Boundary vs Teleport
Zero-trust access for SSH, k8s, and databases, HashiCorp Boundary vs Teleport compared on identity, session recording, and self-host fit.
All the articles with the tag "devops".
Zero-trust access for SSH, k8s, and databases, HashiCorp Boundary vs Teleport compared on identity, session recording, and self-host fit.
Three inner-loop dev tools for Kubernetes, Garden, Tilt, and Skaffold. Which one actually makes K8s development bearable? Honest comparison, no fluff.
Docker Compose Watch syncs your code into running containers without rebuilds. Here's how to set it up and why your dev loop is about to get a lot less painful.
Build container images without writing a single Dockerfile, ko for Go, Jib for Java, Paketo Buildpacks for everything else. Real benchmarks, real tradeoffs.
Cosign keyless signing uses GitHub OIDC + Fulcio + Rekor to sign container images without managing private keys. Here's how it actually works and why you want it.
Orchestrating multi-image Docker builds: docker buildx bake vs compose build, matrix targets, multi-arch, caching, and when each one actually wins.
nerdctl is the containerd-native docker CLI replacement, when it's a drop-in, when it's not, and why you'd bother switching at all.
Trivy, Grype, and Docker Scout go head-to-head on speed, CVE coverage, CI integration, and cost. Pick the right scanner for your home lab or pipeline.
OpenTelemetry plus the Grafana LGTM stack gives you Datadog-class traces, metrics, and logs for $0/month. Deploy an OTel Collector and instrument your app fast.
K3s, K0s, and MicroK8s all slim down Kubernetes for home labs and edge, but they make very different tradeoffs. Here's how to pick the right one without losing a weekend.
Per-container control over Docker image updates with labels. Auto-update or notify via Discord, Slack, ntfy, no sidecar needed.
You've been compromised. Now what? A practical incident response playbook for self-hosters who didn't think they'd need one until right now.