<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
      <title>Alek&#x27;s Blog - best-practices</title>
      <link>https://blog.none.at</link>
      <description>Production notes on Kubernetes, OpenShift, and OVHcloud: observability, log archiving, service mesh, LLM inference, and digital sovereignty.</description>
      <generator>Zola</generator>
      <language>en</language>
      <atom:link href="https://blog.none.at/tags/best-practices/rss.xml" rel="self" type="application/rss+xml"/>
      <lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate>
      <item>
          <title>K8s &amp; OpenShift: Compliance</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-compliance/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-compliance/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-compliance/">&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-07-01-k8s-openshift-bp-operations&#x2F;&quot;&gt;Part 6&lt;&#x2F;a&gt; covered the operational loop:
GitOps, observability, cost control, and upgrades. This final part maps the cluster configuration
covered throughout this series to the regulatory frameworks that require it — NIS2, DORA,
PCI-DSS, HIPAA, and the Cyber Resilience Act (CRA) — and covers the two topics that compliance
work adds on top of security: audit logging as evidence and log retention as a contractual
obligation.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>K8s &amp; OpenShift: Day-2 Operations &amp; GitOps</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-operations/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-operations/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-operations/">&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-07-01-k8s-openshift-bp-security&#x2F;&quot;&gt;Part 5&lt;&#x2F;a&gt; covered the security controls that
harden workloads and the cluster. This part covers what keeps a cluster healthy after the initial
deployment: GitOps workflows, observability, cost control, and the operational cadence of upgrades.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>K8s &amp; OpenShift: The Big Picture</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-overview/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-overview/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-overview/">&lt;p&gt;This is the opening post of a seven-part series on Kubernetes and OpenShift best practices, written
from the vantage point of 2026 and eight years of hands-on experience — from initial cluster design
through Day-2 operations and production debugging. This first part is deliberately non-technical: it is about &lt;em&gt;whether&lt;&#x2F;em&gt;
and &lt;em&gt;when&lt;&#x2F;em&gt; a container platform earns its keep — the decisions that happen before anyone writes a
single YAML manifest.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>K8s &amp; OpenShift: Resource Management</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-resources/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-resources/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-resources/">&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-07-01-k8s-openshift-bp-workloads&#x2F;&quot;&gt;Part 2&lt;&#x2F;a&gt; covered the workload contract —
probes, security context, graceful shutdown. This part goes one level lower: how the Linux kernel
enforces the resource boundaries you declare in your YAML, what happens when a container hits
those boundaries, and why misconfigurations here are the single most common source of both cloud
waste and production incidents.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>K8s &amp; OpenShift: Scaling &amp; Resilience</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-scaling/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-scaling/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-scaling/">&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-07-01-k8s-openshift-bp-resources&#x2F;&quot;&gt;Part 3&lt;&#x2F;a&gt; covered resource requests, limits,
and how the kernel enforces them. This part covers what sits on top of that foundation: the
mechanisms Kubernetes provides to scale workloads automatically and to keep them available when
nodes drain, cluster upgrades run, or traffic spikes arrive unexpectedly.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>K8s &amp; OpenShift: Security</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-security/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-security/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-security/">&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-07-01-k8s-openshift-bp-scaling&#x2F;&quot;&gt;Part 4&lt;&#x2F;a&gt; covered scaling and resilience.
This part covers security — not as a checklist to complete before an audit, but as a set of
controls that reduce real attack surface and limit the blast radius when something goes wrong.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>K8s &amp; OpenShift: Building Workloads Right</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-workloads/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-workloads/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-k8s-openshift-bp-workloads/">&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-07-01-k8s-openshift-bp-overview&#x2F;&quot;&gt;Part 1&lt;&#x2F;a&gt; covered the business case and
organisational framing. This part goes inside the pod: image hygiene, security context, health
probes, graceful shutdown, and the application design choices that determine whether a workload
actually fits the platform.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>The Kubernetes &amp; OpenShift Best Practices Guide (2026 Edition)</title>
          <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-07-01-kubernetes-openshift-best-practices-guide-2026/</link>
          <guid>https://blog.none.at/blog/2026/2026-07-01-kubernetes-openshift-best-practices-guide-2026/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-07-01-kubernetes-openshift-best-practices-guide-2026/">&lt;p&gt;This is the index and reading guide for a seven-part series on running Kubernetes and OpenShift in
production, written from the vantage point of 2026 and eight years of hands-on cluster design,
Day-2 operations, and production debugging. Each part stands on its own; together they cover a
workload’s whole life on the platform — from the image it ships in to the audit trail it leaves
behind.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>Kubernetes &amp; OpenShift Best Practices in 2026: The Big Picture</title>
          <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-xx-xx-new-post/</link>
          <guid>https://blog.none.at/blog/2026/2026-xx-xx-new-post/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-xx-xx-new-post/">&lt;p&gt;Hier beschreiben wir ein paar Best practices für Applikation die in Kubernetes laufen sollen.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;IMMER Container probes  nutzen&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Die Container probes ermöglichen dem Kubernetes System den Zustand der Applikation von außen festzustellen. Die Probes sollten leichtgewichtig sein aber auch aussagekräftig.&lt;&#x2F;p&gt;
&lt;p&gt;Hier ein paar Beispiele für Java basierte Applikationen&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Spring Boot: health ac…&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Tomcat: Health Check Valve&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Prometheus Endpunkte zur Verfügung stellen was das Monitoring in der Container Welt wesentlich vereinfacht. Es gibt für viele Programmiersprachen CLIENT LIBRARIES  was die Verfügungstellung der Endpukte vereinfacht.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Die Applikation MUSS jederzeit bereit sein gestopped zu werden.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Falls mehr als eine Instanz (Pod’s) zur gleichen Zeit laufen sollen ( replicas &amp;gt;1 ) muss die Applikation “Clusterfähig” sein.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Für Session Daten sollte man keine lokale Ablage nutzen.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Logging by default auf STDOUT oder via einem Logshipper auf eine zentrales Logging System&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Best practice für Container Image Erstellung&lt;&#x2F;p&gt;
&lt;p&gt;Hier fassen wir einige Richtlinien und Tips zusammen welche aus unserer Erfahrung hilfreich sind.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Keine spezifischen User&lt;&#x2F;p&gt;
&lt;p&gt;Der Hintergrund dafür ist das man damit die Möglichkeit hat der Container Runtime die Runtime Sicherheit zu spezifizieren und konfigurieren.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Keine Shell freien Basis-Images nutzen (z. B.: Distroless, Scratch, …)&lt;&#x2F;p&gt;
&lt;p&gt;Der Hintergrund dafür ist das man ohne Shell einen laufenden Container gar nicht oder sehr schwer Debuggen kann.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Immer spezifische Versionen in der Produktion laufen lassen&lt;&#x2F;p&gt;
&lt;p&gt;Der Hintergrund dafür ist das “latest” alles mögliche sein kann.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Es sollten zu mindest folgende Tools im Image installiert sein.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;curl&lt;&#x2F;li&gt;
&lt;li&gt;ps&lt;&#x2F;li&gt;
&lt;li&gt;dig&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;alpine als Basis-Images Image nutzt nicht die glibc sondern die musl libc  was zu gewissen Problemen führen kann.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Setzen der Time and timezones  geht nicht über TZ Variable&lt;&#x2F;li&gt;
&lt;li&gt;Bisher haben sich ubuntu und UBI  Basis-Images als recht zuverlässig herausgestellt&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
</description>
      </item>
    </channel>
</rss>
