire team along to do a retrospective of the year and answer any questions you might have about our product.

Tips & Tricks for using Kubernetes

Businesses around the world are increasingly turning to container technology to streamline the process of deploying and managing complex, cloud native applications. Containers bundle all necessary dependencies into a single package, offering portability, speed, security, scalability, and ease of management, making them the preferred choice over traditional virtual machines (VMs).

How Tint Streamlines Infrastructure Automation and Meets Compliance Requirements

I recently had the opportunity to speak with Kevin Maschtaler, the Platform and Reliability lead at Tint, about their experience with Qovery. Tint began using Qovery in early 2022 to automate their infrastructure and support their team and customer growth. In this article, we will explore Tint's journey with Qovery, including how we continue to assist them with compliance in the testing and release process and how we help them save on cloud costs through our partnerships.

Dashboard Fridays: Sample Google Kubernetes Engine Dashboard

This SquaredUp dashboard shows key metrics from any GKE (Google Kubernetes Engine) clusters and node groups, including utilization of resources and health status. Tune in to learn how it was made, the challenges it solves, and our top tips for building it yourself.

Epinio End of Year Wrap

This 2022 was an incredible year for Epinio, SUSE’s application development engine for Kubernetes, enabling developers to go from Code to URL in one push. We removed many dependencies in the first few months, increasing the deployment speed and shortening the development feedback loop. We standardized the installation process with Helm, dropping the original installer. We added many new features, such as Services, allowing developers to provision custom resources autonomously.

5 Ways to Ensure Success With Your Kubernetes Platform

Moving towards a Kubernetes platform might seem a simple move. You’ll ask your smartest engineers to get started. They will love a move towards cloud and container technology. However, if you want to realize maximum benefit as you start using a platform like Kubernetes, there is more to it.

Sysdig Monitor introduces native support for Microsoft Azure Monitor

Microsoft Azure Monitor allows customers to get critical details about their Azure cloud environments and services. The API for Azure Monitor can be a great way for teams to pull this information into their own storage systems for further analysis. However, it can be an overwhelming amount of data to process. Sysdig can help with this problem and eliminate time and effort. Here is how we do it …

How to Scale DevOps: 5 Keys to Success

DevOps is one of the core pillars of any organization. As the company grows, its processes also scale to absorb the new growth. Scaling DevOps is inevitable for any organization's growth. You cannot scale consistently if your DevOps processes involve a lot of manual steps and take much time to deliver new projects. A scalable DevOps means the system can expand automatically during a high workload and shrink back when the needs are reduced to normal.

How to build a service mesh with Istio and Calico

Microservices are loosely coupled software that provides flexibility and scalability to a cloud environment. However, securing this open architecture from vulnerabilities and malicious actors can be challenging without a service mesh. This blog post will demonstrate how you can create an Istio and Calico integration to establish a service mesh that will manipulate HTTP traffic in the application layer.

Exploiting IAM security misconfigurations and how to detect them

These three IAM security misconfiguration scenarios are rather common. Discover how they can be exploited, but also, how easy it is to detect and correct them. Identity and access management (IAM) misconfigurations are one of the most common concerns in cloud security. Over the last few years, we have seen how these security holes put organizations at increased risk of experiencing serious attacks on their Cloud accounts.

A comprehensive guide to cloud cost management

With 34% of cloud developers facing difficulties when calculating how much their cloud provider is going to charge them each month, it is essential to prioritize cloud cost management. This concept surrounds the process of monitoring, controlling, and optimizing an organization’s cloud service spend. By having the correct cloud cost management strategies in place, organizations are able to eliminate unnecessary expenses through optimizing resource allocation and cost-saving strategies.

Enterprise and Edge Scale Security with NeuVector Container Security 5.1

I’m excited to announce the general availability of the SUSE NeuVector container security platform version 5.1. With the 5.1 release, customers will benefit from more efficient and powerful vulnerability scanning and admission controls across multiple clusters through centralized enterprise scanning, auto-scaling scanners and support for the new Kubernetes (1.25+) pod security admission (PSA) standard. The release also supports the Cilium network plug-in.

Our Journey Into Cutting Kubernetes Costs by 40%

As companies start their Kubernetes and cloud-native journey, cloud infrastructures and services grow at a rapid pace. This happens all too often as organizations shift left without thorough controls, which can lead to overallocating and overspending on their Kubernetes environments. Organizations running workloads in the cloud can put budgets at risk when they lack information about key facts.

Chiselled Ubuntu: the perfect present for your containerised and cloud applications

As we enter the holiday season, online shopping and payment systems are gearing up for higher traffic and workloads. Ensuring that these applications can handle the increased demand without slowing down or crashing is critical for providing a smooth and efficient experience for customers. One way to improve the performance and reliability of these applications is by using chiselled Ubuntu images in your containerised deployment.

Codefresh 2022 - Year in Review

Code, features, pull requests, code reviews and so much more! 2022 has been a year of dramatic growth and change for Codefresh. Join us for a review of the year! As companies that build software, you rewarded Codefresh with healthy revenue growth throughout 2022 because you’ve told us progressive software delivery remains a critical investment and top priority.

Modern observability and security on Kubernetes with Elastic and OpenTelemetry

The structured nature of Kubernetes enables a repeatable and scalable means of deploying and managing services and applications. This has led to widespread adoption across market verticals for both on-premises and cloud deployment models. The autonomous nature of Kubernetes operation, however, demands comprehensive, fully-converged observability and security. This is uniquely possible today using the Elastic platform.

VMware Tanzu and AWS Accelerate Apps: Key Takeaways from AWS re:Invent 2022

Another successful AWS re:Invent is in the books for VMware Tanzu. This year, like in previous years, the event had a high attendance with 51,000+ people descending on Las Vegas to learn and explore everything AWS-related. However, there were some notable changes in the focus areas for 2022. This year, VMware was pleased to see that Amazon hosted their first-ever Kubernetes Leadership segment at re:Invent, delivered by Barry Cooks, vice president, Kubernetes for AWS.

Docker Container Lifecycle Tutorial | Create, Run, Pause, Stop, Kill

In this tutorial, we will learn about Docker container lifecycle. But first, let me share a personal anecdote. On a hot summer afternoon in 2021, my manager called me out of the blue and said, “Muskan, the project file you shared with me is not working on my machine. Could you please come over and fix the setup? It’s really urgent.” I rushed to his cabin and tried my best but could not fix the dependencies issues.

From Struggle to Success: How We Solve Common DevOps Challenges

In a previous article, we walked you through key steps to become a proficient DevOps: However, even experienced DevOps are still struggling in their day-to-day work for several reasons. One of the most common challenges is the fast-paced nature of the DevOps field, which requires professionals to learn and adapt to new technologies and methodologies constantly. This can be difficult for even the most experienced individuals, as it requires them to stay up-to-date with the latest developments in the field.

Introduction to Kubernetes Imperative Commands

Kubernetes was born out of the need to make our complex applications highly available, scalable, portable and deployable in small microservices independently. It also extends its capabilities to make adoption of DevOps processes and helps you set up modern Incident Response strategies to enhance the reliability of your applications.

What You Need To Know About Hybrid Cloud Kubernetes

Enterprises are increasingly adopting Kubernetes. In fact, Gartner estimates that by 2026 more than 90% of global organizations will be running containerized applications in production, an increase from fewer than 40% in 2020. And IDC reports that 80% of new workloads are being developed in containers.

How to Monitor kube-controller-manager

When it comes to creating new Pods from a ReplicationController or ReplicaSet, ServiceAccounts for namespaces, or even new EndPoints for a Service, kube-controller-manager is the one responsible for carrying out these tasks. Monitoring the Kubernetes controller manager is fundamental to ensure the proper operation of your Kubernetes cluster. If you are in your cloud-native journey, running your workloads on top of Kubernetes, don’t miss the kube-controller-manager observability.

What's new in Calico Enterprise 3.15: FIPS 140-2 compliance, new dashboards, egress gateway pod failover, and more!

Tigera provides the industry’s only active Cloud-Native Application Security Platform (CNAPP) for containers and Kubernetes. Available as a fully managed SaaS (Calico Cloud) or a self-managed service (Calico Enterprise), the platform prevents, detects, troubleshoots, and automatically mitigates exposure risks of security issues in build, deploy, and runtime stages across multi-cluster, multi-cloud, and hybrid deployments.

Provoking thinking: Why we launched Civo Navigate

At Civo, we have always sought to expand people’s understanding of technology. From setting up an academy to help people get to grips with Kubernetes to running developer events around the world, we firmly believe that the benefits of technology should be accessible to everyone. There is a growing global community in the tech sector that is focused on a new way of doing things. This community is united by a conviction that these changes must be done for the benefit of all.

Sponsored Post

The Role of Kubernetes in Production Traffic Replication

Organizations are starting to realize that simply writing tests to generate traffic is simply not good enough. Rather, production traffic replication is now necessary, where you record traffic from your production environment and then replay it in your development environment. To match the modern principles of this testing methodology, it makes sense to also utilize modern infrastructure, like Kubernetes. Some benefits of using Kubernetes for production traffic replication are the ability to: Additionally, load generators are ephemeral. These reasons-and a few more besides-will be covered later in this post, but let's first take a deeper look at what production traffic replication is.

5 Predictions for Kubernetes in 2023

It should surprise no one that Kubernetes uptake is growing and will continue to do so. The wildly popular container orchestration platform’s continuous development is fueled by broad adoption. This will continue in 2023 as more companies, teams and individuals embrace it as a platform for innovation, building new applications and scaling existing ones faster than ever before.

A 2022 Recap for VMware Tanzu Application Service and Cloud Foundry

VMware Tanzu Application Service is a modern application platform for enterprises that want to deliver mission-critical microservices across clouds. The team at VMware Tanzu has been hard at work this year, continuing to enhance the overall developer and operator experiences on the platform. In addition to this work, the team continued to collaborate closely with the Cloud Foundry community and honor VMware’s commitment to open source ecosystems.

When to Use K3s and RKE2

K3s and Rancher Kubernetes Engine (RKE2) are two Kubernetes distributions from the SUSE Rancher container platform. Either project can be used to run a production-ready cluster; however, they target different use cases and consequently possess unique characteristics. This article will explain the similarities and differences between the projects. You’ll learn when it makes sense to use RKE2 instead of K3s and vice versa.

Exploring the New Container Checkpointing Feature

Kubernetes is a continuously evolving technology strongly supported by the open source community. In the last What’s new in Kubernetes 1.25, we mentioned the latest features that have been integrated. Among these, one may have great potential in future containerized environments because it can provide interesting forensics capabilities and container checkpointing.

Kubernetes and Cross-cloud Service Meshes

As today’s enterprises shift to the cloud, Kubernetes has emerged as the de facto platform for running containerized microservices. And while Kubernetes operates as a single cluster, enterprises inevitably run their applications on a complex, often confusing, architecture of multiple clusters deployed to a hybrid of multiple cloud providers and private data centers. This approach creates a lot of problems. How do your services find each other? How do they communicate securely?

Kubernetes Lens: Improving Operational Awareness of Kubernetes Clusters

Kubernetes Lens is an integrated development environment (IDE) that allows users to connect and manage multiple Kubernetes clusters on Mac, Windows, and Linux platforms. It is an intuitive graphical interface that allows users to deploy and manage clusters directly from the console. It provides dashboards that display key metrics and insights into everything running on a cluster, including deployments, configurations, networking, storage, and access control.

What is FluentD, and how does it work with Kubernetes?

FluentD is a free and open-source data collector. With its decentralized ecosystem, it’s known for its built-in reliability and cross-platform compatibility. One of the biggest challenges in big data collection is the lack of standardization between collection sources. They just aren’t able to talk to each other. With FluentD, you can address one of the biggest challenges to big data log collection.

VMware Tanzu Mission Control Year in Review: 2022 Edition

We aren’t done with 2022 yet, but phew! This was a busy year for the VMware Tanzu Mission Control team. In the two short years since VMware introduced Tanzu Mission Control, the Kubernetes management hub has evolved rapidly to meet industry trends and changing customer needs with important new features, such as data protection, lifecycle management capabilities, GitOps automation, and integration across the VMware portfolio, to name a few.

Getting started with the NGINX ingress controller

When moving production workloads to a new containerized environment, application traffic management (ATM) can become complex. This is especially true for organizations that are transitioning workloads to Kubernetes, as managing traffic requires load balancing and configuring other Kubernetes networking components, such as ingress and ingress controllers.

Rancher Wrap: Another Year of Innovation and Growth

2022 was another year of innovation and growth for SUSE’s Enterprise Container Management business. We introduced significant upgrades to our Rancher and NeuVector products, launched new open source projects and matured others. Exiting 2022, Rancher remains the industry’s most widely adopted container management platform and SUSE remains the preferred vendor for enabling enterprise cloud native transformation. Here’s a quick look at a few key themes from 2022.

Kubernetes Federated Clusters on AWS

This blog will discuss federated Kubernetes installations. Why and when we should use them and provide a working example of such a setup on AWS’s EKS. This blog post includes working code examples. As engineers with a never ending task list – which only grows as we strive for the next best thing we can add to our system – context is vital.

Container Monitoring Demo

Datadog Container Monitoring gives you real-time, end-to-end visibility into your containerized environments. In this demo, we show you how Container Monitoring helps you correlate container metrics with logs, traces, and network data to quickly detect and investigate anomalies across every layer of your Kubernetes clusters. We also walk you through setting up AI-enhanced monitors to receive automatic alerts for future issues.

Kubernetes Services: ClusterIP, Nodeport and LoadBalancer

Pods are ephemeral. And they are meant to be. They can be seamlessly destroyed and replaced if using a Deployment. Or they can be scaled at some point when using Horizontal Pod Autoscaling (HPA). This means we can’t rely on the Pod IP address to connect with applications running in our containers internally or externally, as the Pod might not be there in the future.

How to Monitor Kubernetes K3s Using Telegraf and InfluxDB Cloud

This article was originally published in The New Stack and is reposted here with permission. A Helm chart can simplify our lives and enable us to see what is happening with our K3s cluster using an external system. Lightweight Kubernetes, known as K3s, is an installation of Kubernetes half the size in terms of memory footprint. Do you need to monitor your nodes running K3s to know the status of your cluster?

Improve Visibility of Kubernetes Clusters with Tanzu Mission Control Events and Audit Logs

Kubernetes administrators and platform operators want quick access to information to help identify, troubleshoot, and track what happens on their Kubernetes clusters at any given time. However, lack of user attributes in events and audit logs can make it difficult for them to know who triggered an action, so VMware Tanzu Mission Control is expanding visibility into that data to fast-track remediation.

Kubernetes Observability 101: Tools, Best Practices, And More

Many companies are rapidly adopting cloud-native computing services, like containers, microservices, and serverless computing. Unlike monolithic applications, these technologies rely on distributed architectures. Whether you are running them in the cloud, on-premises, or both, distributed systems consist of thousands or millions of processes and components. The challenge now is to make these complex systems' inner workings visible, controllable, and improvable.

Argo Project Graduates With Unanimous Support

After 33k commits, nearly 200k contributions, 9.6k contributors, and almost 15k pull requests, the Argo Project has officially graduated within the Cloud Native Computing Foundation (CNCF). The Argo Project was first created and open-sourced in 2017 by Applatix who was later acquired by Intuit. Shortly thereafter, BlackRock, Codefresh, and RedHat joined the project as it moved into the CNCF.

Cycle is the LowOps Approach To Platform Engineering!

If you're involved in deploying and managing applications and servers, you know that it is a complex and resource-intensive process. Container orchestration platforms help automate the deployment, scaling, and management of your applications, but the challenges don’t stop there. Everything from the way applications communicate, down to the underlying infrastructure they run on, exposes vulnerabilities, complexities, and builds up technical debt.

Q&A: How to Find Value at the Edge Featuring Michele Pelino

We recently held a webinar, “Find Value at the Edge: Innovation Opportunities and Use Cases,” where Forrester Principal Analyst Michele Pelino was our guest speaker. After the event, we held a Q&A with Pelino highlighting edge infrastructure solutions and benefits. Here’s a look into the interview.

Scaling Your CI/CD: What You Need To Know

CI/CD is the process that ensures that code updates are deployed efficiently and reliably. However, more than simply having CI/CD pipelines is required for modern business application development needs. The problems start as soon as your team grows, but your CI/CD process does not. Static CI/CD pipelines result in an operational bottleneck and slow down your application workflow. Today, we will discuss why scaling your CI/CD is an inevitable need for your organization.

Baking Security into your DevOps Supply Chain with Argo CD & OPA - Dan Garfield (DevOps Experience)

Argo CD has become the defacto entry for engineering teams to deploy and manage their applications while Open Policy Agent has become one of the most reliable security policy enforcement engines. These two tools work perfectly together and yet there are very few articles and videos on the subject! In this talk, we look at the best strategies for getting these tools to work together to improve the software delivery supply chain. We’ll look at admission hooks, sync waves, and other ways to ensure your applications and clusters are always running in a secure and safe manner. Including example files and reference repos.

A day in the life of a Customer Support Detective

I open my laptop and look over my cases while I slurp down my first cup of coffee. Most of my backlog is waiting on customer updates, or bug fixes. Two of my cases have been marked for closure. Not a bad start for a Monday! A pod CrashLoopBackoff issue was resolved by bumping up memory requests, and the missing metrics issue was solved after applying some Prometheus annotations to the customer’s nginx pods. I notate and close both cases. No sooner do I hear the beep of the badge scanner.

How to Setup InfluxDB, Telegraf and Grafana on Docker: Part 2

This tutorial describes how to install the Telegraf plugin as a data-collection interface with InfluxDB 1.7 and Docker. In Part 1 of this tutorial series, we covered the steps to install InfluxDB 1.7 on Docker for Linux instances. We describe in Part 2 how to install the Telegraf plugin as a data-collection interface with InfluxDB 1.7 and Docker.

Take a Journey to the Center of the Multi-Cloud Universe: A VMware Explore 2022 Recap

Another VMware Explore has come and gone! Thousands of attendees have headed home from Barcelona ready to implement new strategies, skillsets, and tools for making digital transformation happen. It’s no secret that converting traditional data centers into virtualized, modernized environments can be a daunting task. In fact, the general session was kicked off by CEO Raghu Raghuram, who discussed what the typical customer’s journey looks like.

VMware Application Catalog extends support to JFrog Container Registry

VMware Application Catalog (formerly Tanzu Application Catalog) is a catalog of trusted, continuously maintained, and verifiably tested open source images, custom-built to enterprise specifications and privately delivered directly to a customer’s registry of choice. Until recently, VMware Application Catalog had Google Container Registry, Azure Container Registry, and Harbor as supported registries, but last month we announced support for Amazon Elastic Container Registry.