Why Does Developing on Kubernetes Suck? | Tilt Blog
Kubernetes has changed the way I operate software. Whole classes of production problems have disappeared–arguably to be replaced by others. But such is the way of the world. All told I’m happier operating a microservices app today than I was before I started using Kubernetes.

Some useful tools are linked that help visualize and audit pod relationships.

That said, this is another example of how k8s introduces so much cognitive overhead and complexity that it makes it extraordinarily difficult to troubleshoot.
The sheer number of tools needed to keep k8s supported is infrastructure equivalent of "code smell."

I get that it's a standard pattern to identify a problem, write a solution, and maybe even charge money for it.
That's business.
But the sheer number of essential tools in the k8s ecosystem that aren't kubernetes-qua-kubernetes always gives me pause because complexity kills.
GitHub - StanfordSNR/gg: The Stanford Builder
The Stanford Builder. Contribute to StanfordSNR/gg development by creating an account on GitHub.
This looks less rubbishy than the goog runtime.
Kubernetes: The Difference Between Containers and Virtual Machines | Dyn Blog
If you are remotely involved in technology and haven’t just hatched out of an egg, you have probably have heard of Kubernetes. ...
The Almighty Pause Container - Ian Lewis
When checking out the nodes of your Kubernetes cluster, you may have noticed some containers called
GitHub - theupdateframework/notary: Notary is a project that allows anyone to have trust over arbitrary collections of data
Notary is a project that allows anyone to have trust over arbitrary collections of data - theupdateframework/notary

Data signing, basically.
Looks like it still requires a secure channel for keys.
Which makes me wonder why they're not using pki or even pubic keys. (I may be misunderstanding the architecture.)
The Packer Book
The Packer Book - A hands-on book on Packer
quick start | Rancher Labs
Follow our easy steps to get started with Rancher 2.0. Install a supported version of Docker software on the Linux host, then run the Rancher server. Learn more.
Releases · kubernetes/minikube
30.0/minikube-darwin-amd64 && chmod +x minikube && sudo cp minikube /usr/local/bin/ && rm minikube
Docker is the dangerous gamble which we will regret | Smash Company
a foolish consistency is something something...

>And as near as I can tell, this is 100% why Docker is winning. Forget all the nonsense you read about Docker making deployment or security or orchestration easier. It doesn’t. But it is emerging as a standard, something a person can learn at one company and then take to another company. It isn’t messy and ad-hoc the way a custom bash script would be. And that is the real argument in favor of Docker. Whether it can live up to that promise is the gamble.

Fascinating. Never considered the labor skill aspect of it.
Escaping Docker container using waitid() – CVE-2017-5123 | Hacker News
For a forum where tptacek has been informally instructing other hn readers for years, they still come up with some profound misunderstandings of some pretty basic security concepts.
