[{"data":1,"prerenderedAt":1490},["ShallowReactive",2],{"navigation":3,"\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026":508,"\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026-surround":1484},[4],{"title":5,"icon":6,"path":7,"stem":8,"children":9},"Docs","i-ph-book-open","\u002Fdocs","1.docs",[10,12,23,63,73,99,123,214,279,287,326,394,420,482],{"title":5,"path":7,"stem":11},"1.docs\u002Findex",{"title":13,"icon":14,"path":15,"stem":16,"children":17,"page":22},"Coffee","i-ph-coffee-bean","\u002Fdocs\u002Fcoffee","1.docs\u002Fcoffee",[18],{"title":19,"path":20,"stem":21},"Shops","\u002Fdocs\u002Fcoffee\u002Fshops","1.docs\u002Fcoffee\u002Fshops",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Databases","i-ph-database","\u002Fdocs\u002Fdatabases","1.docs\u002Fdatabases",[29,33],{"title":30,"path":31,"stem":32},"MongoDB","\u002Fdocs\u002Fdatabases\u002Fmongodb","1.docs\u002Fdatabases\u002Fmongodb",{"title":34,"icon":35,"path":36,"stem":37,"children":38,"page":22},"MySQL","i-simple-icons-mysql","\u002Fdocs\u002Fdatabases\u002Fmysql","1.docs\u002Fdatabases\u002Fmysql",[39,43,47,51,55,59],{"title":40,"path":41,"stem":42},"Cheat Sheet","\u002Fdocs\u002Fdatabases\u002Fmysql\u002Fcheat-sheet","1.docs\u002Fdatabases\u002Fmysql\u002Fcheat-sheet",{"title":44,"path":45,"stem":46},"event_scheduler","\u002Fdocs\u002Fdatabases\u002Fmysql\u002Fevent_scheduler","1.docs\u002Fdatabases\u002Fmysql\u002Fevent_scheduler",{"title":48,"path":49,"stem":50},"init_file: Run SQL file on startup","\u002Fdocs\u002Fdatabases\u002Fmysql\u002Finit_file","1.docs\u002Fdatabases\u002Fmysql\u002Finit_file",{"title":52,"path":53,"stem":54},"MariaDB","\u002Fdocs\u002Fdatabases\u002Fmysql\u002Fmariadb","1.docs\u002Fdatabases\u002Fmysql\u002Fmariadb",{"title":56,"path":57,"stem":58},"Pitfalls","\u002Fdocs\u002Fdatabases\u002Fmysql\u002Fpitfalls","1.docs\u002Fdatabases\u002Fmysql\u002Fpitfalls",{"title":60,"path":61,"stem":62},"Slow Log","\u002Fdocs\u002Fdatabases\u002Fmysql\u002Fslow-log","1.docs\u002Fdatabases\u002Fmysql\u002Fslow-log",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":22},"Development","i-ph-code","\u002Fdocs\u002Fdevelopment","1.docs\u002Fdevelopment",[69],{"title":70,"path":71,"stem":72},"Protobuf \u002F gRPC","\u002Fdocs\u002Fdevelopment\u002Fprotobuf","1.docs\u002Fdevelopment\u002Fprotobuf",{"title":74,"icon":75,"path":76,"stem":77,"children":78,"page":22},"General","i-ph-wrench","\u002Fdocs\u002Fgeneral","1.docs\u002Fgeneral",[79,83,87,91,95],{"title":80,"path":81,"stem":82},"ADB","\u002Fdocs\u002Fgeneral\u002Fadb","1.docs\u002Fgeneral\u002Fadb",{"title":84,"path":85,"stem":86},"VS Codium","\u002Fdocs\u002Fgeneral\u002Fcodium","1.docs\u002Fgeneral\u002Fcodium",{"title":88,"path":89,"stem":90},"OpenSSL","\u002Fdocs\u002Fgeneral\u002Fopenssl","1.docs\u002Fgeneral\u002Fopenssl",{"title":92,"path":93,"stem":94},"Projects, Tools and Utilites","\u002Fdocs\u002Fgeneral\u002Ftools-utilities","1.docs\u002Fgeneral\u002Ftools-utilities",{"title":96,"path":97,"stem":98},"Online Tools","\u002Fdocs\u002Fgeneral\u002Fuseful-online-tools","1.docs\u002Fgeneral\u002Fuseful-online-tools",{"title":100,"icon":101,"path":102,"stem":103,"children":104,"page":22},"Hassio","i-simple-icons-homeassistant","\u002Fdocs\u002Fhassio","1.docs\u002Fhassio",[105,115,119],{"title":106,"icon":107,"path":108,"stem":109,"children":110,"page":22},"ESPHome","i-simple-icons-esphome","\u002Fdocs\u002Fhassio\u002Fesphome","1.docs\u002Fhassio\u002Fesphome",[111],{"title":112,"path":113,"stem":114},"Voltage - ADC","\u002Fdocs\u002Fhassio\u002Fesphome\u002Fvoltage-adc","1.docs\u002Fhassio\u002Fesphome\u002Fvoltage-adc",{"title":116,"path":117,"stem":118},"Raspberry Pi","\u002Fdocs\u002Fhassio\u002Fraspberrypi","1.docs\u002Fhassio\u002Fraspberrypi",{"title":120,"path":121,"stem":122},"Zigbee2MQTT","\u002Fdocs\u002Fhassio\u002Fzigbee2mqtt","1.docs\u002Fhassio\u002Fzigbee2mqtt",{"title":124,"icon":125,"path":126,"stem":127,"children":128,"page":22},"Kubernetes","i-simple-icons-kubernetes","\u002Fdocs\u002Fkubernetes","1.docs\u002Fkubernetes",[129,133,136,140,157,161,165,175,188,192,210],{"title":130,"path":131,"stem":132},"Certificates","\u002Fdocs\u002Fkubernetes\u002Fcertificates","1.docs\u002Fkubernetes\u002Fcertificates",{"title":40,"path":134,"stem":135},"\u002Fdocs\u002Fkubernetes\u002Fcheat-sheet","1.docs\u002Fkubernetes\u002Fcheat-sheet",{"title":137,"path":138,"stem":139},"Cluster Components Upgrade Order","\u002Fdocs\u002Fkubernetes\u002Fcluster-components-upgrade-order","1.docs\u002Fkubernetes\u002Fcluster-components-upgrade-order",{"title":141,"icon":142,"path":143,"stem":144,"children":145,"page":22},"Etcd","i-simple-icons-etcd","\u002Fdocs\u002Fkubernetes\u002Fetcd","1.docs\u002Fkubernetes\u002Fetcd",[146,149,153],{"title":40,"path":147,"stem":148},"\u002Fdocs\u002Fkubernetes\u002Fetcd\u002Fcheat-sheet","1.docs\u002Fkubernetes\u002Fetcd\u002Fcheat-sheet",{"title":150,"path":151,"stem":152},"Editing Kubernetes Objects","\u002Fdocs\u002Fkubernetes\u002Fetcd\u002Fediting-kubernetes-objects","1.docs\u002Fkubernetes\u002Fetcd\u002Fediting-kubernetes-objects",{"title":154,"path":155,"stem":156},"Snapshots: Save & Restore","\u002Fdocs\u002Fkubernetes\u002Fetcd\u002Fsnapshots-save-restore","1.docs\u002Fkubernetes\u002Fetcd\u002Fsnapshots-save-restore",{"title":158,"path":159,"stem":160},"Ingress","\u002Fdocs\u002Fkubernetes\u002Fingress","1.docs\u002Fkubernetes\u002Fingress",{"title":162,"path":163,"stem":164},"kubeadm","\u002Fdocs\u002Fkubernetes\u002Fkubeadm","1.docs\u002Fkubernetes\u002Fkubeadm",{"title":166,"icon":167,"path":168,"stem":169,"children":170,"page":22},"Logging","i-ph-log","\u002Fdocs\u002Fkubernetes\u002Flogging","1.docs\u002Fkubernetes\u002Flogging",[171],{"title":172,"path":173,"stem":174},"Regex","\u002Fdocs\u002Fkubernetes\u002Flogging\u002Fregex","1.docs\u002Fkubernetes\u002Flogging\u002Fregex",{"title":176,"icon":177,"path":178,"stem":179,"children":180,"page":22},"Monitoring","i-ph-binoculars","\u002Fdocs\u002Fkubernetes\u002Fmonitoring","1.docs\u002Fkubernetes\u002Fmonitoring",[181,184],{"title":176,"path":182,"stem":183},"\u002Fdocs\u002Fkubernetes\u002Fmonitoring\u002Fbasics","1.docs\u002Fkubernetes\u002Fmonitoring\u002Fbasics",{"title":185,"path":186,"stem":187},"Components","\u002Fdocs\u002Fkubernetes\u002Fmonitoring\u002Fcomponents","1.docs\u002Fkubernetes\u002Fmonitoring\u002Fcomponents",{"title":189,"path":190,"stem":191},"Kubernetes Name Schemas","\u002Fdocs\u002Fkubernetes\u002Fname-schema","1.docs\u002Fkubernetes\u002Fname-schema",{"title":193,"icon":194,"path":195,"stem":196,"children":197,"page":22},"Networking","i-ph-network","\u002Fdocs\u002Fkubernetes\u002Fnetworking","1.docs\u002Fkubernetes\u002Fnetworking",[198,202,206],{"title":199,"path":200,"stem":201},"Benchmarking","\u002Fdocs\u002Fkubernetes\u002Fnetworking\u002Fbenchmarking","1.docs\u002Fkubernetes\u002Fnetworking\u002Fbenchmarking",{"title":203,"path":204,"stem":205},"Explained","\u002Fdocs\u002Fkubernetes\u002Fnetworking\u002Fexplained","1.docs\u002Fkubernetes\u002Fnetworking\u002Fexplained",{"title":207,"path":208,"stem":209},"Troubleshooting","\u002Fdocs\u002Fkubernetes\u002Fnetworking\u002Ftroubleshooting","1.docs\u002Fkubernetes\u002Fnetworking\u002Ftroubleshooting",{"title":211,"path":212,"stem":213},"System Requirements","\u002Fdocs\u002Fkubernetes\u002Fsystem-requirements","1.docs\u002Fkubernetes\u002Fsystem-requirements",{"title":215,"icon":216,"path":217,"stem":218,"children":219,"page":22},"Linux","i-simple-icons-linux","\u002Fdocs\u002Flinux","1.docs\u002Flinux",[220,224,246,250,268,272,275],{"title":221,"path":222,"stem":223},"git","\u002Fdocs\u002Flinux\u002Fgit","1.docs\u002Flinux\u002Fgit",{"title":225,"path":226,"stem":227,"children":228,"page":22},"GRUB","\u002Fdocs\u002Flinux\u002Fgrub","1.docs\u002Flinux\u002Fgrub",[229,242],{"title":230,"path":231,"stem":232,"children":233,"page":22},"Boot .XYZ File","\u002Fdocs\u002Flinux\u002Fgrub\u002Fbooting-xyz-files","1.docs\u002Flinux\u002Fgrub\u002Fbooting-xyz-files",[234,238],{"title":235,"path":236,"stem":237},".img File","\u002Fdocs\u002Flinux\u002Fgrub\u002Fbooting-xyz-files\u002Fimg-file","1.docs\u002Flinux\u002Fgrub\u002Fbooting-xyz-files\u002Fimg-file",{"title":239,"path":240,"stem":241},".iso File","\u002Fdocs\u002Flinux\u002Fgrub\u002Fbooting-xyz-files\u002Fiso-file","1.docs\u002Flinux\u002Fgrub\u002Fbooting-xyz-files\u002Fiso-file",{"title":243,"path":244,"stem":245},"Preparations for 'Booting XYZ FIle'","\u002Fdocs\u002Flinux\u002Fgrub\u002Fpreparations-for-boot-xyz-file","1.docs\u002Flinux\u002Fgrub\u002Fpreparations-for-boot-xyz-file",{"title":247,"path":248,"stem":249},"mdadm","\u002Fdocs\u002Flinux\u002Fmdam","1.docs\u002Flinux\u002Fmdam",{"title":251,"icon":252,"path":253,"stem":254,"children":255,"page":22},"Nixos","i-simple-icons-nixos","\u002Fdocs\u002Flinux\u002Fnixos","1.docs\u002Flinux\u002Fnixos",[256,260,264],{"title":257,"path":258,"stem":259},"Cleanup Storage","\u002Fdocs\u002Flinux\u002Fnixos\u002Fcleanup","1.docs\u002Flinux\u002Fnixos\u002Fcleanup",{"title":261,"path":262,"stem":263},"Quick NixOS VM","\u002Fdocs\u002Flinux\u002Fnixos\u002Fquick-vm","1.docs\u002Flinux\u002Fnixos\u002Fquick-vm",{"title":265,"path":266,"stem":267},"Update","\u002Fdocs\u002Flinux\u002Fnixos\u002Fupdate","1.docs\u002Flinux\u002Fnixos\u002Fupdate",{"title":269,"path":270,"stem":271},"Quick Commands","\u002Fdocs\u002Flinux\u002Fquick-commands","1.docs\u002Flinux\u002Fquick-commands",{"title":116,"path":273,"stem":274},"\u002Fdocs\u002Flinux\u002Fraspberrypi","1.docs\u002Flinux\u002Fraspberrypi",{"title":276,"path":277,"stem":278},"sysctl","\u002Fdocs\u002Flinux\u002Fsysctl","1.docs\u002Flinux\u002Fsysctl",{"title":166,"icon":167,"path":280,"stem":281,"children":282,"page":22},"\u002Fdocs\u002Flogging","1.docs\u002Flogging",[283],{"title":284,"path":285,"stem":286},"Loki","\u002Fdocs\u002Flogging\u002Floki","1.docs\u002Flogging\u002Floki",{"title":176,"icon":177,"path":288,"stem":289,"children":290,"page":22},"\u002Fdocs\u002Fmonitoring","1.docs\u002Fmonitoring",[291,322],{"title":292,"icon":293,"path":294,"stem":295,"children":296,"page":22},"Prometheus","i-simple-icons-prometheus","\u002Fdocs\u002Fmonitoring\u002Fprometheus","1.docs\u002Fmonitoring\u002Fprometheus",[297,318],{"title":298,"path":299,"stem":300,"children":301,"page":22},"Exporters","\u002Fdocs\u002Fmonitoring\u002Fprometheus\u002Fexporters","1.docs\u002Fmonitoring\u002Fprometheus\u002Fexporters",[302,306,310,314],{"title":303,"path":304,"stem":305},"dellhw_exporter by galexrt","\u002Fdocs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fdellhw_exporter","1.docs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fdellhw_exporter",{"title":307,"path":308,"stem":309},"ethtool_exporter by Showmax","\u002Fdocs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fethtool_exporter","1.docs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fethtool_exporter",{"title":311,"path":312,"stem":313},"node_exporter by Prometheus Project","\u002Fdocs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fnode_exporter","1.docs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fnode_exporter",{"title":315,"path":316,"stem":317},"Other exporters","\u002Fdocs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fothers","1.docs\u002Fmonitoring\u002Fprometheus\u002Fexporters\u002Fothers",{"title":319,"path":320,"stem":321},"Tips","\u002Fdocs\u002Fmonitoring\u002Fprometheus\u002Ftips","1.docs\u002Fmonitoring\u002Fprometheus\u002Ftips",{"title":323,"path":324,"stem":325},"Thanos","\u002Fdocs\u002Fmonitoring\u002Fthanos","1.docs\u002Fmonitoring\u002Fthanos",{"title":193,"icon":194,"path":327,"stem":328,"children":329,"page":22},"\u002Fdocs\u002Fnetworking","1.docs\u002Fnetworking",[330,347,351,363,367],{"title":331,"icon":332,"path":333,"stem":334,"children":335,"page":22},"Cisco","i-simple-icons-cisco","\u002Fdocs\u002Fnetworking\u002Fcisco","1.docs\u002Fnetworking\u002Fcisco",[336,340,343],{"title":337,"path":338,"stem":339},"ACLs","\u002Fdocs\u002Fnetworking\u002Fcisco\u002Facls","1.docs\u002Fnetworking\u002Fcisco\u002Facls",{"title":40,"path":341,"stem":342},"\u002Fdocs\u002Fnetworking\u002Fcisco\u002Fcheat-sheet","1.docs\u002Fnetworking\u002Fcisco\u002Fcheat-sheet",{"title":344,"path":345,"stem":346},"Switch Configuration","\u002Fdocs\u002Fnetworking\u002Fcisco\u002Fswitch-configuration","1.docs\u002Fnetworking\u002Fcisco\u002Fswitch-configuration",{"title":348,"path":349,"stem":350},"Cloudflare","\u002Fdocs\u002Fnetworking\u002Fcloudflare","1.docs\u002Fnetworking\u002Fcloudflare",{"title":352,"path":353,"stem":354,"children":355,"page":22},"Fiber","\u002Fdocs\u002Fnetworking\u002Ffiber","1.docs\u002Fnetworking\u002Ffiber",[356,359],{"title":40,"path":357,"stem":358},"\u002Fdocs\u002Fnetworking\u002Ffiber\u002Fcheat-sheet","1.docs\u002Fnetworking\u002Ffiber\u002Fcheat-sheet",{"title":360,"path":361,"stem":362},"Glossar","\u002Fdocs\u002Fnetworking\u002Ffiber\u002Fglossar","1.docs\u002Fnetworking\u002Ffiber\u002Fglossar",{"title":364,"path":365,"stem":366},"IP-Blocklists","\u002Fdocs\u002Fnetworking\u002Fip-blocklists","1.docs\u002Fnetworking\u002Fip-blocklists",{"title":368,"icon":369,"path":370,"stem":371,"children":372,"page":22},"Mikrotik","i-simple-icons-mikrotik","\u002Fdocs\u002Fnetworking\u002Fmikrotik","1.docs\u002Fnetworking\u002Fmikrotik",[373,376,390],{"title":40,"path":374,"stem":375},"\u002Fdocs\u002Fnetworking\u002Fmikrotik\u002Fcheat-sheet","1.docs\u002Fnetworking\u002Fmikrotik\u002Fcheat-sheet",{"title":377,"icon":378,"path":379,"stem":380,"children":381,"page":22},"DNS","i-mdi-dns","\u002Fdocs\u002Fnetworking\u002Fmikrotik\u002Fdns","1.docs\u002Fnetworking\u002Fmikrotik\u002Fdns",[382,386],{"title":383,"path":384,"stem":385},"Adlists \u002F Blocklists","\u002Fdocs\u002Fnetworking\u002Fmikrotik\u002Fdns\u002Fadlists-blocklists","1.docs\u002Fnetworking\u002Fmikrotik\u002Fdns\u002Fadlists-blocklists",{"title":387,"path":388,"stem":389},"DNS over HTTPS (DOH)","\u002Fdocs\u002Fnetworking\u002Fmikrotik\u002Fdns\u002Fdns-over-https-doh","1.docs\u002Fnetworking\u002Fmikrotik\u002Fdns\u002Fdns-over-https-doh",{"title":391,"path":392,"stem":393},"Example Configs","\u002Fdocs\u002Fnetworking\u002Fmikrotik\u002Fexample-configs","1.docs\u002Fnetworking\u002Fmikrotik\u002Fexample-configs",{"title":395,"icon":396,"path":397,"stem":398,"children":399,"page":22},"Software","i-ph-file-code","\u002Fdocs\u002Fsoftware","1.docs\u002Fsoftware",[400,404,408,412,416],{"title":401,"path":402,"stem":403},"CRI-O","\u002Fdocs\u002Fsoftware\u002Fcrio","1.docs\u002Fsoftware\u002Fcrio",{"title":405,"path":406,"stem":407},"Docker Registry","\u002Fdocs\u002Fsoftware\u002Fdocker-registry","1.docs\u002Fsoftware\u002Fdocker-registry",{"title":409,"path":410,"stem":411},"GitLab CI","\u002Fdocs\u002Fsoftware\u002Fgitlab-ci","1.docs\u002Fsoftware\u002Fgitlab-ci",{"title":413,"path":414,"stem":415},"Harbor Registry","\u002Fdocs\u002Fsoftware\u002Fharbor-registry","1.docs\u002Fsoftware\u002Fharbor-registry",{"title":417,"path":418,"stem":419},"SSH","\u002Fdocs\u002Fsoftware\u002Fssh","1.docs\u002Fsoftware\u002Fssh",{"title":421,"icon":422,"path":423,"stem":424,"children":425,"page":22},"Storage","i-ph-hard-drives","\u002Fdocs\u002Fstorage","1.docs\u002Fstorage",[426,448,456,464],{"title":427,"icon":428,"path":429,"stem":430,"children":431,"page":22},"Ceph","i-simple-icons-ceph","\u002Fdocs\u002Fstorage\u002Fceph","1.docs\u002Fstorage\u002Fceph",[432,436,440,444],{"title":433,"path":434,"stem":435},"Architecture","\u002Fdocs\u002Fstorage\u002Fceph\u002Farchitecture","1.docs\u002Fstorage\u002Fceph\u002Farchitecture",{"title":437,"path":438,"stem":439},"Common Issues","\u002Fdocs\u002Fstorage\u002Fceph\u002Fcommon-issues","1.docs\u002Fstorage\u002Fceph\u002Fcommon-issues",{"title":441,"path":442,"stem":443},"OSDs","\u002Fdocs\u002Fstorage\u002Fceph\u002Fosds","1.docs\u002Fstorage\u002Fceph\u002Fosds",{"title":445,"path":446,"stem":447},"RBD (Block Storage)","\u002Fdocs\u002Fstorage\u002Fceph\u002Frbd","1.docs\u002Fstorage\u002Fceph\u002Frbd",{"title":449,"path":450,"stem":451,"children":452,"page":22},"Gluster","\u002Fdocs\u002Fstorage\u002Fgluster","1.docs\u002Fstorage\u002Fgluster",[453],{"title":437,"path":454,"stem":455},"\u002Fdocs\u002Fstorage\u002Fgluster\u002Fcommon-issues","1.docs\u002Fstorage\u002Fgluster\u002Fcommon-issues",{"title":457,"path":458,"stem":459,"children":460,"page":22},"NFS","\u002Fdocs\u002Fstorage\u002Fnfs","1.docs\u002Fstorage\u002Fnfs",[461],{"title":437,"path":462,"stem":463},"\u002Fdocs\u002Fstorage\u002Fnfs\u002Fcommon-issues","1.docs\u002Fstorage\u002Fnfs\u002Fcommon-issues",{"title":465,"icon":466,"path":467,"stem":468,"children":469,"page":22},"Rook","i-simple-icons-rook","\u002Fdocs\u002Fstorage\u002Frook","1.docs\u002Fstorage\u002Frook",[470,473,476,479],{"title":433,"path":471,"stem":472},"\u002Fdocs\u002Fstorage\u002Frook\u002Farchitecture","1.docs\u002Fstorage\u002Frook\u002Farchitecture",{"title":40,"path":474,"stem":475},"\u002Fdocs\u002Fstorage\u002Frook\u002Fcheat-sheet","1.docs\u002Fstorage\u002Frook\u002Fcheat-sheet",{"title":465,"path":477,"stem":478},"\u002Fdocs\u002Fstorage\u002Frook\u002Fcluster","1.docs\u002Fstorage\u002Frook\u002Fcluster",{"title":437,"path":480,"stem":481},"\u002Fdocs\u002Fstorage\u002Frook\u002Fcommon-issues","1.docs\u002Fstorage\u002Frook\u002Fcommon-issues",{"title":483,"icon":484,"path":485,"stem":486,"children":487,"page":22},"Web","i-ph-browser","\u002Fdocs\u002Fweb","1.docs\u002Fweb",[488,498],{"title":489,"icon":490,"path":491,"stem":492,"children":493,"page":22},"Nuxt","i-simple-icons-nuxt","\u002Fdocs\u002Fweb\u002Fnuxt","1.docs\u002Fweb\u002Fnuxt",[494],{"title":495,"path":496,"stem":497},"Loading Indicator","\u002Fdocs\u002Fweb\u002Fnuxt\u002Floading-indicator","1.docs\u002Fweb\u002Fnuxt\u002Floading-indicator",{"title":499,"icon":500,"path":501,"stem":502,"children":503,"page":22},"Tiptap","i-mdi-file-edit-outline","\u002Fdocs\u002Fweb\u002Ftiptap","1.docs\u002Fweb\u002Ftiptap",[504],{"title":505,"path":506,"stem":507},"Snippets","\u002Fdocs\u002Fweb\u002Ftiptap\u002Fsnippets","1.docs\u002Fweb\u002Ftiptap\u002Fsnippets",{"id":509,"title":510,"authors":511,"badge":517,"body":518,"date":1474,"description":1475,"extension":1476,"image":1477,"meta":1478,"navigation":1479,"path":1480,"seo":1481,"stem":1482,"__hash__":1483},"posts\u002F3.blog\u002F2026\u002Fcontainer-days-hamburg-2026.md","ContainerDays Hamburg 2026",[512],{"name":513,"to":514,"avatar":515},"Alexander Trost","https:\u002F\u002Fgithub.com\u002Fgalexrt",{"src":516},"\u002Fimages\u002Fprofile-picture.webp",null,{"type":519,"value":520,"toc":1451},"minimark",[521,525,528,531,534,539,544,555,562,571,574,580,583,589,592,595,598,601,604,607,610,614,620,629,638,646,658,661,664,667,670,683,689,692,701,704,710,719,722,730,737,746,749,763,769,775,778,781,787,790,818,824,827,833,844,847,857,860,863,867,873,876,883,892,895,901,904,907,910,913,916,930,933,936,938,942,946,949,959,962,965,971,974,977,984,988,991,1002,1008,1021,1037,1043,1056,1082,1093,1099,1125,1141,1147,1150,1156,1170,1174,1177,1183,1186,1189,1192,1198,1207,1211,1214,1220,1223,1229,1232,1235,1237,1241,1245,1248,1251,1259,1262,1268,1271,1277,1280,1283,1289,1297,1300,1306,1309,1312,1315,1318,1324,1327,1330,1333,1337,1348,1351,1354,1360,1363,1366,1372,1392,1398,1406,1412,1418,1421,1423,1427,1430,1445],[522,523,524],"p",{},"Finally, I am attending ContainerDays again after a few years of not being able to attend because of planning issues.\nThis year the event was held in the harbor area again, to be exact at \"Schuppen 52\" instead of the previous year's \"Kampnagel\" location, which was closer in the city.",[522,526,527],{},"It almost feels like going back to the roots of the event, with \"Schuppen 52\" being quite close to the \"Hafenmuseum\", but \"we\", the attendees, have simply outgrown the \"Hafenmuseum\" and \"Kampnagel\" locations.\nAs a side note, my first ContainerDays was in 2018 at the \"Hafenmuseum\", different times and different jobs, but the same event and same great community.",[522,529,530],{},"Now let's dive into the talks. As we haven't mastered the art of cloning ourselves yet, I was obviously not able to attend all of them, but I hope that my selection of talks will at least provide you with some new knowledge.",[532,533],"hr",{},[535,536,538],"h2",{"id":537},"day-1","Day 1",[540,541,543],"h3",{"id":542},"sovereign-by-design-open-by-default-christian-hüning-niklas-voss","Sovereign by Design, Open by Default - Christian Hüning, Niklas Voss",[522,545,546,547,554],{},"The talk was about the relationship between digital sovereignty and open source. These two ideas are sometimes treated as opposites: sovereignty sounds like building something closed and controlled, while open source implies that everyone can inspect and use the result.\nTheir point was that openness can actually help build sovereignty. Open standards, interoperable components, and transparent supply chains make it easier to retain control over the infrastructure instead of depending on a single vendor.\nThe talk was presented in the context of the ",[548,549,553],"a",{"href":550,"rel":551},"https:\u002F\u002Fneonephos.org\u002F",[552],"nofollow","NeoNephos Foundation",", a vendor-neutral foundation supporting an open, sovereign cloud-native ecosystem.",[522,556,557],{},[558,559],"img",{"alt":560,"src":561},"CDS2026 - Sovereign by Design, Open by Default - Christian talking","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sovereign-by-design-1.webp",[522,563,564,565,570],{},"The infrastructure itself also needs to be part of this story. Using ",[548,566,569],{"href":567,"rel":568},"https:\u002F\u002Fmetal3.io\u002F",[552],"Metal³"," components, the hardware and network for Kubernetes clusters can be provisioned and managed through open, Kubernetes-native APIs.",[522,572,573],{},"This kind of sovereignty is particularly important for defence contracts and other public-sector workloads. It is not only about where a workload runs. It is also about who can operate the infrastructure, which jurisdiction applies, and whether the systems can still be used independently years later.",[522,575,576],{},[558,577],{"alt":578,"src":579},"CDS2026 - Sovereign by Design, Open by Default - Niklas talking","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sovereign-by-design-2.webp",[522,581,582],{},"Talos Linux is used as the operating system for the Kubernetes nodes, which made me smile. An immutable, API-driven operating system fits nicely with the goal of managing the whole infrastructure in a predictable and declarative way.",[522,584,585],{},[558,586],{"alt":587,"src":588},"CDS2026 - Sovereign by Design, Open by Default - KCP Workspace Architecture: Isolating & API Binding","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sovereign-by-design-3.webp",[522,590,591],{},"The presentation also showed the kcp workspace architecture. As I understood it, a cluster-or more precisely, its control planes-is treated as one single namespace. APIs and resources can then be isolated and selectively exposed through workspaces instead of making everything available everywhere.",[522,593,594],{},"One comparison from the talk stuck with me: permissions should be requested more like popups on smartphones. Access should be explicit and understandable, rather than silently granting every user or component more permissions than it needs.",[522,596,597],{},"This also connects to compliance enforcement and supply-chain security. Policies need to ensure that systems are configured safely, while the software supply chain needs to give us confidence that the software itself is safe and has not been tampered with.",[522,599,600],{},"Air-gapped environments make these requirements especially visible and painful. If an environment is completely offline, you can't just download a container image or package when it is needed. Everything has to be bundled, verified, and transferred into the environment in advance.",[522,602,603],{},"Using OCI as a common format helps with this process. The artifacts can be transported as files on physical media-so, as the talk joked, they could even be carried on a USB stick by a pigeon.\nThe Open Component Model (OCM) is a specification for describing and distributing software components in an OCI-compatible way. It can be used to define the dependencies of a workload,\nincluding the exact versions of container images, configuration files, and other artifacts.",[522,605,606],{},"The phrase “public money, public code” was another important part of the talk. BWI is owned by the German government, so the argument is that publicly funded work should also create reusable value for the public.\nThe goal is not to create a foundation exclusively for the defence industry, but to contribute to an open ecosystem that can be used by everyone.",[522,608,609],{},"For me, the main takeaway was that sovereignty does not necessarily mean building a closed alternative. It is about retaining meaningful choices: where infrastructure runs, who can operate it, how software is verified, and whether the components remain usable by others.",[540,611,613],{"id":612},"from-frankenstein-to-kamaji-lessons-in-building-a-single-capi-cluster-across-multiple-providers-xavier-avrillier-antonia-von-den-driesch","From Frankenstein to Kamaji: Lessons in Building a Single CAPI Cluster Across Multiple Providers - Xavier Avrillier, Antonia von den Driesch",[522,615,616],{},[558,617],{"alt":618,"src":619},"CDS2026 - From Frankenstein to Kamaji: Lessons in Building a Single CAPI Cluster Across Multiple Providers - Presenters talking","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-frankenstein-to-kamaji-1.webp",[522,621,622,623,628],{},"Before starting with the talk, a quick clarification on an abbreviation used: \"CAPI\" stands for ",[548,624,627],{"href":625,"rel":626},"https:\u002F\u002Fcluster-api.sigs.k8s.io\u002F",[552],"Cluster API of Kubernetes",".",[522,630,631,632,637],{},"When creating and managing clusters with CAPI, ",[548,633,636],{"href":634,"rel":635},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Fconcepts\u002Foverview\u002Fworking-with-objects\u002Fowners-dependents\u002F",[552],"owner references"," come in clutch for cleanup and knowing which cluster owns which resources. In general, owner references and finalizers are a good way to manage resources in Kubernetes.\nTo increase the resilience of Kubernetes clusters, you might want to \"stretch\" a cluster across multiple providers, e.g., AWS and Azure. While \"hybrid clusters\" are possible in themselves, CAPI tooling might not fully support them.",[522,639,640,641,645],{},"By making the \"management cluster\" a \"hybrid\" cluster-or at least \"connected\" to both providers, vSphere and Proxmox-they can \"easily\" manage clusters with nodes across both providers, but it feels like ",[642,643,644],"strong",{},"Frankenstein",".\n(Disclaimer from the talk: Obviously, this is not supported by GiantSwarm upstream products.)",[522,647,648,649,657],{},"As mentioned before, some tooling around CAPI might not work as expected when using multiple providers. For example, ",[548,650,653],{"href":651,"rel":652},"https:\u002F\u002Fcluster-api.sigs.k8s.io\u002Fclusterctl\u002Foverview",[552],[654,655,656],"code",{},"clusterctl"," can have issues connecting to control planes or machines in different providers. From my experience and what I saw, this feels more like a \"network segmentation\" issue than a tooling issue.",[522,659,660],{},"Their demo showed a brand-new CAPI cluster with nodes from both providers, vSphere and Proxmox. After a few seconds, the Proxmox nodes disappeared because the vSphere Cloud Controller Manager (CCM) was not aware of them.\nBut what does \"CCM is not aware\" mean here? The CCMs are responsible for managing the lifecycle of nodes in a Kubernetes cluster, including provisioning, scaling, and deleting nodes. So, when a node is created, most CCMs will \"check\" whether the node is \"known\" to the CCM. If it is not, the node will be deleted from the cluster.\nDepending on how you see this, you could consider it a \"safety\" mechanism to prevent \"unknown\" nodes from being part of the cluster.\nBut in the case of a \"hybrid\" cluster, a CCM that deletes nodes from a different provider is not really what you want.",[522,662,663],{},"I personally ran into that situation on Hetzner Cloud (HCloud), where the HCloud CCM would delete \"unknown\" nodes, e.g., dedicated servers. To the credit of the HCloud CCM maintainers, they added a label\u002Fconfig option to prevent such nodes from being deleted from the Kubernetes cluster when they were considered \"unknown\".\nNowadays, the HCloud CCM even has some integration for dedicated servers, but at the time, adding or setting labels was the \"safe\" way to ensure the CCM did not remove the node from Kubernetes and break the cluster.",[522,665,666],{},"They built a custom vSphere CCM that ignores nodes with a certain name prefix. That \"works\", but labels feel \"better\" for this use case. Based on that, I think it would be good to add \"label exclusion\" of nodes as a feature to the \"So you wanna build a CCM?\" guidelines.\nKeep that in mind when you wanna build hybrid clusters with multiple CCMs. You might run into issues with a CCM deleting nodes from another provider because it is not aware of them.\nAdditionally, what I currently consider a \"Kubernetes limitation\" is that you are not really expected to run multiple CCMs in a single cluster. You can only specify one \"main\" CCM in the Kubernetes Controller Manager.",[522,668,669],{},"So, to summarize, most CCMs are not designed to work across multiple providers. This is a \"limitation\" of the current CAPI ecosystem. If you wanna run a hybrid cluster across multiple providers, you might run into issues with CCMs deleting nodes from the cluster that they are not aware of.",[522,671,672,673,678,679,682],{},"To circle back to the project, they showed ",[548,674,677],{"href":675,"rel":676},"https:\u002F\u002Fkamaji.clastix.io\u002F",[552],"Kamaji"," for running hosted control planes. Running control planes as \"normal\" Pods in a management cluster can help reduce the resource overhead of managing multiple clusters.\nUsing such a \"hosted control plane\" for a cluster makes the control plane nodes \"disappear\" from the ",[654,680,681],{},"kubectl get nodes"," output. Since you don't have to take care of the control plane nodes directly, this can make managing a cluster easier or harder, depending on the situation.",[522,684,685],{},[558,686],{"alt":687,"src":688},"CDS2026 - From Frankenstein to Kamaji: Lessons in Building a Single CAPI Cluster Across Multiple Providers - Customer: \"I need bare metal nodes\"","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-frankenstein-to-kamaji-2.webp",[522,690,691],{},"Chef's kiss for the meme about the customer not wanting to waste \"expensive\" resources on control plane nodes. :-D",[540,693,695,696,700],{"id":694},"so-i-generated-over-3000-10000-sboms-for-the-cncf-ecosystem-mario-fahlandt","So I generated over ",[697,698,699],"del",{},"3000"," 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt",[522,702,703],{},"(I have taken the liberty of using the \"updated\" title from Mario's presentation.)",[522,705,706],{},[558,707],{"alt":708,"src":709},"CDS2026 - So I generated over 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt - SBOM in 60 seconds","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sboms-1.webp",[522,711,712,713,718],{},"The ",[548,714,717],{"href":715,"rel":716},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcyber-resilience-act",[552],"EU's \"Cyber Resilience Act\""," is one of the things pushing software transparency forward.\nThe goal is that you should be able to get an SBOM for something like the new AI smart oven in your kitchen and know what software it is actually running.",[522,720,721],{},"The CNCF started a project to generate SBOMs for its projects, mainly to find out whether the licenses of the libraries and other software components are compatible.",[522,723,724,729],{},[548,725,728],{"href":726,"rel":727},"https:\u002F\u002Fspdx.github.io\u002Fspdx-spec\u002Fv2.3\u002F",[552],"SPDX 2.3"," seems to be the standard they are using for SBOM generation, though a quick search reveals there are different formats.",[522,731,732,733,736],{},"Their first, \"basic\" way of generating SBOMs was quite limited. The dependencies that are part of the build process are not only ",[654,734,735],{},"devDependencies",". GitHub Actions, container images, and other tools used to build and publish the software are also part of the software supply chain and should be included in the SBOMs.",[522,738,739,740,745],{},"They use ",[548,741,744],{"href":742,"rel":743},"https:\u002F\u002Fgithub.com\u002Fkusari-oss\u002Fwaybill",[552],"Waybill"," to generate the SBOMs. From the talk, it sounds like it works well for projects that use multiple languages, for example JavaScript and Golang.",[522,747,748],{},"Using GitHub Actions at this scale also caused some issues. For example, there were page-loading errors with so many tasks and artifacts.",[522,750,712,751,756,757,762],{},[548,752,755],{"href":753,"rel":754},"https:\u002F\u002Fgithub.com\u002Fseebom-labs\u002FBOMHort",[552],"BOMHort project"," is an ",[548,758,761],{"href":759,"rel":760},"https:\u002F\u002Fopenssf.org\u002F",[552],"OpenSSF sandbox project",". The name comes from the German word \"Hort\", which can mean a place where treasures are kept-or, in this case, where dragons hoard their riches.",[522,764,765],{},[558,766],{"alt":767,"src":768},"CDS2026 - So I generated over 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt - BOMHort project and logo","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sboms-2.webp",[522,770,771],{},[558,772],{"alt":773,"src":774},"CDS2026 - So I generated over 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt - What BOMHort does","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sboms-3.webp",[522,776,777],{},"They are working on fixing some of the limitations around licenses in SBOMs. For example, someone could accidentally modify a license and end up with \"Mario's Apache license\", which might not really be an Apache License anymore.",[522,779,780],{},"The architecture of BOMHort looks like this:",[522,782,783],{},[558,784],{"alt":785,"src":786},"CDS2026 - So I generated over 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt - BOMHort architecture","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sboms-4.webp",[522,788,789],{},"From the 10000+ SBOMs they analyzed, these were some of the findings:",[791,792,793,808,815],"ul",{},[794,795,796,799,800,803,804,807],"li",{},[654,797,798],{},"NOASSERTION"," - No license was ",[642,801,802],{},"identified",", or there was ",[642,805,806],{},"uncertainty"," about the license or other properties of the project or its dependencies.",[794,809,810,811,814],{},"\"Unresolvable Dependencies\" - Dependencies could ",[642,812,813],{},"not be resolved",", for example because repositories had been removed.",[794,816,817],{},"Licensing - Not every CNCF project makes sure that the correct licenses are specified and used by its dependencies.",[522,819,820],{},[558,821],{"alt":822,"src":823},"CDS2026 - So I generated over 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt - The toolchain","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sboms-5.webp",[522,825,826],{},"Generating SBOMs after the build is not optimal. Generating them during the build is better, and signing and enriching them is the cherry on top.",[522,828,829],{},[558,830],{"alt":831,"src":832},"CDS2026 - So I generated over 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt - Five steps","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-sboms-6.webp",[522,834,835,836,840,841,628],{},"\"Everything, all in one place\"-check out these resources: ",[548,837,838],{"href":838,"rel":839},"https:\u002F\u002Fcncf.io\u002Fsecurity",[552]," and ",[548,842,759],{"href":759,"rel":843},[552],[522,845,846],{},"Hopefully, the \"Cyber Resilience Act\" causes companies to put more money into actual open source maintenance, instead of \"just opening an issue\" in the repository and \"calling it a job well done.\"",[522,848,849,852,853,856],{},[642,850,851],{},"In my opinion:"," Maintainers being paid for fixing issues and\u002For maintaining the software would be a nice change, but there is more to it than that.\nIf you take a project as \"basic\" but important as ",[654,854,855],{},"curl",", it is critical that development of such a library continues no matter what.\nAs things get more expensive, people will have less \"free time\" to put into open source libraries and projects.\nI think the old saying that \"time is money\" is simply at play here and is a factor for motivation.",[522,858,859],{},"You can call me greedy, but if some of my \"slightly\" more \"popular\" open source projects brought in a \"few bucks\"-not hundreds of euros, just a few euros as motivation to keep working on and improving them, that would be nice.\nIt would also help \"everyone\" using the project for their own or their company's infrastructure.",[522,861,862],{},"It will be quite interesting to see what companies will do when this goes into effect.",[540,864,866],{"id":865},"one-platform-could-not-fit-them-all-artem-lajko-annika-opitz","One Platform Could Not Fit Them All - Artem Lajko, Annika Opitz",[522,868,869],{},[558,870],{"alt":871,"src":872},"CDS2026 - One Platform Could Not Fit Them All - Artem Lajko, Annika Opitz - Terminology","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-one-platform-1.webp",[522,874,875],{},"Every team builds its own platform. A central platform team will have to work with teams that have very different levels of knowledge and experience.\nA central platform team should mostly be about knowledge sharing and helping teams.\nEven with a central approach\u002Fteam, there are still \"hard decisions\" to make. The CNCF Landscape is huge, and not every tool is the right one for every team.\n\"Do you work to buy tools or do you work to use them?\"",[522,877,878,879,882],{},"Reports show that even after spending \"millions\" on internal developer platforms, most teams (64%) still run ",[654,880,881],{},"kubectl"," directly to do things on the \"platform\". So the \"platform\" is being \"bypassed\".",[522,884,885,886,891],{},"This is where ",[548,887,890],{"href":888,"rel":889},"https:\u002F\u002Fkubara.io\u002F",[552],"Kubara"," comes in. It packages and distributes \"modules\" or \"apps\" for teams to use.",[522,893,894],{},"They use a \"HUB\" cluster for the common tools and \"Spoke\" clusters for the actual workloads.\nIf you compare it to other solutions, a \"HUB\" cluster is basically a management cluster for the \"Spoke\" clusters.",[522,896,897],{},[558,898],{"alt":899,"src":900},"CDS2026 - One Platform Could Not Fit Them All - Artem Lajko, Annika Opitz - 2. Add Spoke Clusters. Distribute Workload.","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-one-platform-2.webp",[522,902,903],{},"Argo CD, GitOps, Helm, and Kustomize are used heavily for this approach.\nAdding the \"Spokes\" also configures Argo CD for them, so they can then be managed centrally.",[522,905,906],{},"The (real) challenge is updating more than 15,000 clusters.",[522,908,909],{},"Managing that many clusters and their applications needs a different architecture.\nSveltos is used to manage more clusters, simply as a \"wrapped application\" in Kubara.",[522,911,912],{},"In a load test, Sveltos used a lot less memory and CPU than Argo CD. Sadly, I didn't get a chance to take a screenshot. Make sure to check the recordings.",[522,914,915],{},"Moving from \"inner source\" to open source is a challenge:",[791,917,918,921,924,927],{},[794,919,920],{},"Documentation needs to be written for people who are not part of the \"inner\" circle.",[794,922,923],{},"Legal and trademarks: who pays for them in the company?",[794,925,926],{},"Marketing and promotion.",[794,928,929],{},"A catchy logo or icon.",[522,931,932],{},"There is also a project Slack, and community meetings are hosted regularly. If you want to learn more, be sure to check out the documentation and join the Kubara community.",[522,934,935],{},"(They are not tied to a specific Kubernetes cluster provider. You \"just need a kubeconfig\" to get started, although a provider that offers Cluster API would be recommended\u002Fneeded.)",[532,937],{},[535,939,941],{"id":940},"day-2","Day 2",[540,943,945],{"id":944},"building-production-ready-kubernetes-operators-fortune-ndlovu","Building Production-Ready Kubernetes Operators - Fortune Ndlovu",[522,947,948],{},"Operators let us extend the Kubernetes API and package deployment and operational knowledge into it.\nHelm \"only\" handles some of the steps involved in running an application, such as installing and \"upgrading\" it.\nTools like Ansible can go further and manage the whole application lifecycle. Operators can do something similar, but in the native Kubernetes way.",[522,950,951,952,840,955,958],{},"Configuration has several layers, e.g., \"defaults\" from the operator, options from the CustomResource, and additional overrides that a user can provide via ConfigMaps\u002FSecrets, etc.\nTo give a concrete example, the \"defaults\" from an operator could be very specific. With older Java versions, we had to add ",[654,953,954],{},"-Xms",[654,956,957],{},"-Xmx"," to set the JVM memory limits, while \"newer\" versions could \"read\" the container information instead of \"confusing\" it with the host's resources.\nThis means that if an operator deploys a Java application as a container, it would need to use \"other defaults\" for the application to run smoothly.",[522,960,961],{},"An operator would need to ensure that the application is running and healthy, which is the operational part of running an application.\nOne thing that can easily be overlooked is the operator \"informing\" the application or its deployments about configuration changes.\nOne way to do this is by using a \"config hash\", which causes Kubernetes to \"auto-restart\" the necessary resources when the configuration changes.",[522,963,964],{},"They call these customized operators \"Flavours\", depending on the customer or use case.",[522,966,967],{},[558,968],{"alt":969,"src":970},"CDS2026 - Building Production-Ready Kubernetes Operators - Fortune Ndlovu - How a flavour extends RHDH","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-operators-1.webp",[522,972,973],{},"They seemingly allow ConfigMaps to be referenced but also included in a CustomResource. If that is how they are doing it, it can make deploying the application easier, as \"everything\" would be contained in the one YAML file for the CR.",[522,975,976],{},"In the demo, they used a \"custom\" operator to deploy Backstage. The deployed Backstage instance also included the Lightspeed chatbot, but the chatbot was not working at first.\nThe initially applied custom resources were missing secrets for, e.g., accessing the AI model. After updating the Custom Resource with the ConfigMaps and Secrets, the operator reconciled the application and the chatbot started working.",[522,978,979,980],{},"Repository URL: ",[548,981,982],{"href":982,"rel":983},"https:\u002F\u002Fgithub.com\u002Fredhat-developer\u002Frhdh-operator",[552],[540,985,987],{"id":986},"kubernetes-rbac-at-scale-without-losing-your-sanity-kevin-gimbel","Kubernetes RBAC at scale without losing your sanity - Kevin Gimbel",[522,989,990],{},"RBAC (Role-Based Access Control), quickly summarized, gives access based on roles. There is no \"denying\" access, only granting access.",[522,992,993,994,997,998,1001],{},"Since Kubernetes 1.8 was released in December 2018, RBAC has been the default authorization mode in Kubernetes. So, we have been using RBAC in Kubernetes for quite a long time, but it is still something you can easily get wrong.\nWhile ",[654,995,996],{},"aggregationRule"," has been part of ",[654,999,1000],{},"ClusterRole"," since Kubernetes 1.6 (July 2017), not everyone might be aware of it. The talk highlights the feature and how it can be used to make RBAC easier to manage at scale.",[522,1003,1004],{},[558,1005],{"alt":1006,"src":1007},"CDS2026 - Kubernetes RBAC at scale without losing your sanity - Kevin Gimbel - How does RBAC look in Kubernetes?","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-rbac-1.webp",[522,1009,1010,1011,1013,1014,1016,1017,1020],{},"To start off, ",[654,1012,996],{}," is already a standard ",[654,1015,1000],{}," feature in Kubernetes. You do not need an additional operator or any flags on your ",[654,1018,1019],{},"kube-apiserver"," and friends.\nIt allows you to, you guessed it, aggregate roles into other \"bigger\" roles based on label selectors.",[522,1022,1023,1024,1026,1027,1030,1031,1033,1034,628],{},"The example below would aggregate ",[654,1025,1000],{},"s with the label ",[654,1028,1029],{},"rbac.authorization.k8s.io\u002Faggregate-to-developer=true"," into the ",[654,1032,1000],{}," named ",[654,1035,1036],{},"developer",[522,1038,1039],{},[558,1040],{"alt":1041,"src":1042},"CDS2026 - Kubernetes RBAC at scale without losing your sanity - Kevin Gimbel - Kubernetes ClusterRole aggregrationRule YAML example","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-rbac-2.webp",[1044,1045,1046],"note",{},[522,1047,1048,1049,1052,1053,1055],{},"The indentation of the label in the ",[654,1050,1051],{},"matchLabels:"," block in the ",[654,1054,996],{}," in the picture is not correct, but you get the idea.",[522,1057,1058,1059,1061,1062,1067,1068,1070,1071,1074,1075,1074,1078,1081],{},"Using ",[654,1060,996],{}," can make it easy to grant access to, e.g., new CRDs. Some operators I know, e.g., ",[548,1063,1066],{"href":1064,"rel":1065},"https:\u002F\u002Fgithub.com\u002Fprometheus-operator\u002Fprometheus-operator",[552],"prometheus-operator",", come with ",[654,1069,1000],{},"s for the \"default\" Kubernetes RBAC roles (e.g., ",[654,1072,1073],{},"admin",", ",[654,1076,1077],{},"edit",[654,1079,1080],{},"view",") to easily allow users of the cluster to use the operator's CRDs.",[522,1083,1084,1085,1088,1089,1092],{},"OpenID Connect (OIDC) provides the \"users\" on the fly, as Kubernetes does not \"store\" information about users and groups directly. The login token contains the user information, e.g., name and groups\u002Froles.\nThis information can then be used in ",[654,1086,1087],{},"ClusterRoleBinding","s and ",[654,1090,1091],{},"RoleBinding","s to grant access to users and\u002For the groups they are part of.\nThe login token is basically a JWT (JSON Web Token):",[522,1094,1095],{},[558,1096],{"alt":1097,"src":1098},"CDS2026 - Kubernetes RBAC at scale without losing your sanity - Kevin Gimbel - OIDC Login Flow","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-rbac-3.webp",[522,1100,1101,1102,1105,1106,1108,1109,1121,1122,1124],{},"In the past, OIDC could only be configured using ",[654,1103,1104],{},"--oidc-*"," flags on the ",[654,1107,1019],{},". In more recent Kubernetes releases, it can be configured using the ",[548,1110,1113,1116,1117,1120],{"href":1111,"rel":1112},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Freference\u002Faccess-authn-authz\u002Fauthentication\u002F#api-server-authn-config-file",[552],[654,1114,1115],{},"AuthenticationConfiguration"," API resource (",[654,1118,1119],{},"apiserver.config.k8s.io\u002Fv1",")",".\nThis makes the process a bit more streamlined, as it is just another YAML file to place next to the ",[654,1123,1019],{}," configuration.",[522,1126,1127,1128,1131,1132,1137,1138,1140],{},"One thing that is still annoying with OIDC login is that you need to create a ",[654,1129,1130],{},"kubeconfig"," file for the user to use, which contains the OIDC \"plugin\" configuration for the OIDC login, e.g., ",[548,1133,1136],{"href":1134,"rel":1135},"https:\u002F\u002Fgithub.com\u002Fint128\u002Fkubelogin",[552],"kubelogin by int128",".\nSo the user might even need to install additional software besides ",[654,1139,881],{}," just to log in to the Kubernetes cluster.",[522,1142,1143],{},[558,1144],{"alt":1145,"src":1146},"CDS2026 - Kubernetes RBAC at scale without losing your sanity - Kevin Gimbel - kubeconfig YAML example for OIDC login","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-rbac-4.webp",[522,1148,1149],{},"Thanks for the recap slide, Kevin Gimbel! Makes it easier to remember the key points of the talk.",[522,1151,1152],{},[558,1153],{"alt":1154,"src":1155},"CDS2026 - Kubernetes RBAC at scale without losing your sanity - Kevin Gimbel - Recap","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-rbac-5.webp",[522,1157,1158,1159,1164,1165,628],{},"For more information about RBAC in Kubernetes, check out the ",[548,1160,1163],{"href":1161,"rel":1162},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Freference\u002Faccess-authn-authz\u002Frbac\u002F",[552],"Kubernetes RBAC documentation"," and for more information on authentication, check out the ",[548,1166,1169],{"href":1167,"rel":1168},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Freference\u002Faccess-authn-authz\u002Fauthentication\u002F",[552],"Kubernetes Authentication documentation",[540,1171,1173],{"id":1172},"bootable-containers-an-entire-os-as-a-containerfile-robert-guske","Bootable Containers: An entire OS as a Containerfile - Robert Guske",[522,1175,1176],{},"I haven't been able to attend the whole talk, but I took a few important points for implementing a \"fully containerized RHEL OS\" approach away from it.",[522,1178,1179],{},[558,1180],{"alt":1181,"src":1182},"CDS2026 - Bootable Containers: An entire OS as a Containerfile - Robert Guske - An opinionated way of deploying, configuring, and managing immutable image-based Linux systems","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-bootable-containers-1.webp",[522,1184,1185],{},"While it feels a bit weird to \"install\" a \"container\" image as an OS, it is still a very interesting way to manage Linux systems. Especially if you think about Flatcar Linux, Talos Linux, and similar systems, which are already somewhat \"containerized\" OSes.\nSo, this approach is already being used for quite a few Kubernetes clusters and basically all OpenShift 4 clusters.",[522,1187,1188],{},"Being able to \"configure\" your OS via a \"Containerfile\" could make things easier. You could \"just\" build a new image with the updated configuration and deploy it to your systems.\nTo update it, you simply build a new image with the updated configuration and deploy it to your systems. \"All you need\" is an image registry to store the images.\nFor the \"first install\", you could use the good old PXE boot approach on bare metal. In the cloud, you could use the cloud provider's \"image\" service to deploy the image to the systems.",[522,1190,1191],{},"Instead of installing and updating packages, the future seems to be moving towards \"installing\" container images and updating them from your normal everyday container registry.",[522,1193,1194],{},[558,1195],{"alt":1196,"src":1197},"CDS2026 - Bootable Containers: An entire OS as a Containerfile - Robert Guske - Bootc: Image-based updates perfected","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-bootable-containers-2.webp",[522,1199,1200,1201,1206],{},"As already mentioned, updating the OS is as simple as pulling the updated container image and rebooting the system. With this approach, you could also roll back if needed.\nSimilar to Flatcar Linux and Talos Linux, most Android smartphones use ",[548,1202,1205],{"href":1203,"rel":1204},"https:\u002F\u002Fsource.android.com\u002Fdocs\u002Fcore\u002Fota\u002Fab",[552],"A\u002FB (seamless) system updates",", where two system partitions help ensure that an update can be rolled back if something goes wrong.",[540,1208,1210],{"id":1209},"kafka-without-disks-making-streaming-brokers-disposable-on-k8s-anton-borisov","Kafka Without Disks: Making Streaming Brokers Disposable on K8S - Anton Borisov",[522,1212,1213],{},"This is a topic I don't know much about, but I was interested in the \"disposable\" aspect, as one thing I do know is that Kafka needs persistent storage to work well. :-D",[522,1215,1216],{},[558,1217],{"alt":1218,"src":1219},"CDS2026 - Kafka Without Disks: Making Streaming Brokers Disposable on K8S - Anton Borisov - Why are we triple-mirroring every hot byte when the object store already handles durability?","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-kafka-without-disks-1.webp",[522,1221,1222],{},"I think I have heard that question before... \"Why would a database cluster 'triple replicate' the data while the underlying Ceph storage also 'triple replicates' the data? Isn't that a bit overkill?\"\nIt was also interesting to hear a bit about how the project handles this with KIPs (Kafka Improvement Proposals).",[522,1224,1225],{},[558,1226],{"alt":1227,"src":1228},"CDS2026 - Kafka Without Disks: Making Streaming Brokers Disposable on K8S - Anton Borisov - The Good - Slack's KIP-1176","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-kafka-without-disks-2.webp",[522,1230,1231],{},"From what I gathered, the implementation they went with feels a lot like how Thanos (\"long-term Prometheus monitoring storage\") handles this. Thanos queries the \"hot\" data from the \"live\" Prometheus via a sidecar, while the \"cold\" data is stored in object storage, e.g., S3.",[522,1233,1234],{},"It was interesting to hear about Kafka, especially how they are trying to make it \"disposable\" on Kubernetes.",[532,1236],{},[535,1238,1240],{"id":1239},"day-3","Day 3",[540,1242,1244],{"id":1243},"federated-identity-for-distributed-systems-understanding-spiffe-leon-kraß","Federated Identity for Distributed Systems: Understanding SPIFFE - Leon Kraß",[522,1246,1247],{},"For authentication and authorization in a distributed \"world\", you need to know which \"user\" or \"agent\" is trying to access a resource.",[522,1249,1250],{},"In the talk, they split identities into two categories:",[791,1252,1253,1256],{},[794,1254,1255],{},"Human identities - your classical \"meatbag\" human user.",[794,1257,1258],{},"Non-human identities - In the past, this mostly meant \"robot users\" or \"service accounts\". Nowadays, with the rise of AI, it could also be an AI agent or \"bot\" trying to access a resource.",[522,1260,1261],{},"This makes a huge difference in how you handle them. A human may use a password or other identifying information, while a non-human identity will usually use a token or certificate to \"prove\" its identity.",[522,1263,1264],{},[558,1265],{"alt":1266,"src":1267},"CDS2026 - Federated Identity for Distributed Systems: Understanding SPIFFE - Leon Kraß - Non-Human Identities","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-spiffe-1.webp",[522,1269,1270],{},"Broken down further, a human identity is a physical entity with attributes, such as a name or email address, that are mapped to digital attributes.\nA non-human identity is a digital entity with digital attributes, for example, a Kubernetes service account.",[522,1272,1273],{},[558,1274],{"alt":1275,"src":1276},"CDS2026 - Federated Identity for Distributed Systems: Understanding SPIFFE - Leon Kraß - Trust Boundaries and Identity Federation","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-spiffe-2.webp",[522,1278,1279],{},"In the past, distributed systems were mostly \"static\", so using something like an IP address as the identity was often enough. In a dynamic system-where workloads can scale, move between platforms, or be replaced-the network identity is no longer enough.",[522,1281,1282],{},"This becomes even more challenging when authentication and authorization need to work across platforms. In the age of AI, you especially want to know what an agent did, while also being able to limit what that agent is allowed to do, including across platforms.",[522,1284,1285],{},[558,1286],{"alt":1287,"src":1288},"CDS2026 - Federated Identity for Distributed Systems: Understanding SPIFFE - Leon Kraß - Challenges with (Non-) Human Identities","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-spiffe-3.webp",[522,1290,1291,1296],{},[548,1292,1295],{"href":1293,"rel":1294},"https:\u002F\u002Fspiffe.io\u002F",[552],"SPIFFE"," stands for \"Secure Production Identity Framework For Everyone\".",[522,1298,1299],{},"\"The Bottom Turtle Analogy\"",[522,1301,1302],{},[558,1303],{"alt":1304,"src":1305},"CDS2026 - Federated Identity for Distributed Systems: Understanding SPIFFE - Leon Kraß - The Bottom Turtle Analogy","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-spiffe-4.webp",[522,1307,1308],{},"The idea is basically a chain of trust, or a \"trust chain\".",[522,1310,1311],{},"SPIFFE provides non-human identities that can be cryptographically verified and used across platforms.\nAn SVID, or \"SPIFFE Verifiable Identity Document\", is the document containing that identity. It is usually represented as an X.509 certificate or a JWT and can be used to verify the identity of a workload.\nIn the end, the cryptography itself is not new. Certificates, JWTs, signing, and verification are all established technologies. SPIFFE provides a common framework for using them to identify workloads.",[522,1313,1314],{},"A SPIFFE identity service can establish and federate trust across platforms, for example between a Kubernetes cluster and a VM-based system.",[522,1316,1317],{},"SPIRE is the reference implementation of SPIFFE. Red Hat OpenShift and HashiCorp Vault Enterprise also support or integrate with SPIFFE\u002FSPIRE.",[522,1319,1320],{},[558,1321],{"alt":1322,"src":1323},"CDS2026 - Federated Identity for Distributed Systems: Understanding SPIFFE - Leon Kraß - SPIFFE + SPIRE Live Demo","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-spiffe-5.webp",[522,1325,1326],{},"They also showed a CSI driver for using SPIFFE\u002FSPIRE identities in Kubernetes-based environments.\nSPIRE also provides CRDs for configuring the SPIFFE\u002FSPIRE service in Kubernetes. For example, the trust domain can be configured, and pod label selectors can be used to determine which pods should receive a SPIFFE identity.",[522,1328,1329],{},"In the X.509 demo, a client retrieved a certificate from SPIRE and used it to authenticate to a server that also had a SPIFFE identity. The client and server were able to verify each other's certificates because the certificates were issued by the same certificate authority within the same SPIFFE trust domain.",[522,1331,1332],{},"That is the main benefit of SPIFFE: workloads can authenticate based on who they are instead of where they currently run or which IP address they have.",[540,1334,1336],{"id":1335},"kubernetes-as-the-universal-control-plane-from-pods-to-multi-cloud-infrastructure-rabieh-fashwall","Kubernetes as the Universal Control Plane: From Pods to Multi-Cloud Infrastructure - Rabieh Fashwall",[1338,1339,1340,1343],"blockquote",{},[522,1341,1342],{},"\"Infrastructure as Code is great until there's a bug and finops\u002Ffinance is on your back (about the bill).\"",[791,1344,1345],{},[794,1346,1347],{},"Rabieh Fashwall (The quote is not fully verbatim, but the meaning is the same.)",[522,1349,1350],{},"Every cloud provider has its own CLIs, tooling, and Terraform code for creating resources. For example, \"creating a database\" can mean something very different across providers in regard to what needs to happen.\nThis can lead to fragmentation. Every team ends up with its own toolchain and way of doing things. A company-wide \"cloud strategy\" can turn into a game of \"disk fragmentation\" when trying to\nmanage resources across multiple clouds and, more importantly, consolidate cloud resources and costs.",[522,1352,1353],{},"If you wanna create a database in the cloud, you gotta create VPCs, subnets, security groups\u002Fprofiles, etc., to get it up and running and integrate it into your existing cloud infrastructure.\nIn the \"YAML world\", aka Kubernetes, this can be simpler when using custom resources and operators. A \"Database\" custom resource definition (CRD) could be used to define the desired state of a database, and an operator would be responsible for managing the lifecycle of that database.",[522,1355,1356],{},[558,1357],{"alt":1358,"src":1359},"CDS2026 - Kubernetes as the Universal Control Plane: From Pods to Multi-Cloud Infrastructure - Rabieh Fashwall - Crossplane: The Cloud-Native Infrastructure Manager","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-crossplane-1.webp",[522,1361,1362],{},"But how would you go about creating operators for every resource and every cloud provider? That would definitely be a lot of work just to get some cloud resources managed in Kubernetes. This is where a tool like Crossplane comes into play.\nCrossplane allows you to manage cloud resources through Kubernetes APIs. Cloud resources can then be defined and managed as Kubernetes custom resources, so you can use the same declarative approach you already know from Kubernetes.\nTo interject, calling Crossplane just a \"tool\" would be an understatement. It is more like a framework for building your own operators for cloud resources. It also comes with a lot of community-built providers, e.g., for AWS, Azure, GCP, etc., as well as a \"provider for Kubernetes\" to manage resources in other Kubernetes clusters.",[522,1364,1365],{},"With the Kubernetes provider, you could even manage Kubernetes clusters via the Cluster API (CAPI) and the Cluster API provider for your cloud provider of choice, e.g., AWS, Azure, GCP, etc. It's just YAML in the end.",[522,1367,1368],{},[558,1369],{"alt":1370,"src":1371},"CDS2026 - Kubernetes as the Universal Control Plane: From Pods to Multi-Cloud Infrastructure - Rabieh Fashwall - Demo Time: From kubectl to a running database","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-crossplane-2.webp",[522,1373,1374,1375,1378,1379,1381,1382,1384,1385,1388,1389,628],{},"But to get back to the talk, it focused on using Crossplane to manage cloud resources for developers and teams.\nThe demo showed how Crossplane could provision a cloud database through a ",[654,1376,1377],{},"DatabaseClaim",". The ",[654,1380,1377],{}," is a Crossplane custom resource that defines the desired state of a database.\nThe credentials were stored in a Kubernetes Secret, which can be used by apps to connect to the database. The demo also showed that changing the ",[654,1383,1377],{}," would trigger Crossplane to update the database resource accordingly, e.g., changing the size of the database from ",[654,1386,1387],{},"small"," to ",[654,1390,1391],{},"medium",[522,1393,1394],{},[558,1395],{"alt":1396,"src":1397},"CDS2026 - Kubernetes as the Universal Control Plane: From Pods to Multi-Cloud Infrastructure - Rabieh Fashwall - The Power Combo: Crossplane + Cluster API","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-crossplane-3.webp",[522,1399,1400,1405],{},[548,1401,1404],{"href":1402,"rel":1403},"https:\u002F\u002Fwww.crossplane.io\u002F",[552],"Crossplane"," is great, but what happens when you combine it with the powerful Cluster API (CAPI)? The demo showed how easy it can be to create a cluster and scale it up or down (adding or removing nodes) with Cluster API.\nBringing Crossplane back into the picture, developers could \"easily\" create a new test environment with a cluster and a database using GitOps.\nIn the demo, they used ArgoCD for the GitOps part, but you could use any GitOps tool of your choice, e.g., FluxCD.",[522,1407,1408],{},[558,1409],{"alt":1410,"src":1411},"CDS2026 - Kubernetes as the Universal Control Plane: From Pods to Multi-Cloud Infrastructure - Rabieh Fashwall - The Internal Developer Platform: Self-Service Infrastructure","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-crossplane-4.webp",[522,1413,1414],{},[558,1415],{"alt":1416,"src":1417},"CDS2026 - Kubernetes as the Universal Control Plane: From Pods to Multi-Cloud Infrastructure - Rabieh Fashwall - Challenges You'll Face","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-crossplane-5.webp",[522,1419,1420],{},"I have to say that the title of the talk felt like it promised something more or something \"new\" than it delivered. Still, it was a good refresher on Crossplane and CAPI, especially the last two pictures about the layers of developer self-service and the \"challenges you'll face.\"\nAs a consultant, the pain is real. Just shoving Crossplane, CAPI, and GitOps tools into a company and saying, \"Here you go, now you can self-service your infrastructure,\" is not going to work.\nThere are many more factors to consider, e.g., security, compliance, cost management, etc., but also the \"human factor.\"\nOne point about the \"human factor\" I want to highlight is that some people, or even whole teams, might not actually want to \"self-service\" the infrastructure for their applications. You gotta show them gradually that it actually makes their lives easier.",[532,1422],{},[535,1424,1426],{"id":1425},"the-future","The Future",[522,1428,1429],{},"Based on the plans laid out for upcoming ContainerDays and AIContext conferences, ContainerDays seems to be successful. I have to agree that ContainerDays is my favorite conference, besides events such as FOSDEM. Those are great as well, but in their own category.",[522,1431,1432,1433,1438,1439,1444],{},"Be sure to check out the ",[548,1434,1437],{"href":1435,"rel":1436},"https:\u002F\u002Fwww.youtube.com\u002F@ContainerDays",[552],"ContainerDays YouTube channel"," for the upcoming recordings and check the ",[548,1440,1443],{"href":1441,"rel":1442},"https:\u002F\u002Fwww.containerdays.io",[552],"ContainerDays website"," for upcoming ContainerDays and AIContext-related events (use the \"View all events\" button in the top right of the page). I should be attending next year's ContainerDays in Hamburg if my planning works out.",[522,1446,1447],{},[558,1448],{"alt":1449,"src":1450},"CDS2026 - Future Events World Map","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-future-events.webp",{"title":1452,"searchDepth":1453,"depth":1453,"links":1454},"",2,[1455,1463,1469,1473],{"id":537,"depth":1453,"text":538,"children":1456},[1457,1459,1460,1462],{"id":542,"depth":1458,"text":543},3,{"id":612,"depth":1458,"text":613},{"id":694,"depth":1458,"text":1461},"So I generated over 3000 10000+ SBOMS for the CNCF ecosystem - Mario Fahlandt",{"id":865,"depth":1458,"text":866},{"id":940,"depth":1453,"text":941,"children":1464},[1465,1466,1467,1468],{"id":944,"depth":1458,"text":945},{"id":986,"depth":1458,"text":987},{"id":1172,"depth":1458,"text":1173},{"id":1209,"depth":1458,"text":1210},{"id":1239,"depth":1453,"text":1240,"children":1470},[1471,1472],{"id":1243,"depth":1458,"text":1244},{"id":1335,"depth":1458,"text":1336},{"id":1425,"depth":1453,"text":1426},"2026-09-02T08:00:00+02:00","Blog post about the ContainerDays Hamburg 2026 conference and some of the talks I attended.","md","\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026\u002Fcds2026-registration-wardrobe.webp",{},true,"\u002Fblog\u002F2026\u002Fcontainer-days-hamburg-2026",{"title":510,"description":1475},"3.blog\u002F2026\u002Fcontainer-days-hamburg-2026","4D5p6L3zghSUKDNVzKj5tOHs1ObS0j4yrPUhOqxqIOQ",[1485,517],{"title":1486,"path":1487,"stem":1488,"description":1489,"children":-1},"Kubernetes: IPv6-only For Real In Good This Time","\u002Fblog\u002F2025\u002Fkubernetes-ipv6-only-for-real-in-good-this-time","3.blog\u002F2025\u002Fkubernetes-ipv6-only-for-real-in-good-this-time","Let's set up a Kubernetes cluster that runs using IPv6-only networking, using the \u002F64 networks of your machines, with Talos Linux and Cilium CNI.",1790368349791]