Unclaimed tool
Kubernetes
kubernetes.io
Portable platform for orchestrating containerized workloads.
Unclaimed tool
kubernetes.io
Portable platform for orchestrating containerized workloads.
From public taxonomy evidence
When migrating hooks from the Elastic CI Stack, do not rely on env vars set in pre-checkout, checkout, or post-checkout reaching pre-command or command hooks.
supporting matchWhen exporting the Defender daemonset with twistcli defender export kubernetes, always pass --privileged and --cri.
supporting matchWhat Middleware.io users hit in practice, with the verified fix: Middleware on Kubernetes: one DaemonSet per cluster, name each cluster
supporting matchThe supported Kubernetes install is the Helm chart: a DaemonSet agent on every node plus the Cluster Agent for cluster-level metadata. The Datadog Operator is the alternative for GitOps shops.
supporting matchWorkload identity federates a Kubernetes service account to an Entra managed identity. Pods get tokens via the OIDC issuer with no secrets to rotate, replacing the old pod-identity and secret-mount patterns.
supporting matchHow to fix stale internode gRPC connections after pod termination when using Kubernetes Deployments (Temporal). The verified answer from the upstream issue, distilled into steps.
supporting matchIf the Grafana 12.0 to 12.1 upgrade gets stuck on the annotation migration with the pod crashlooping (Kubernetes restarts the pod mid-migration, leaving several copies of the slow query running), the fix shipped in v12.2.3 and v12.3.1 via PR #113589, so upgrade past that. If you are mid-upgrade: scale Grafana down to o
supporting matchWhen deploying a multi-node Qdrant cluster with docker-compose / swarm / kubernetes, the initial cluster topology (bootstrap, peer URIs) could only be passed as CLI flags (--bootstrap, --uri), not configured in config.yaml, making containerized scaling awkward.
supporting matchIn Lacework: It is safe to upgrade. The agent discovers and queries whatever APIs exist on the cluster, so it will not call removed APIs on 1.29.
supporting matchHow to fix mend io: renovate process never exits since 24.40.0 in kubernetes.
supporting matchRename the 26257 port from grpc to tcp in the CockroachDB Service and StatefulSet manifests so the Istio sidecar treats the traffic as plain TCP instead of trying gRPC protocol sniffing. That is the fix multiple users confirmed (one via mike-holberger's manifests, another directly: changing grpc to tcp in the service a
supporting matchTeaches the verified fix from a real dagger support thread: how to run Dagger inside a container, for example on Kubernetes
supporting matchPublic conversations
Public search query: Coralogix Kubernetes integrations need a coralogix-keys secret with
Public search query: Migrating Buildkite hooks to the Kubernetes stack env
Starting with Renovate 24.40.0, the renovate process finishes its work but never exits, hanging the Kubernetes cronjob pod. The cause was the AWS SDK ECR client keeping a connection open, so the node process stayed alive.
Running CockroachDB (insecure mode) as a StatefulSet on GKE with Istio injected, cockroach sql --insecure failed with connection refused even though the pods were running. The root cause discussed in the thread: the install manifests name the 26257 port grpc, so the Istio sidecar tries to speak gRPC to it, but Cockroac
Self-hosted Prefect 3 servers showed memory climbing steadily until Kubernetes OOM-killed the pod, a regression from Prefect 2 which was flat. The reporter ran without Redis and noted Prefect 2 had no such problem. Prefect maintainers and collaborators dug in and found several contributing leaks: unbounded queues in th
Upgrading Flipt from 1.8.3 to 1.9.0 or 1.10.0 breaks Postgres connectivity in Kubernetes with: getting db driver for: postgres: dial tcp: lookup postgres.database.svc.cluster.local: device or resource busy. Versions 1.8.2 and 1.8.3 worked fine, and the error appears even against a fresh database, so it is a regression
On recent agent versions the Kubernetes API deprecation dashboard still flags /apis/flowcontrol.apiserver.k8s.io/v1beta2/flowschemas usage. The agent works on multiple Kubernetes versions, so it queries whatever APIs are present on each cluster for backward compatibility.
After upgrading to Kubernetes 1.29, the Lacework agent logs show it querying APIs that were removed in 1.29, like the flowcontrol v1beta2 resources. The worry is the agent will break against the removed APIs.
Unclaimed tool
kubernetes.io
Portable platform for orchestrating containerized workloads.
From public taxonomy evidence
When migrating hooks from the Elastic CI Stack, do not rely on env vars set in pre-checkout, checkout, or post-checkout reaching pre-command or command hooks.
supporting matchWhen exporting the Defender daemonset with twistcli defender export kubernetes, always pass --privileged and --cri.
supporting matchWhat Middleware.io users hit in practice, with the verified fix: Middleware on Kubernetes: one DaemonSet per cluster, name each cluster
supporting matchThe supported Kubernetes install is the Helm chart: a DaemonSet agent on every node plus the Cluster Agent for cluster-level metadata. The Datadog Operator is the alternative for GitOps shops.
supporting matchWorkload identity federates a Kubernetes service account to an Entra managed identity. Pods get tokens via the OIDC issuer with no secrets to rotate, replacing the old pod-identity and secret-mount patterns.
supporting matchHow to fix stale internode gRPC connections after pod termination when using Kubernetes Deployments (Temporal). The verified answer from the upstream issue, distilled into steps.
supporting matchIf the Grafana 12.0 to 12.1 upgrade gets stuck on the annotation migration with the pod crashlooping (Kubernetes restarts the pod mid-migration, leaving several copies of the slow query running), the fix shipped in v12.2.3 and v12.3.1 via PR #113589, so upgrade past that. If you are mid-upgrade: scale Grafana down to o
supporting matchWhen deploying a multi-node Qdrant cluster with docker-compose / swarm / kubernetes, the initial cluster topology (bootstrap, peer URIs) could only be passed as CLI flags (--bootstrap, --uri), not configured in config.yaml, making containerized scaling awkward.
supporting matchIn Lacework: It is safe to upgrade. The agent discovers and queries whatever APIs exist on the cluster, so it will not call removed APIs on 1.29.
supporting matchHow to fix mend io: renovate process never exits since 24.40.0 in kubernetes.
supporting matchRename the 26257 port from grpc to tcp in the CockroachDB Service and StatefulSet manifests so the Istio sidecar treats the traffic as plain TCP instead of trying gRPC protocol sniffing. That is the fix multiple users confirmed (one via mike-holberger's manifests, another directly: changing grpc to tcp in the service a
supporting matchTeaches the verified fix from a real dagger support thread: how to run Dagger inside a container, for example on Kubernetes
supporting matchPublic conversations
Public search query: Coralogix Kubernetes integrations need a coralogix-keys secret with
Public search query: Migrating Buildkite hooks to the Kubernetes stack env
Starting with Renovate 24.40.0, the renovate process finishes its work but never exits, hanging the Kubernetes cronjob pod. The cause was the AWS SDK ECR client keeping a connection open, so the node process stayed alive.
Running CockroachDB (insecure mode) as a StatefulSet on GKE with Istio injected, cockroach sql --insecure failed with connection refused even though the pods were running. The root cause discussed in the thread: the install manifests name the 26257 port grpc, so the Istio sidecar tries to speak gRPC to it, but Cockroac
Self-hosted Prefect 3 servers showed memory climbing steadily until Kubernetes OOM-killed the pod, a regression from Prefect 2 which was flat. The reporter ran without Redis and noted Prefect 2 had no such problem. Prefect maintainers and collaborators dug in and found several contributing leaks: unbounded queues in th
Upgrading Flipt from 1.8.3 to 1.9.0 or 1.10.0 breaks Postgres connectivity in Kubernetes with: getting db driver for: postgres: dial tcp: lookup postgres.database.svc.cluster.local: device or resource busy. Versions 1.8.2 and 1.8.3 worked fine, and the error appears even against a fresh database, so it is a regression
On recent agent versions the Kubernetes API deprecation dashboard still flags /apis/flowcontrol.apiserver.k8s.io/v1beta2/flowschemas usage. The agent works on multiple Kubernetes versions, so it queries whatever APIs are present on each cluster for backward compatibility.
After upgrading to Kubernetes 1.29, the Lacework agent logs show it querying APIs that were removed in 1.29, like the flowcontrol v1beta2 resources. The worry is the agent will break against the removed APIs.