Podo Stack
Subscribe
Sign in
Home
Notes
Archive
About
Latest
Top
Discussions
The Flux Kustomization that adopted a namespace it never should have touched
path scope, targetNamespace, prune: true, atomic paths, .fluxignore
Sep 4
•
Ilia Gusev
The 25% of your node that's gone before the first pod lands
kube-reserved, eviction thresholds, pause containers, DaemonSet overhead, hosted control plane fees
Sep 2
•
Ilia Gusev
TOON, zot, and the RCE Kubernetes calls working as intended
A token format that beats JSON by half, a registry that ditched the database, the Probe CRD gap nobody's closed, and a WebSocket handshake that skips…
Sep 1
•
Ilia Gusev
August 2026
LowCardinality: the dictionary stops at 8192
The rule of thumb everyone repeats is downstream of one default setting, and crossing it produces no error - just a column that quietly goes back to…
Aug 28
•
Ilia Gusev
Knative and PDB: protects nothing, blocks drains forever
A PodDisruptionBudget on a Knative revision cannot stop the autoscaler removing your pod, and it can absolutely stop you draining the node it runs on
Aug 26
•
Ilia Gusev
Issue #032 - Keyless signing: nobody manages signing keys anymore
The key-custody problem is solved and what replaced it is a verification problem, which is harder to notice when you have got it wrong
Aug 25
•
Ilia Gusev
Topology-aware routing: 7 replicas work, 8 don't
The annotation refuses to act when the arithmetic looks risky, the newer trafficDistribution field has no such guard, and migrating between them quietly…
Aug 21
•
Ilia Gusev
Informer resync: the API call that never happens
Lowering resyncPeriod to get fresher data is advice built on a misreading, and the client-go source settles it in one line
Aug 19
•
Ilia Gusev
Issue #031 - Ambient mesh: the sidecar was a five-year detour
Istio's node proxy opens its listening sockets inside your pod's network namespace, and it holds a workload certificate for every service account…
Aug 18
•
Ilia Gusev
externalTrafficPolicy Local: client IP for skewed load
The setting that preserves the source address also hands each node an equal share of traffic regardless of how many pods it is running
Aug 14
•
Ilia Gusev
1
Hyperthreading: the throughput win that costs you latency
Netflix turned SMT off on a 24xlarge and container launches got 20-30% faster, because two siblings fighting over one lock also fight over one core
Aug 12
•
Ilia Gusev
Issue #030 - Mount storm: 20,200 syscalls to start 100 pods
User namespaces made containers safer and rewrote the arithmetic of startup, and the global lock underneath is a pattern you have met before
Aug 11
•
Ilia Gusev
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts