[{"data":1,"prerenderedAt":426},["ShallowReactive",2],{"navigation":3,"topic-edge":14,"topic-edge-ventures":75,"topic-edge-oss":94,"topic-edge-posts":105},[4],{"title":5,"path":6,"stem":7,"children":8,"page":13},"Blog","\u002Fblog","blog",[9],{"title":10,"path":11,"stem":12},"Kubernetes 101","\u002Fblog\u002Fkubernetes-introduction","blog\u002Fkubernetes-introduction",false,{"id":15,"title":16,"body":17,"description":61,"draftNotice":62,"extension":63,"meta":64,"navigation":62,"order":55,"path":65,"pillar":66,"related":67,"seo":72,"stem":73,"__hash__":74},"topics\u002Ftopics\u002Fedge.md","Fleet management",{"type":18,"value":19,"toc":53},"minimark",[20,24,29,32,36,39,43,46,50],[21,22,23],"p",{},"One cluster is a tutorial. A hundred clusters in a hundred buildings, half of them behind a firewall an OT team controls, is a different discipline.",[25,26,28],"h2",{"id":27},"intermittent-is-the-normal-case","Intermittent is the normal case",[21,30,31],{},"Designing for a link that is usually up is how you build something that fails badly. Reconciliation has to be the default behaviour, not the recovery path.",[25,33,35],{"id":34},"the-commissioning-window","The commissioning window",[21,37,38],{},"Line commissioning is when infrastructure decisions get made under time pressure by people who will never touch them again. What you ship has to survive that.",[25,40,42],{"id":41},"resource-budgets-are-a-design-constraint","Resource budgets are a design constraint",[21,44,45],{},"If it needs a datacenter, it does not belong at the edge. What that rules out, and what it forces you to do better.",[25,47,49],{"id":48},"the-handover-test","The handover test",[21,51,52],{},"We built the fleet. Another supplier runs it now. Reversibility is not a licensing claim, it is whether the next team can actually take over — and most architectures fail this test the first time it is applied.",{"title":54,"searchDepth":55,"depth":55,"links":56},"",2,[57,58,59,60],{"id":27,"depth":55,"text":28},{"id":34,"depth":55,"text":35},{"id":41,"depth":55,"text":42},{"id":48,"depth":55,"text":49},"Running k3s across a hundred sites with intermittent connectivity — and the test almost nobody applies to their own architecture, which is whether someone else can take it over.",true,"md",{},"\u002Ftopics\u002Fedge","edge",{"ventures":68,"oss":70},[69],"start-alpha",[71],"k3s",{"title":16,"description":61},"topics\u002Fedge","H4aYowyeNQMS3ibcx-uLRmRz8wngi6JE2iK7a4UADxk",[76],{"id":77,"description":78,"extension":79,"meta":80,"name":81,"order":82,"period":83,"role":84,"slug":69,"stack":85,"stem":90,"tagline":91,"url":92,"__hash__":93},"ventures\u002Fwork\u002Fventures\u002Fstart-alpha.yml","A sovereign control plane for fleets that cannot assume connectivity. A single declarative blueprint covers workloads, OS configuration, cloud resources, security policy and disaster recovery; agents reconcile it across every site autonomously. Built on Kubernetes and OpenTelemetry, with export so the definition stays yours.","yml",{},"Start-Alpha",1,"2026 — present","Co-founder & CTO",[86,71,87,88,89],"Kubernetes","Go","OpenTelemetry","SPIFFE\u002FSPIRE","work\u002Fventures\u002Fstart-alpha","One blueprint to deploy, govern and recover distributed infrastructure — from edge to cloud. Secure software supply-chain, from OS to applications.","https:\u002F\u002Fstart-alpha.io","bUXmRvaZL5nHtGzSaPvPBx-GogtjN6x367nKeLKxgs8",[95],{"id":96,"description":97,"extension":79,"featured":13,"language":87,"meta":98,"name":71,"order":99,"repo":100,"role":101,"slug":71,"stem":102,"why":103,"__hash__":104},"oss\u002Fwork\u002Foss\u002Fk3s.yml","A certified Kubernetes distribution small enough to run in a plant cabinet.",{},5,"https:\u002F\u002Fgithub.com\u002Fk3s-io\u002Fk3s","watching","work\u002Foss\u002Fk3s","It is the reason \"if it needs a datacenter it does not belong at the edge\" is a design constraint rather than a complaint.","VFzFEQeRQHsxeOcQknHeoEoI6ks_dqacKmCHVZfZj7c",[106],{"id":107,"title":10,"body":108,"canonical":416,"date":417,"description":418,"draft":13,"extension":63,"featured":13,"format":419,"image":416,"meta":420,"minRead":412,"navigation":62,"path":11,"pillar":66,"seo":421,"series":416,"slides":62,"stem":12,"tags":422,"updated":416,"__hash__":425},"blog\u002Fblog\u002Fkubernetes-introduction.md",{"type":18,"value":109,"toc":400},[110,113,117,120,124,153,156,176,180,183,186,189,193,196,199,203,206,209,213,216,230,233,236,240,251,305,309,314,338,342,368,372,390,394,397],[21,111,112],{},"A short primer before anything edge-specific.",[25,114,116],{"id":115},"what-it-is","What it is",[21,118,119],{},"Kubernetes is an open-source container orchestrator. It joins several machines into one cluster and takes care of deploying, scaling and managing containerised applications through a standard API.",[25,121,123],{"id":122},"why-use-it-and-when-not-to-use-it","Why use it, and when not to use it",[125,126,127,135,141,147],"ul",{},[128,129,130,134],"li",{},[131,132,133],"strong",{},"Resilience."," With several nodes, workloads move elsewhere when a machine fails.",[128,136,137,140],{},[131,138,139],{},"Scaling."," An application runs as one or many containers behind the same API.",[128,142,143,146],{},[131,144,145],{},"Service discovery."," Workloads find each other by name, not by hand-managed IP addresses.",[128,148,149,152],{},[131,150,151],{},"Consistency."," The same manifests deploy on-premise, in the cloud, or across both.",[21,154,155],{},"And when not to:",[125,157,158,164,170],{},[128,159,160,163],{},[131,161,162],{},"One app on one box."," Docker Compose or systemd is simpler and enough.",[128,165,166,169],{},[131,167,168],{},"Nobody to run it."," Kubernetes is a platform to operate, not a tool to install. The learning curve is real, and so is the day-two work.",[128,171,172,175],{},[131,173,174],{},"Hard real time."," It schedules containers. It does not replace a PLC or a real-time OS.",[25,177,179],{"id":178},"brief-history","Brief history",[21,181,182],{},"Kubernetes grew out of a decade of running containers inside Google, went open source in 2014, and was handed to a vendor-neutral foundation a year later. That last move is what turned it into an industry standard rather than a Google product.",[184,185],"k8s-history",{},[21,187,188],{},"One of the 3 most mature projects in the CNCF.",[25,190,192],{"id":191},"an-extensible-product","An extensible product...",[21,194,195],{},"The API is the contract. Every object has a path on it, operators add their own kinds, and runtime, network and storage are swappable behind standard interfaces. Like Linux, it comes in many distributions.",[197,198],"k8s-api-path",{},[25,200,202],{"id":201},"based-on-a-reconciliation-principle","...based on a reconciliation principle",[21,204,205],{},"You tell Kubernetes what you want, not how to get there: \"two copies of this container, reachable on this port\". The cluster stores that desired state and keeps comparing it with what is actually running. When a pod crashes or a node disappears, the gap is noticed and closed without anyone being paged. The same loop applies your changes: edit the desired state, and the cluster converges to it.",[207,208],"k8s-reconcile",{},[25,210,212],{"id":211},"control-plane-and-data-plane","Control plane and data plane",[21,214,215],{},"A cluster has two halves.",[125,217,218,224],{},[128,219,220,223],{},[131,221,222],{},"The control plane"," holds the desired state. It is made of the API server, the scheduler, the controller managers, and a datastore (etcd, or SQLite in a default k3s install).",[128,225,226,229],{},[131,227,228],{},"The data plane"," is the worker nodes. They run the containers the control plane assigns to them.",[231,232],"k8s-architecture",{},[21,234,235],{},"Operators and tooling talk to the API server. End users never see it; they reach the applications running on the nodes.",[25,237,239],{"id":238},"hands-on","Hands-on",[21,241,242,243,250],{},"Exercises in ",[244,245,249],"a",{"href":246,"rel":247},"https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Fk8s-101-exercices",[248],"nofollow","k8s-101-exercices",": a folder each, with README, manifests and a check script. Work in your own namespace on the shared k3s cluster.",[252,253,254,265,275,285,295],"ol",{},[128,255,256,264],{},[131,257,258,263],{},[244,259,262],{"href":260,"rel":261},"https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Fk8s-101-exercices\u002Ftree\u002Fmain\u002F00-hello",[248],"Hello","."," Two replicas. Delete a pod by hand, watch it come back.",[128,266,267,274],{},[131,268,269,263],{},[244,270,273],{"href":271,"rel":272},"https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Fk8s-101-exercices\u002Ftree\u002Fmain\u002F01-service",[248],"Service"," A NodePort in front, reached from outside and by name inside.",[128,276,277,284],{},[131,278,279,263],{},[244,280,283],{"href":281,"rel":282},"https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Fk8s-101-exercices\u002Ftree\u002Fmain\u002F02-configmap",[248],"ConfigMap"," Config out of the image. Which changes need a rollout?",[128,286,287,294],{},[131,288,289,263],{},[244,290,293],{"href":291,"rel":292},"https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Fk8s-101-exercices\u002Ftree\u002Fmain\u002F03-initcontainer",[248],"Init containers"," Wait for a dependency, seed a volume, then start.",[128,296,297,304],{},[131,298,299,263],{},[244,300,303],{"href":301,"rel":302},"https:\u002F\u002Fgithub.com\u002Fmathieu-sabatier\u002Fk8s-101-exercices\u002Ftree\u002Fmain\u002F04-break-it",[248],"Break it"," Wrong image tag, failing probe. Describe, logs, events, fix.",[25,306,308],{"id":307},"key-tools","Key tools",[310,311,313],"h3",{"id":312},"cli","CLI:",[125,315,316,324],{},[128,317,318,323],{},[244,319,322],{"href":320,"rel":321},"https:\u002F\u002Fkubernetes.io\u002Fdocs\u002Freference\u002Fkubectl\u002F",[248],"kubectl",", the go-to for quick debug and inspection.",[128,325,326,331,332,337],{},[244,327,330],{"href":328,"rel":329},"https:\u002F\u002Fk9scli.io\u002F",[248],"k9s",", ",[244,333,336],{"href":334,"rel":335},"https:\u002F\u002Flenshq.io\u002F",[248],"lens",", tool to visualise cluster state",[310,339,341],{"id":340},"application-packaging","Application packaging:",[125,343,344,352,360],{},[128,345,346,351],{},[244,347,350],{"href":348,"rel":349},"https:\u002F\u002Fkustomize.io\u002F",[248],"kustomize"," native templates",[128,353,354,359],{},[244,355,358],{"href":356,"rel":357},"https:\u002F\u002Fhelm.sh\u002Fdocs\u002F",[248],"helm"," app templating, client side",[128,361,362,367],{},[244,363,366],{"href":364,"rel":365},"https:\u002F\u002Fkro.run\u002F",[248],"kro"," app templating, server side",[310,369,371],{"id":370},"gitops","GitOps",[125,373,374,382],{},[128,375,376,381],{},[244,377,380],{"href":378,"rel":379},"https:\u002F\u002Ffluxcd.io\u002F",[248],"flux",", unix-style & lighweight controllers",[128,383,384,389],{},[244,385,388],{"href":386,"rel":387},"https:\u002F\u002Fargo-cd.readthedocs.io\u002Fen\u002Fstable\u002F",[248],"argocd",", dev friendly app & UI",[25,391,393],{"id":392},"what-gitops-is-exactly","What GitOps is exactly?",[21,395,396],{},"Instead of pointing kubectl at the cluster, you push manifests to a Git repository and an agent inside the cluster pulls them and applies them through the API server. The repository becomes the source of truth: every change is a reviewed commit, the whole cluster can be rebuilt from it, and rolling back is a revert.",[398,399],"k8s-gitops",{},{"title":54,"searchDepth":55,"depth":55,"links":401},[402,403,404,405,406,407,408,409,415],{"id":115,"depth":55,"text":116},{"id":122,"depth":55,"text":123},{"id":178,"depth":55,"text":179},{"id":191,"depth":55,"text":192},{"id":201,"depth":55,"text":202},{"id":211,"depth":55,"text":212},{"id":238,"depth":55,"text":239},{"id":307,"depth":55,"text":308,"children":410},[411,413,414],{"id":312,"depth":412,"text":313},3,{"id":340,"depth":412,"text":341},{"id":370,"depth":412,"text":371},{"id":392,"depth":55,"text":393},null,"2026-09-25","What Kubernetes is, what problems it solves, and how it is composed and start using it.","guide",{},{"title":10,"description":418},[423,71,424],"kubernetes","primer","2FT5iJNmj4lFDtUu7noSIWC_iMV6MpwPA4mFEmCKtiM",1791414106400]