81 posts in category technical

Blog post cover image

Can You Leave? Data Portability & Egress

Data export formats, API/query-language openness, and egress pricing checked across AWS, GCP, Azure, OVH, and five EU sovereignty offerings. Part 5 of 6.

Can You Leave? Data Portability & Egress
Blog post cover image

Digital Sovereignty: The Complete Guide

Reading guide for a six-part series testing "sovereign cloud" claims against ownership, technology stack, access, enforcement, exit, and switching cost.

Digital Sovereignty: The Complete Guide
Blog post cover image

What Does It Cost to Leave — or Arrive?

Switching cost in practice: skills gaps, familiarity, and a working example of designing for reversibility instead of assuming permanence. Part 6 of 6.

What Does It Cost to Leave — or Arrive?
Blog post cover image

Who Builds the Platform? Ownership vs. Stack

Bleu, S3NS, Google, Microsoft, and AWS: how EU sovereign-cloud ownership claims pair with technology stacks — checked against primary sources. Part 2 of 6.

Who Builds the Platform? Ownership vs. Stack
Rust programming language logo

k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob

A Rust CLI that scales or restarts a single Kubernetes Deployment from a CronJob — with cosign-signed images, SPDX SBOM attestation, and SLSA build provenance.

k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob
Code displayed on a screen

Which Tool Mirrors a Cosign-Signed Image into a Private Registry?

A verified, sourced comparison of regctl, oras, skopeo, Zot, Harbor, and cosign copy for mirroring a Cosign-signed container image into a private registry.

Which Tool Mirrors a Cosign-Signed Image into a Private Registry?
Kubernetes logo

K8s & OpenShift: Compliance

NIS2, DORA, PCI-DSS, HIPAA, and CRA controls mapped to Kubernetes configuration — audit logging, log retention, and incident reporting. Part 7 of 7.

K8s & OpenShift: Compliance
Kubernetes logo

K8s & OpenShift: Day-2 Operations & GitOps

GitOps with Argo CD and Flux, observability, FinOps controls, and cluster upgrade strategies — keeping a Kubernetes cluster healthy after launch. Part 6 of 7.

K8s & OpenShift: Day-2 Operations & GitOps
Diagram: Kubernetes CPU and memory zones from request to limit, showing CFS throttling for CPU and OOM kill for memory

K8s & OpenShift: Resource Management

How Kubernetes enforces CPU and memory boundaries: requests vs limits, QoS classes, cgroup v2, and what happens when a container hits its limit. Part 3 of 7.

K8s & OpenShift: Resource Management
Flowchart: Kubernetes pod termination sequence from scale-down or node drain through preStop hook and SIGTERM to SIGKILL

K8s & OpenShift: Scaling & Resilience

HPA, VPA, cluster autoscaler, pod disruption budgets, and topology spread — how to scale Kubernetes workloads and keep them available under load. Part 4 of 7.

K8s & OpenShift: Scaling & Resilience