Skip to content

Tag: kubernetes

All the articles with the tag "kubernetes".

Cilium on k3s: When eBPF Networking Pays

Cilium on k3s: When eBPF Networking Pays

· Updated:

Replace flannel with Cilium 1.19 on k3s for eBPF routing, Hubble observability, WireGuard encryption, and L7 network policies, here's when it pays off.

k3s + Tailscale: Cluster Across Two Sites

k3s + Tailscale: Cluster Across Two Sites

· Updated:

Run a single k3s cluster spanning two physical sites using Tailscale as the WireGuard fabric, home lab server plus cloud VPS, one single kubectl context.

KubeVirt on k3s: VMs Next to Pods

KubeVirt on k3s: VMs Next to Pods

· Updated:

Run real KVM virtual machines as Kubernetes resources on k3s. One control plane for pods and VMs, no more juggling Proxmox alongside your cluster every day.

OPA & Gatekeeper: Policy as Code

OPA & Gatekeeper: Policy as Code

· Updated:

Open Policy Agent and Gatekeeper enforce rules across Kubernetes, block privileged pods, require labels, restrict images. Rego basics and real homelab constraints.

Longhorn vs Rook-Ceph

Longhorn vs Rook-Ceph

Two ways to give your K8s cluster persistent block storage, Longhorn for simplicity, Rook-Ceph for scale. Real homelab tradeoffs, not vendor marketing slides.

Gateway API vs Ingress in 2026

Gateway API vs Ingress in 2026

Ingress is the annotation-soup classic. Gateway API is the role-oriented future with proper L4/L7 separation. Here's when to migrate and when to wait.

Velero: K8s Backup and DR

Velero: K8s Backup and DR

Your cluster will fail. Velero captures everything, manifests, CRDs, persistent volumes, and lets you replay it on a fresh cluster. Setup, gotchas, real DR plans.

cert-manager: ACME at Scale

cert-manager: ACME at Scale

cert-manager makes Let's Encrypt automatic on Kubernetes, once. Then you scale, hit DNS-01 quirks, wildcard limits, and rate-limit walls. Here's the full survival guide.