kubernetes
In-depth articles from the OrchesTerra engineering team.
Kubernetes
How Karpenter decides to replace nodes, how disruption budgets interact with PDBs, and the settings that stop consolidation from evicting production at the worst time.
2026-09-08 · 4 min read
Kubernetes
Validate, mutate, and generate with Kyverno without turning every deploy into a 403 — policy types, failure actions, exceptions, and a starter set for platform clusters.
2026-09-07 · 4 min read
ArgoCD
Hub-and-spoke vs per-cluster Argo CD, Application destination vs ApplicationSet, secrets, and the RBAC mistakes that let staging sync prod.
2026-09-05 · 4 min read
Kubernetes
What CPU limits actually do, why memory limits OOMKill, how requests drive scheduling, and a way to set numbers from Prometheus instead of folklore.
2026-09-04 · 4 min read
ArgoCD
How sync waves and sync phases actually work, when to use them instead of PreSync hooks, and the failure modes that leave apps stuck OutOfSync.
2026-09-02 · 5 min read
Kubernetes
How to put real workload on Spot / preemptible nodes without turning every interruption into an incident — taints, PDBs, grace periods, and mixed on-demand capacity.
2026-09-01 · 5 min read
Kubernetes
A practical ESO setup: ClusterSecretStore, ExternalSecret refresh, IRSA/Workload Identity, and the failure modes that look like “the app has empty env vars.”
2026-08-22 · 4 min read
Kubernetes
Patterns for building reliable, auditable GitOps workflows on Kubernetes—covering repository structure, reconciliation hygiene, and governance gates.
2026-08-10 · 2 min read
Kubernetes
A platform-team checklist to keep clusters cost-efficient and security-hardened: quotas, least privilege, network restrictions, and rightsizing.
2026-06-20 · 2 min read