<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>kontrolplane - notes from the field</title>
    <link>https://kontrolplane.dev/blog/</link>
    <atom:link href="https://kontrolplane.dev/rss.xml" rel="self" type="application/rss+xml" />
    <description>practical takes on kubernetes, infrastructure, and platform engineering - from real client work.</description>
    <language>en</language>
    <managingEditor>info@kontrolplane.dev (kontrolplane)</managingEditor>
    <lastBuildDate>Sun, 04 Oct 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>prometheus cardinality</title>
      <link>https://kontrolplane.dev/blog/prometheus-cardinality/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/prometheus-cardinality/</guid>
      <description>every unique label combination is its own series in prometheus, and one label holding an id or a raw path can outweigh every other metric combined.</description>
      <pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>terraform state without surgery</title>
      <link>https://kontrolplane.dev/blog/terraform-state-without-surgery/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/terraform-state-without-surgery/</guid>
      <description>terraform's moved, import, and removed blocks turn state surgery into configuration changes that get a plan, a review, and a history like any other.</description>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>promotions with kargo</title>
      <link>https://kontrolplane.dev/blog/promotions-with-kargo/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/promotions-with-kargo/</guid>
      <description>kargo models the sequence and requirements for promoting a version between environments, layering on top of argocd without replacing its sync.</description>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>graceful shutdown in kubernetes</title>
      <link>https://kontrolplane.dev/blog/graceful-shutdown-in-kubernetes/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/graceful-shutdown-in-kubernetes/</guid>
      <description>rolling updates drop connections when kubelet sends sigterm before the endpoint is removed from routing. the fix spans the pod spec and the application.</description>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>messaging with nats</title>
      <link>https://kontrolplane.dev/blog/messaging-with-nats/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/messaging-with-nats/</guid>
      <description>nats routes messages by subject with a single small binary, and its jetstream layer adds persistence, replay, and at-least-once delivery on top.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>row level security in postgres</title>
      <link>https://kontrolplane.dev/blog/row-level-security-in-postgres/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/row-level-security-in-postgres/</guid>
      <description>row level security moves tenant filtering out of application code and into the table definition, so a forgotten where clause returns nothing.</description>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>password management with pass</title>
      <link>https://kontrolplane.dev/blog/password-management-with-pass/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/password-management-with-pass/</guid>
      <description>pass encrypts each password into its own gpg file and tracks the whole store with git, avoiding proprietary databases and vendor sync services.</description>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>system and user prompts</title>
      <link>https://kontrolplane.dev/blog/system-and-user-prompts/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/system-and-user-prompts/</guid>
      <description>system and user prompts in an llm api request look interchangeable but carry different authority, and blurring the distinction causes real failures.</description>
      <pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>secrets management with external secrets operator</title>
      <link>https://kontrolplane.dev/blog/secrets-management-with-external-secrets-operator/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/secrets-management-with-external-secrets-operator/</guid>
      <description>the external secrets operator syncs secrets from aws parameter store and other backends into native kubernetes secrets, keeping the source outside the cluster.</description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>terminal user interfaces with bubbletea</title>
      <link>https://kontrolplane.dev/blog/terminal-user-interfaces-with-bubbletea/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/terminal-user-interfaces-with-bubbletea/</guid>
      <description>bubbletea is a go framework for terminal interfaces built on the elm architecture, for interactive cli tools driven by state and messages.</description>
      <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>managing dotfiles with stow</title>
      <link>https://kontrolplane.dev/blog/managing-dotfiles-with-stow/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/managing-dotfiles-with-stow/</guid>
      <description>gnu stow turns a directory of dotfiles into symlinks placed in the right spots, replacing brittle install scripts with plain directory structure.</description>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>preview environments with argocd</title>
      <link>https://kontrolplane.dev/blog/preview-environments-with-argocd/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/preview-environments-with-argocd/</guid>
      <description>argocd applicationsets can generate a full preview environment for every open pull request and remove it automatically once the pull request closes.</description>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>terminal multiplexing with tmux</title>
      <link>https://kontrolplane.dev/blog/terminal-multiplexing-with-tmux/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/terminal-multiplexing-with-tmux/</guid>
      <description>tmux keeps terminal sessions alive across disconnects and splits them into panes and windows, replacing a pile of manually tiled terminal tabs.</description>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>postgres on kubernetes with cloudnativepg</title>
      <link>https://kontrolplane.dev/blog/postgres-on-kubernetes-with-cloudnativepg/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/postgres-on-kubernetes-with-cloudnativepg/</guid>
      <description>cloudnativepg is a kubernetes operator built for postgresql that handles replication, failover, backups, and monitoring through custom resources.</description>
      <pubDate>Sat, 10 May 2025 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>policy as code with kyverno</title>
      <link>https://kontrolplane.dev/blog/policy-as-code-with-kyverno/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/policy-as-code-with-kyverno/</guid>
      <description>kyverno enforces security standards, injects defaults, and generates resources in kubernetes using plain yaml policies instead of a new language.</description>
      <pubDate>Fri, 02 May 2025 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>cgroup-based security in kubernetes</title>
      <link>https://kontrolplane.dev/blog/cgroup-based-security-in-kubernetes/</link>
      <guid isPermaLink="true">https://kontrolplane.dev/blog/cgroup-based-security-in-kubernetes/</guid>
      <description>kubernetes translates pod resource requests and limits into linux cgroups, and missing or misconfigured ones let a memory leak or a fork bomb take down the whole node.</description>
      <pubDate>Fri, 25 Apr 2025 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
